The Digital Operational Resilience Act (DORA), Regulation (EU) 2022/2554, applies from January 17, 2025. It gives EU financial entities, from banks and insurers to payment institutions and crypto-asset service providers, a single set of ICT risk rules. DORA rests on five pillars: ICT risk management, incident reporting, resilience testing, ICT third-party risk management and information sharing. It also brings ICT providers designated as critical to the financial sector under EU-level oversight. With about six weeks to go, most of the detailed technical standards are final, but some are still working through adoption.
What is DORA and when does it apply?
DORA was published in the Official Journal on December 27, 2022 and entered into force on January 16, 2023. Its obligations apply from January 17, 2025. Because it's a regulation, it applies directly in every member state without national transposition.
Before DORA, ICT risk rules for financial firms were spread across sector laws and supervisory guidelines. DORA replaces that patchwork, and for the entities it covers it takes precedence over the NIS2 Directive's security and reporting rules.
The full text is on EUR-Lex.
Who does DORA apply to?
Article 2 lists 20 types of financial entity, including:
- Credit institutions, payment institutions, account information service providers and e-money institutions
- Investment firms, trading venues, central counterparties, central securities depositories and trade repositories
- Crypto-asset service providers and issuers of asset-referenced tokens
- Managers of alternative investment funds and UCITS management companies
- Insurance and reinsurance undertakings, and insurance intermediaries
- Institutions for occupational retirement provision
- Credit rating agencies, crowdfunding service providers and administrators of critical benchmarks
Some very small entities are excluded. Article 4 makes proportionality a general principle, so the size, risk profile and complexity of the entity shape how it implements the rules. Article 16 sets out a lighter, simplified ICT risk management framework for certain entities, such as small and non-interconnected investment firms and some exempted payment and e-money institutions.
ICT third-party service providers are also in scope, but mostly indirectly. They'll feel DORA through their financial-sector customers' contracts, and those designated as critical fall under direct EU oversight.
What are the five pillars of DORA?
1. ICT risk management (Articles 5–16)
The management body "bears the ultimate responsibility" for managing ICT risk. It must approve the digital operational resilience strategy, allocate budget, and keep its own ICT risk knowledge current through regular training.
Entities need a documented ICT risk management framework, reviewed at least once a year and after major incidents. It has to cover identification of ICT assets and dependencies, protection and prevention, detection of anomalous activity, response and recovery, backup and restoration, learning from incidents, and crisis communication. ICT business continuity and response and recovery plans must be tested at least yearly.
Delegated Regulation (EU) 2024/1774 fills in the detail on tools, methods, processes and policies, including the simplified framework.
2. ICT-related incident management and reporting (Articles 17–23)
Entities must detect, manage, log and classify ICT-related incidents. Those classified as major under the criteria in Delegated Regulation (EU) 2024/1772 must be reported to the competent authority in three stages: an initial notification, an intermediate report and a final report. Where a major incident affects clients' financial interests, you must inform them without undue delay.
The exact timelines sit in a separate standard that hasn't yet been published in the Official Journal. The ESAs' final draft, submitted in July 2024, proposes:
| Report | Proposed deadline |
|---|---|
| Initial notification | Within 4 hours of classifying the incident as major, and no later than 24 hours after becoming aware of it |
| Intermediate report | Within 72 hours of the initial notification |
| Final report | Within one month of the latest intermediate report |
Reporting significant cyber threats is voluntary. Plan your runbooks around the draft timelines, and confirm them once the final text is published.
3. Digital operational resilience testing (Articles 24–27)
Every financial entity other than a microenterprise needs a risk-based testing program. DORA lists the tools it expects, including vulnerability assessments and scans, network security assessments, gap analyses, source code reviews where feasible, scenario-based tests, performance testing, end-to-end testing and penetration testing. ICT systems and applications supporting critical or important functions must be tested at least yearly.
Some entities must also carry out threat-led penetration testing (TLPT) at least every three years. Competent authorities identify these entities based on impact, financial stability concerns and ICT risk profile. TLPT covers several or all critical or important functions on live production systems, including those supported by ICT third-party providers. The detailed TLPT standard, aligned with the TIBER-EU framework, was submitted as a final draft in July 2024.
4. ICT third-party risk management (Articles 28–30)
This pillar will likely take the most work for mid-sized firms. You need a strategy on ICT third-party risk and must assess risks, including concentration risk, and carry out due diligence before signing. Article 30 lists mandatory contract terms, such as service descriptions, data locations, access and return of data, incident assistance, cooperation with authorities and termination rights. Contracts for critical or important functions need more, including precise service levels, audit and access rights, participation in TLPT, and exit strategies with a transition period.
You must also maintain a register of information covering all contractual arrangements for ICT services, at entity level and at sub-consolidated and consolidated levels. You'll report on new arrangements to your competent authority at least yearly and must provide the full register on request. The templates are in Implementing Regulation (EU) 2024/2956, published in the Official Journal at the start of December.
Exit strategies need to be documented and tested for arrangements supporting critical or important functions, so you can leave a provider without disrupting services or breaching regulatory requirements.
5. Information sharing (Article 45)
Financial entities may set up arrangements to share cyber threat information and intelligence, such as indicators of compromise and tactics, with each other. Sharing must happen within trusted communities and protect sensitive data. If you join one of these arrangements, you have to notify your competent authority.
How does oversight of critical ICT third-party providers work?
DORA gives EU supervisors direct oversight of ICT providers that are critical to the financial sector. The European Supervisory Authorities (EBA, EIOPA and ESMA), acting through their Joint Committee, will designate critical ICT third-party service providers. Article 31 lists the criteria: systemic impact if the provider failed, the importance of the financial entities that rely on it, the degree of reliance for critical or important functions, and how hard the provider would be to replace. Delegated Regulation (EU) 2024/1502 specifies these criteria further.
Each critical provider gets a Lead Overseer, one of the three ESAs. The Lead Overseer can request information, run investigations and inspections, and issue recommendations. It can also impose periodic penalty payments of up to 1% of the provider's average daily worldwide turnover, daily for up to six months, to force compliance. Delegated Regulation (EU) 2024/1505 sets the oversight fees critical providers will pay.
Financial entities may only use a critical provider established outside the EU if it sets up an EU subsidiary within 12 months of designation. For financial entities, this oversight is no substitute for their own third-party risk management. You remain responsible for your providers.
Which DORA technical standards have been adopted?
DORA delegates much of the detail to regulatory and implementing technical standards (RTS and ITS). The ESAs delivered them in two batches, in January and July 2024. Here's where the main ones stand at the time of writing.
| Standard | Status |
|---|---|
| ICT risk management framework and simplified framework (RTS) | Delegated Regulation (EU) 2024/1774 |
| Classification of ICT-related incidents and cyber threats (RTS) | Delegated Regulation (EU) 2024/1772 |
| Policy on ICT services supporting critical or important functions (RTS) | Delegated Regulation (EU) 2024/1773 |
| Register of information templates (ITS) | Implementing Regulation (EU) 2024/2956 |
| Criteria for designating critical ICT providers | Delegated Regulation (EU) 2024/1502 |
| Oversight fees | Delegated Regulation (EU) 2024/1505 |
| Incident reporting content, timelines and templates (RTS and ITS) | Final drafts submitted July 2024; not yet in the Official Journal |
| Threat-led penetration testing (RTS) | Final draft submitted July 2024 |
| Subcontracting of ICT services for critical or important functions (RTS) | Final draft submitted July 2024 |
| Oversight activities and joint examination teams (RTS) | Final drafts submitted July 2024 |
The first batch's three delegated regulations entered into force in July 2024. Build to the final drafts for the rest, but expect possible changes before publication.
DORA readiness checklist
With January 17 close, these are the items we'd confirm first:
- Scope and proportionality. Confirm which entity types in your group are covered and whether the simplified framework applies.
- Management body. Board approval of the digital operational resilience strategy and ICT risk framework is documented, and training is scheduled.
- ICT risk framework. Mapped against Delegated Regulation 2024/1774, with a review cycle of at least once a year.
- Asset and dependency inventory. Critical or important functions are mapped to the systems, data and providers that support them.
- Incident classification. Your triage process applies the 2024/1772 criteria and thresholds, and someone owns the "major" decision.
- Reporting runbook. Contacts, channels and templates are ready for the initial, intermediate and final reports.
- Continuity testing. ICT business continuity and response and recovery plans have been tested within the last year.
- Testing program. An annual plan covers systems supporting critical or important functions, and you know whether TLPT applies to you.
- Register of information. Populated in the 2024/2956 format, reconciled with procurement and finance records, and assigned an owner.
- Contract remediation. A plan to update ICT contracts to include Article 30 terms, starting with critical or important functions.
- Exit strategies. Documented for arrangements supporting critical or important functions.
Frequently asked questions
Does DORA replace NIS2 for financial entities?
For the entities DORA covers, yes, as far as ICT risk management and incident reporting go. DORA is the sector-specific law that applies in place of NIS2's equivalent requirements.
We're an ICT provider to banks. Does DORA apply to us?
Not directly, unless you're designated as critical. Your financial-sector customers will still need DORA-compliant contract terms, audit rights, incident assistance and, in some cases, participation in their testing.
What are the penalties for financial entities under DORA?
DORA leaves administrative penalties and remedial measures for financial entities to member states and their competent authorities. It doesn't set a single EU-wide fine amount for them. The 1% daily turnover penalty applies to critical ICT providers under oversight.
Key takeaways
- DORA applies from January 17, 2025 and binds financial entities directly, with no national transposition.
- The five pillars are ICT risk management, incident reporting, resilience testing, ICT third-party risk management and information sharing.
- All first-batch standards are final. The incident reporting and TLPT standards are still going through adoption.
- The register of information and contract remediation tend to be the most labor-intensive items, so start there if you haven't.
- Critical ICT providers will face direct oversight, but that doesn't reduce your own responsibility for third-party risk.
This post explains the Regulation and isn't legal advice. Confirm how it applies to your entity with counsel and your competent authority.