Regulations › European Union

DORA

Digital Operational Resilience Act, Regulation (EU) 2022/2554

In force security financial third party
WhenIn effect since 17 January 2025
Who enforces itEuropean and national financial supervisors
Who it applies toEU financial entities and their critical ICT third-party providers.

ICT risk management, incident reporting, resilience testing and a register of ICT third-party arrangements for the financial sector.

The law in brief

DORA, the Digital Operational Resilience Act, sets one EU-wide rulebook for how financial entities manage information and communication technology risk. It covers risk management, incident reporting, resilience testing and, unusually, the ICT providers the financial sector depends on.

It is a regulation, so it applies directly across the EU, and it has applied since 17 January 2025. Detailed technical standards fill in much of the practice.

Who it applies to

  • Financial entities, including credit institutions, payment and e-money institutions, investment firms, crypto-asset service providers, trading venues, insurers and reinsurers, and many others listed in Article 2.
  • ICT third-party service providers serving them, with the most critical designated for direct EU oversight.
  • A simplified framework applies to some smaller and less interconnected entities (Art. 16).

What it requires

An ICT risk-management framework

Keep a sound, documented framework to identify, protect against, detect, respond to and recover from ICT risk. The management body is ultimately responsible for it.

Report major ICT-related incidents

Classify ICT-related incidents against the regulatory criteria and report major ones to the competent authority in initial, intermediate and final reports, within the time limits set by the technical standards.

Resilience testing

Run a testing program appropriate to your size and risk, and, if selected by your authority, threat-led penetration testing at least every three years.

Manage ICT third-party risk

Keep a register of information on every ICT third-party arrangement, assess concentration risk, and have exit strategies for services supporting critical or important functions.

Required contract terms

Include the terms DORA lists in ICT service contracts, such as service descriptions, locations of processing, security, access and audit rights, termination rights and, for critical functions, exit support.

Enforcement and penalties

Member states set administrative penalties and remedial measures (Art. 50). Critical ICT third-party providers overseen at EU level can face periodic penalty payments of up to 1% of their average daily worldwide turnover for each day of non-compliance, for up to six months (Art. 35).

What to do first

  1. Confirm your entity type, and whether the simplified framework applies.
  2. Have your management body approve the ICT risk-management framework and own it.
  3. Build the register of information on all ICT third-party arrangements.
  4. Classify incidents against the regulatory criteria and rehearse the reporting timeline for major incidents.
  5. Update ICT contracts with the Article 30 clauses and exit strategies.
  6. Plan resilience testing, and threat-led penetration testing if you are selected.

Checked against the official text on 28 September 2026. Quotations are the operative words of the law, linked to the article they come from; the official text is the authority. This brief is written by the Association for practitioners and is not legal advice.

Recent developments

Nothing reported yet. Regulatory Watch lists new rules, enforcement and court decisions as they arrive.

Sources