← Standards
Règlement (UE) 2022/2554 — DORAUnion européenne
Digital operational resilience for the financial sector
In force since 17 January 2025, DORA imposes a single digital operational resilience baseline on some twenty categories of EU financial entities. Five pillars: ICT risk governance and management, major incident reporting, resilience testing, third-party risk management, and cyber threat information sharing.
Official textWho it applies to
- EU financial entities of every size
- ICT providers serving the financial sector
- Compliance, risk and security functions
- Management bodies, personally accountable under Article 5
Structuring points
- The management body is explicitly and personally accountable for the ICT risk framework
- The register of ICT contractual arrangements is the most underestimated deliverable
- TLPT applies only to designated entities, but resilience testing applies to everyone
- Major incident notification deadlines are short and non-negotiable
- Proportionality exists but must be documented, not merely asserted
Banks, insurers, investment firms, payment institutions, asset managers, crypto-asset service providers, and — by extension — their designated critical ICT third-party providers.