What is DORA? A guide to the Digital Operational Resilience Act.

DORA is the EU regulation on digital operational resilience for financial entities. Here are its five pillars, who it covers, and how to comply.

The Digital Operational Resilience Act (DORA), Regulation (EU) 2022/2554, is an EU regulation that sets one set of rules for how financial entities manage information and communication technology (ICT) risk. It covers ICT risk management, incident reporting, resilience testing, oversight of ICT third-party providers, and information sharing. DORA has applied since January 17, 2025, to banks, insurers, investment firms, payment and crypto-asset service providers, and many other financial entities in the EU.

Why DORA exists

Before DORA, EU financial rules on ICT risk were spread across sector guidelines and national laws, and they covered some firms far more closely than others. At the same time, banks, insurers, and investment firms came to depend on a small number of cloud and technology providers. DORA is part of the EU's Digital Finance Package. It replaces the patchwork with one regulation that applies in every member state and, for the first time, gives EU supervisors direct oversight of the most important technology providers to the sector.

What ICT means

ICT stands for information and communication technology. Under DORA it covers the hardware, software, networks, data, and services that a financial entity uses to run its business, whether it runs them itself or buys them from a provider. In practice, that means almost every system a modern financial firm relies on.

Who DORA applies to

DORA lists 20 types of financial entities, plus ICT third-party service providers. The main groups are:

  • Credit institutions (banks).
  • Payment institutions, electronic money institutions, and account information service providers.
  • Investment firms, trading venues, central counterparties, and central securities depositories.
  • Crypto-asset service providers and issuers of asset-referenced tokens.
  • Insurance and reinsurance undertakings and intermediaries, and occupational pension funds (IORPs).
  • Asset managers, including UCITS management companies and alternative investment fund managers.
  • Credit rating agencies, crowdfunding service providers, trade and securitisation repositories, and data reporting service providers.
  • ICT third-party service providers, with direct oversight for those designated as critical.

Microenterprises and some smaller firms can use a simplified ICT risk management framework. The rules are applied in proportion to each firm's size, risk profile, and complexity.

The five pillars

PillarWhat it requiresDORA articles
ICT risk managementA documented framework, owned by the management body, to identify, protect, detect, respond, and recoverArticles 5 to 16
ICT incident management and reportingClassify ICT incidents and report major ones to your competent authority on fixed deadlinesArticles 17 to 23
Digital operational resilience testingA risk-based testing program, and threat-led penetration testing (TLPT) for firms identified by supervisorsArticles 24 to 27
ICT third-party riskManage risk from ICT providers across the contract lifecycle and keep a register of informationArticles 28 to 44
Information sharingVoluntary arrangements to share cyber threat intelligence with other financial entitiesArticle 45

1. ICT risk management

The management body (the board and senior management) is responsible for the ICT risk management framework and must approve it, fund it, and keep its knowledge of ICT risk current. The framework covers the familiar cycle: identify ICT assets and risks, protect and prevent, detect anomalies, respond and recover through business continuity and ICT response and recovery plans, and learn from incidents. It must be reviewed at least once a year and after major incidents. Firms that already run to NIST CSF 2.0 or ISO/IEC 27001 will recognize most of it.

2. Incident reporting

Financial entities classify ICT-related incidents using criteria set in the technical standards, such as clients affected, duration, geographic spread, data losses, and economic impact. Major incidents must be reported to the competent authority in three stages:

ReportDeadline
Initial notificationWithin 4 hours of classifying the incident as major, and no later than 24 hours after becoming aware of it
Intermediate reportWithin 72 hours of the initial notification, and updated as the situation changes
Final reportWithin one month of the latest intermediate report, with root cause and lessons learned

Significant cyber threats can be reported voluntarily. Clients must be told without undue delay when a major incident affects their financial interests.

3. Resilience testing

Every in-scope firm needs a testing program that fits its size and risk: vulnerability assessments and scans, network security assessments, scenario-based tests, source code reviews where relevant, and penetration tests. Firms that supervisors identify as significant must also run threat-led penetration testing (TLPT) on live production systems at least every three years, following the TIBER-EU approach.

4. ICT third-party risk

This is where DORA asks the most of many firms. Financial entities must have a strategy for ICT third-party risk, assess providers before contracting, include specific terms in contracts (service descriptions, locations, security, audit rights, termination rights, and exit support), and keep exit plans for providers that support critical or important functions.

Each firm also keeps a register of information listing all of its contractual arrangements with ICT providers, in a standard format that supervisors collect. The first registers were submitted in 2025.

At EU level, the European Supervisory Authorities (EBA, EIOPA, and ESMA) designate critical ICT third-party providers (CTPPs) and oversee them directly through a Lead Overseer. The first list of designated CTPPs was published in November 2025.

5. Information sharing

DORA encourages financial entities to share cyber threat information and intelligence with each other through trusted communities, as long as they protect personal and confidential data. Firms must notify their competent authority when they join such an arrangement.

DORA compared with US rules

DORAUS equivalents
ScopeOne regulation across the EU financial sectorRules vary by sector and state, such as NYDFS 23 NYCRR 500, GLBA, and FFIEC guidance
Incident reportingInitial notice within 4 hours of classifying a major incident, and within 24 hours of awarenessNYDFS 500 requires notice within 72 hours. Bank regulators require notice of significant incidents within 36 hours.
Third partiesRegister of information, mandatory contract terms, exit plans2023 Interagency Guidance on Third-Party Relationships for banks
Oversight of providersDirect EU oversight of critical ICT providersNo direct equivalent
TestingTLPT for significant firms every three yearsPenetration testing required by NYDFS 500 and expected by examiners

How to get to DORA compliance

  1. Confirm scopeIdentify which entities in your group are in scope and which functions are critical or important.
  2. Gap assessmentAssess your current ICT risk management, incident, testing, and third-party processes against DORA and the technical standards.
  3. Update the frameworkClose gaps in policies, roles, and management body oversight, and document the ICT risk management framework.
  4. Build the register of informationInventory every ICT third-party arrangement and map it to the functions it supports.
  5. Fix contractsAdd the required terms to contracts with ICT providers, starting with those supporting critical functions.
  6. Prepare incident reportingSet classification criteria, reporting workflows, and templates so the 4-hour clock can be met.
  7. Plan testingSet a testing program and, if identified, prepare for TLPT.
  8. Monitor and reportKeep evidence current and report status to the management body on a schedule.

How TruOps helps

TruOps runs a DORA assessment pre-filled from your policies and past assessments, with a source behind each answer. Your ICT providers are tiered and assessed in the vendor risk module, which also keeps the data you need for the register of information. The same controls and evidence count toward ISO 27001, NIST CSF, and NIS2, and gaps become findings with recommended fixes. People approve every answer.

Questions

When did DORA start to apply?

DORA entered into force on January 16, 2023, and has applied since January 17, 2025.

Does DORA apply to companies outside the EU?

It applies to financial entities authorized in the EU. Non-EU technology providers are affected when they serve EU financial entities, through contract requirements, and directly if they are designated as critical ICT third-party providers.

What is the register of information?

A standard-format record of every contractual arrangement a financial entity has with ICT third-party service providers, which supervisors collect and use to assess concentration risk.

What is TLPT?

Threat-led penetration testing: a test of live production systems that simulates the tactics of real attackers, based on threat intelligence. DORA requires it at least every three years for firms that supervisors identify.

How does DORA relate to NIS2?

Both are EU cybersecurity laws. DORA is the specific law for the financial sector, and for financial entities it takes precedence where the two overlap.

See it run on your own data.

Book 30 minutes with a GRC specialist. Bring a real document, like a SOC 2 report, risk register, or vendor list (redacted is fine), and we'll show TruOps 2.0 working on it.