EU Regulatory Domain
Regulation (EU) 2022/2554 (DORA): applicable to EU financial entities since 17 January 2025.
Key facts
Regulation (EU) 2022/2554 has applied directly to EU financial entities since 17 January 2025.
Credit, payment and e-money institutions, investment firms, insurers and crypto-asset service providers are among the categories covered.
ICT risk management, incident reporting, resilience testing, ICT third-party risk and information sharing form the framework.
Entities identified by the authorities must carry out threat-led penetration testing at least every three years.
The Digital Operational Resilience Act has applied since 17 January 2025. It creates a single, directly applicable framework for managing ICT risk in the EU financial sector, so that financial entities can withstand, respond to and recover from ICT disruptions. For the entities it covers, DORA operates as the specific regime for digital operational resilience in relation to NIS2.
DORA applies to around twenty categories of financial entities, including credit institutions, payment and electronic money institutions, investment firms, crypto-asset service providers, trading venues, central securities depositories and central counterparties, management companies, insurance and reinsurance undertakings, institutions for occupational retirement provision and crowdfunding service providers. Requirements are applied proportionately, and a simplified framework exists for certain smaller entities.
ICT risk management (Articles 5 to 16): a documented framework under the ultimate responsibility of the management body, with an independent control function for ICT risk;
ICT-related incident management and reporting (Articles 17 to 23): classification of incidents and reporting of major ICT-related incidents to the competent authority, in initial, intermediate and final reports;
digital operational resilience testing (Articles 24 to 27): a risk-based testing programme and, for entities identified by the authorities, threat-led penetration testing at least every three years;
ICT third-party risk (Articles 28 to 30): a strategy for ICT third-party risk, a register of information on all contractual arrangements, mandatory contractual provisions and exit strategies;
information sharing (Article 45): voluntary arrangements for exchanging cyber-threat intelligence.
The European Supervisory Authorities designated the first critical ICT third-party providers in November 2025. A Lead Overseer now supervises each of them directly, but financial entities remain fully responsible for managing the risk of the services they use.
Day-to-day supervision is carried out by national competent authorities, such as Banco de Portugal, the CMVM and the ASF in Portugal, in cooperation with the EBA, ESMA and EIOPA.
Compliance Assessment: a DORA gap analysis across the five pillars;
Implementation Kits: the DORA kit with the ICT risk framework, incident classification and register-of-information templates;
Training & Capacity: training for management bodies on their ICT risk responsibilities;
Alerts & Repository: monitoring of technical standards and supervisory guidance.
Related domains: Cybersecurity (NIS2) · Third-Party & Supply Chain · Anti-Money Laundering · Corporate Governance
Official text: Regulation (EU) 2022/2554 on EUR-Lex
General information as of October 2026; it does not constitute legal advice. Confirm the applicable requirements with the competent authorities.
Related domains
Request a free gap analysis of your ICT risk framework, incident process and third-party register.