EU Regulatory Domain

Digital Operational Resilience

Regulation (EU) 2022/2554 (DORA): applicable to EU financial entities since 17 January 2025.

Key facts

DORA at a glance

Applicable since 2025

Regulation (EU) 2022/2554 has applied directly to EU financial entities since 17 January 2025.

Around twenty entity types

Credit, payment and e-money institutions, investment firms, insurers and crypto-asset service providers are among the categories covered.

Five pillars

ICT risk management, incident reporting, resilience testing, ICT third-party risk and information sharing form the framework.

Threat-led testing

Entities identified by the authorities must carry out threat-led penetration testing at least every three years.

Overview

The Digital Operational Resilience Act has applied since 17 January 2025. It creates a single, directly applicable framework for managing ICT risk in the EU financial sector, so that financial entities can withstand, respond to and recover from ICT disruptions. For the entities it covers, DORA operates as the specific regime for digital operational resilience in relation to NIS2.

Who is in scope

DORA applies to around twenty categories of financial entities, including credit institutions, payment and electronic money institutions, investment firms, crypto-asset service providers, trading venues, central securities depositories and central counterparties, management companies, insurance and reinsurance undertakings, institutions for occupational retirement provision and crowdfunding service providers. Requirements are applied proportionately, and a simplified framework exists for certain smaller entities.

The five pillars

  • ICT risk management (Articles 5 to 16): a documented framework under the ultimate responsibility of the management body, with an independent control function for ICT risk;

  • ICT-related incident management and reporting (Articles 17 to 23): classification of incidents and reporting of major ICT-related incidents to the competent authority, in initial, intermediate and final reports;

  • digital operational resilience testing (Articles 24 to 27): a risk-based testing programme and, for entities identified by the authorities, threat-led penetration testing at least every three years;

  • ICT third-party risk (Articles 28 to 30): a strategy for ICT third-party risk, a register of information on all contractual arrangements, mandatory contractual provisions and exit strategies;

  • information sharing (Article 45): voluntary arrangements for exchanging cyber-threat intelligence.

Oversight of critical ICT providers

The European Supervisory Authorities designated the first critical ICT third-party providers in November 2025. A Lead Overseer now supervises each of them directly, but financial entities remain fully responsible for managing the risk of the services they use.

Supervision

Day-to-day supervision is carried out by national competent authorities, such as Banco de Portugal, the CMVM and the ASF in Portugal, in cooperation with the EBA, ESMA and EIOPA.

How we can help

Related domains: Cybersecurity (NIS2) · Third-Party & Supply Chain · Anti-Money Laundering · Corporate Governance

Official text: Regulation (EU) 2022/2554 on EUR-Lex

General information as of October 2026; it does not constitute legal advice. Confirm the applicable requirements with the competent authorities.

Related domains

Where DORA meets other rules

Cybersecurity (NIS2)

The cross-sector cybersecurity regime that DORA specialises for finance

Third-Party & Supply Chain

ICT third-party risk, the register of information and exit strategies

Anti-Money Laundering

Parallel compliance obligations for the same financial entities

Assess your DORA readiness across the five pillars

Request a free gap analysis of your ICT risk framework, incident process and third-party register.