Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The Digital Operational Resilience Act (DORA), Regulation (EU) 2022/2554, sets EU-wide requirements for the security and resilience of the network and information systems that support financial entities’ business processes. It has applied since 17 January 2025. Its requirements cover governance and ICT risk management, incident handling, resilience testing and ICT supplier risk; separate EU oversight applies to ICT providers designated as critical.

What is DORA?

DORA is an EU regulation intended to make digital operational resilience a consistent responsibility across the financial sector. Article 1 says: “This Regulation lays down uniform requirements concerning the security of network and information systems supporting the business processes of financial entities as follows”. In practical terms, the rules address how financial entities prepare for, withstand, respond to and recover from ICT-related disruption.

The regulation is directly relevant to covered entities, but a general overview cannot determine whether a particular organization is in scope or settle its precise duties. DORA contains detailed scope provisions, definitions, exceptions and procedures. Check the regulation and seek guidance from the competent authority responsible for the organization’s sector and jurisdiction.

Who does DORA apply to?

DORA enumerates multiple categories of financial entity. Coverage depends on those detailed provisions and any applicable exceptions; being a technology supplier to a financial firm does not, by itself, establish that the supplier is covered as a financial entity. The regulation also provides proportionality and simplified requirements in specified circumstances.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Organizations should assess their legal entity, activities and applicable scope provisions rather than relying on a broad label such as “financial services” or “fintech.” Where scope is uncertain, the relevant competent authority is the appropriate source for entity-specific supervisory guidance.

What are the main DORA requirements for financial entities?

DORA places responsibility on the covered financial entity to manage its own digital operational resilience. That work spans connected areas: governance and ICT risk management, incident classification and reporting, testing, and control of risks arising from ICT suppliers.

Govern ICT risk

A covered entity needs an ICT risk-management framework supported by documented policies, procedures, protocols and tools. The management body has responsibility for the framework and the entity’s ICT risk governance. Proportionality matters: DORA provides simplified requirements in specified circumstances, so the applicable standard should be checked against the entity’s status and the detailed rules.

Classify and report ICT incidents

DORA establishes a framework for classifying major ICT-related incidents and reporting them. Classification is not merely an internal label: the regulation’s detailed criteria and procedures determine how an incident is treated. Entities should use the applicable legal text and supervisory materials to establish their reporting process rather than assume that every outage has the same reporting status.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Test resilience

DORA requires resilience-testing programmes, with testing obligations that vary by entity type and selection. The following are legal minimum cadences, not empirical performance measures:

Testing obligation Who it applies to Cadence
Testing of ICT systems supporting critical or important functions Entities other than microenterprises At least yearly
Threat-led penetration testing (TLPT) Entities designated for this testing At least every three years

The regulation’s detailed provisions determine which systems and entities are subject to particular requirements. The yearly programme and TLPT are distinct obligations; the three-year cadence is not a substitute for the baseline testing programme.

Manage ICT supplier risk

Using an ICT provider does not transfer away a financial entity’s responsibility for managing ICT third-party risk. The entity must address relevant supplier risks and contractual arrangements as part of its own resilience framework. The specific requirements depend on the relationship and applicable provisions, so a firm should review its contracts and supplier controls against the regulation rather than treat outsourcing as an exemption.

How is oversight of critical ICT providers different?

DORA distinguishes a financial entity’s responsibility for its suppliers from EU-level oversight of ICT providers that are formally designated as critical. A provider is not subject to that oversight merely because it supplies a financial entity; designation is the relevant distinction.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Area Financial entity’s responsibility EU oversight of designated critical ICT providers
What it addresses The entity’s ICT risk, resilience and use of third-party services Oversight of ICT providers designated as critical
Who is responsible The covered financial entity remains responsible for managing its ICT third-party risk and relevant contracts The EU oversight framework applies to providers that receive the critical designation
How to interpret it Supplier oversight is part of the entity’s own DORA responsibilities Provider oversight is a separate regulatory layer, not a replacement for the entity’s duties
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How does DORA relate to NIS2?

The European Commission describes DORA as sector-specific legislation in relevant subject areas for financial entities covered by DORA. That relationship should not be read as a universal exemption from every NIS2 obligation. An organization should assess which rules apply to its particular activities and legal status, and confirm any interaction with its competent authority.

What should an organization do next?

  1. Confirm scope. Check the detailed scope provisions and exceptions in Regulation (EU) 2022/2554, then confirm uncertain cases with the competent authority.
  2. Map responsibility. Identify who in the management body oversees ICT risk and where the entity’s framework, policies and procedures are documented.
  3. Review operational processes. Check how ICT incidents are classified and reported, how resilience testing is organized, and how supplier risks and contracts are managed.
  4. Check the rules that apply to the entity. Consult the regulation and applicable implementing measures and supervisory materials for detailed definitions, thresholds, classifications and procedures.

DORA’s requirements are legal obligations, not a guarantee that incidents will be prevented. The official materials cited for this overview do not establish a DORA compliance rate or a quantified reduction in cyber incidents; such outcome figures should not be inferred from the existence of the regulation.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.