DORA is the EU Digital Operational Resilience Act, Regulation (EU) 2022/2554. It has applied since 17 January 2025 and sets common requirements for ICT risk management, incident reporting, resilience testing, information sharing and third-party ICT risk in the financial sector.
DORA directly applies to specified financial entities and also shapes their contracts and oversight of ICT providers. The precise obligations depend on entity type, size, role and the associated technical standards.
Who does DORA apply to?
DORA covers many financial entities, including credit and payment institutions, investment firms, insurers, certain managers and crypto-asset service providers. It also names ICT providers and data services relevant to the financial system. Not every obligation applies at the same depth: the regulation includes proportionality and simplified arrangements. Classification therefore requires the exact entity type and applicable regulatory and implementing technical standards.
What are the main areas?
- - Governance and an ICT risk-management framework.
- - Classification and reporting of major ICT-related incidents.
- - Digital operational resilience testing, including TLPT for designated entities.
- - Contractual management and oversight of ICT third-party risk.
| Area | Practical question | Typical evidence |
|---|---|---|
| ICT risk | Which systems support critical functions? | Inventory, risk assessments, policies |
| Incidents | How are incidents detected and reported? | Playbooks, tickets, exercises |
| Testing | Do protection and recovery work? | Test plans, findings, retests |
| Third parties | Which external ICT services are critical? | Register of information, contracts, exit plans |
How does ICT risk management work?
Financial entities need a documented ICT risk-management framework under the responsibility of the management body. It connects strategy, roles, assets, protection, monitoring, response, recovery and continuous improvement. Mapping technical systems and external services to critical or important functions is central. Without that relationship, the organization cannot assess the business impact of failure or set defensible priorities.
- Identify:
record assets, owners, dependencies and risks. - Protect:
secure access, changes, networks, data and development. - Detect:
identify anomalies, performance problems and security events promptly. - Respond and recover:
contain incidents and restore functions within defined objectives. - Learn:
use tests and incidents to improve controls with evidence.
How are ICT incidents handled?
ICT-related incidents must be recorded and classified against defined criteria. Major incidents are reported through the competent supervisory process. Classification considers affected clients, duration, geographic spread, data loss, service criticality and economic impact. Technical detection, business impact, legal assessment and communications therefore need to work together before an incident occurs.
Why are technical alerts not enough?
A SIEM alert does not initially know how many clients are affected or whether the event is reportable. Conversely, a prolonged outage without a visible attack may still meet reporting criteria. A DORA-ready process adds business and regulatory criteria to technical severity, documents decisions and supports updated intermediate and final reports.
Which resilience tests are required?
The testing programme identifies weaknesses in prevention, detection, response and recovery. Depending on risk, it includes vulnerability assessments, configuration reviews, scenario-based tests, penetration tests, recovery tests and exercises. Findings have to be prioritized, remediated and retested. Testing is a recurring improvement process, not a one-off audit.
Threat-led penetration testing (TLPT)
Certain entities selected by the competent authority must conduct threat-led penetration testing at least every three years. Scenarios use current threat intelligence and test critical functions as realistically as possible. Unlike an ordinary penetration test, TLPT also evaluates detection and response and may include relevant ICT providers. TIBER-EU provides an established European framework for this work.
What applies to ICT providers?
The financial entity remains accountable when cloud, software or operations are outsourced. Risks and concentration must be assessed before contracting. Agreements need defined services, security and notification duties, access and audit rights, subcontracting rules, data locations, incident assistance, termination and exit provisions. Contractual ICT relationships are recorded in a register of information.
How is DORA implemented?
- Identify covered entities, critical functions and accountable management bodies.
- Map assets, processes, data flows and ICT providers to those functions.
- Assess risk management, incident handling, testing and third-party controls against DORA and the RTS/ITS.
- Organize the register of information and contract remediation with procurement, legal and business owners.
- Exercise resilience and reporting, remediate findings and report progress to management.
DORA, NIS2 and TIBER-EU
DORA is the sector-specific digital operational resilience framework for covered financial entities. NIS2 has a broader cross-sector approach. TIBER-EU is not a general compliance regulation but a framework for threat-led testing. The three terms should not be used interchangeably.
Thank you for your feedback! We will review it and optimize this content.