The Digital Operational Resilience Act (DORA) is the EU regulation that sets one set of rules for how financial entities manage ICT risk. It has applied since 17 January 2025. This guide explains who the Digital Operational Resilience Act covers, what its five pillars require and how to comply.
Key points
- DORA is Regulation (EU) 2022/2554. It applies directly in every EU Member State.
- It covers 20 types of financial entity, from banks and insurers to crypto-asset service providers, and their ICT suppliers.
- It has five pillars: ICT risk management, incident reporting, resilience testing, third-party risk and information sharing.
- The management body is responsible for ICT risk and must keep its knowledge up to date.
- ICT suppliers designated as critical are overseen directly by the European Supervisory Authorities.
What the Digital Operational Resilience Act is
Before DORA, each Member State and each financial sector had its own rules for ICT risk. The Digital Operational Resilience Act replaces that patchwork with one regulation. Its aim is that a financial entity can withstand, respond to and recover from ICT disruption, whether it is a cyber attack, a system failure or the failure of a supplier.
Who must comply
The Digital Operational Resilience Act applies to financial entities including:
- Credit institutions, payment institutions and electronic money institutions
- Investment firms, trading venues, central counterparties and central securities depositories
- Insurance and reinsurance undertakings and insurance intermediaries
- Fund managers and occupational pension institutions
- Crypto-asset service providers and crowdfunding service providers
- Credit rating agencies and data reporting service providers
ICT third-party service providers, such as cloud, software and data centre providers, are affected in two ways. Financial entities must pass DORA requirements to them through contracts. Providers designated as critical also come under direct oversight.
The rules are proportionate. Microenterprises and some small entities follow a simplified ICT risk management framework.
The five pillars of DORA
1. ICT risk management
Each entity needs a documented ICT risk management framework: identify ICT assets and risks, protect and prevent, detect anomalies, respond and recover, back up, learn and communicate. The management body approves the framework, oversees it and remains responsible for it.
2. ICT-related incident management and reporting
Entities must classify incidents using set criteria and report major ones to their competent authority in three stages:
| Report | Deadline |
|---|---|
| Initial notification | Within 4 hours of classifying the incident as major, and no later than 24 hours after becoming aware of it |
| Intermediate report | Within 72 hours of the initial notification |
| Final report | Within one month of the latest intermediate report |
3. Digital operational resilience testing
Entities must run a risk-based testing programme every year, covering items such as vulnerability assessments, scenario tests and performance tests. Larger and more significant entities must also carry out threat-led penetration testing at least every three years.
4. ICT third-party risk management
Entities must keep a register of all contracts with ICT providers, assess providers before signing, include mandatory terms in contracts (such as access and audit rights, service levels and exit plans) and manage concentration risk.
5. Information sharing
Entities may exchange cyber threat information and intelligence with each other inside trusted arrangements.
Enforcement and penalties
National competent authorities supervise financial entities and apply the penalties set in national law. For critical ICT third-party providers, the Lead Overseer can impose a periodic penalty payment of up to 1% of the provider’s average daily worldwide turnover, for each day of non-compliance, for up to six months.
How to comply with the Digital Operational Resilience Act
- Confirm scope and which proportionality rules apply to you.
- Run a gap analysis against the five pillars.
- Brief the management body on its responsibilities and plan its training.
- Update the ICT risk management framework and its policies.
- Build the incident classification and reporting process so that the deadlines can be met.
- Complete the register of ICT contracts and renegotiate contracts that lack the mandatory terms.
- Set the testing programme and check whether threat-led penetration testing applies to you.
- Review yearly and after every major incident.
DORA, the NIS 2 Directive and ISO standards
For financial entities, DORA applies in place of the matching NIS 2 Directive provisions. ISO/IEC 27001 supports the ICT risk management pillar, and ISO 22301 supports response, recovery and continuity. Neither replaces the regulation: the reporting deadlines, the register of contracts and the testing rules come from DORA itself.
DORA training and certification
| Course | Length | Who it is for |
|---|---|---|
| DORA Foundation | 2 days, 14 CPD credits | People who need to understand the requirements. No prerequisites. |
| DORA Lead Manager | 5 days, 31 CPD credits | People who lead DORA compliance in a financial entity or an ICT provider |
Both are listed with the other DORA training courses.
Sources: Regulation (EU) 2022/2554, the Digital Operational Resilience Act (EUR-Lex) and EIOPA’s page on DORA.
Frequently asked questions
When did the Digital Operational Resilience Act start to apply?
The regulation entered into force on 16 January 2023 and has applied since 17 January 2025. Because it is a regulation, it applies directly in every EU Member State without national laws to transpose it.
Does DORA apply to companies outside the EU?
It applies to financial entities regulated in the EU. It also reaches their ICT suppliers wherever they are based, because financial entities must put DORA terms into their contracts, and suppliers designated as critical come under direct EU oversight.
Is there a DORA certification?
There is no certification of an organization against DORA; a financial entity complies with it and is supervised by its regulator. Individuals can earn a personal credential, such as PECB Certified DORA Lead Manager, by passing an exam.
How is DORA different from the NIS 2 Directive?
The NIS 2 Directive sets cybersecurity duties across many sectors and is written into national law. DORA is a regulation for the financial sector only and is more detailed. For the financial entities it covers, DORA applies in place of the matching NIS 2 provisions.