Standards
Règlement (UE) 2022/2554 — DORAUnion européenne

Digital operational resilience for the financial sector

In force since 17 January 2025, DORA imposes a single digital operational resilience baseline on some twenty categories of EU financial entities. Five pillars: ICT risk governance and management, major incident reporting, resilience testing, third-party risk management, and cyber threat information sharing.

Official text

Who it applies to

  • EU financial entities of every size
  • ICT providers serving the financial sector
  • Compliance, risk and security functions
  • Management bodies, personally accountable under Article 5

Structuring points

  • The management body is explicitly and personally accountable for the ICT risk framework
  • The register of ICT contractual arrangements is the most underestimated deliverable
  • TLPT applies only to designated entities, but resilience testing applies to everyone
  • Major incident notification deadlines are short and non-negotiable
  • Proportionality exists but must be documented, not merely asserted

Banks, insurers, investment firms, payment institutions, asset managers, crypto-asset service providers, and — by extension — their designated critical ICT third-party providers.

Requirements 20