EU Regulation 2022/2554

DORA Compliance Guide

What the Digital Operational Resilience Act requires of financial entities and their ICT providers: risk management, incident reporting, resilience testing, and third-party oversight.

Jan 17, 2025
Applies since
20 entity types
Financial entities in scope
5 pillars
Core requirement areas

What is DORA?

The Digital Operational Resilience Act (Regulation (EU) 2022/2554) is an EU regulation that sets uniform requirements for how financial entities manage information and communication technology (ICT) risk. It entered into force on January 16, 2023 and has applied since January 17, 2025. Because it is a regulation rather than a directive, it applies directly in every member state without national transposition.

DORA's premise is that financial firms are only as resilient as the technology and vendors they run on. It therefore regulates not just the firms themselves but also, for the first time, the critical ICT providers that serve them, including major cloud providers, which can be designated for direct oversight by the European Supervisory Authorities.

Who is in scope

DORA covers around twenty categories of financial entities authorized in the EU, including:

  • Credit institutions, payment institutions, and electronic money institutions
  • Investment firms and management companies (UCITS and AIF managers)
  • Crypto-asset service providers authorized under MiCA and issuers of asset-referenced tokens
  • Insurance and reinsurance undertakings and intermediaries
  • Trading venues, central counterparties, central securities depositories, and trade repositories
  • Credit rating agencies, crowdfunding service providers, and institutions for occupational retirement provision

ICT third-party service providers are also in scope: all of them indirectly through the contractual requirements their financial clients must impose, and those designated as critical ICT third-party providers directly, under an oversight framework run by the ESAs. Obligations are proportionate to size and risk profile, and microenterprises get lighter treatment.

The five pillars

1. ICT risk management (Articles 5-16)

Financial entities must maintain a documented ICT risk management framework owned by the management body, which is personally responsible for approving and overseeing it. The framework covers identification of critical functions and assets, protection and prevention measures, detection capabilities, response and recovery plans, backup and restoration policies, and learning from incidents. A simplified framework applies to smaller, lower-risk entity types.

2. Incident reporting (Articles 17-23)

Entities must classify ICT-related incidents against criteria set in regulatory technical standards and report major incidents to their competent authority in three stages:

  • Initial notification: within 4 hours of classifying the incident as major, and no later than 24 hours after becoming aware of it
  • Intermediate report: within 72 hours of the initial notification
  • Final report: within one month

Significant cyber threats may be reported voluntarily. Clients must be informed without undue delay when a major incident affects their financial interests.

3. Resilience testing (Articles 24-27)

All in-scope entities need a risk-based testing program covering vulnerability assessments, scenario-based testing, and penetration testing of critical systems at least yearly. Entities identified as significant must additionally run threat-led penetration testing (TLPT) at least every three years, following the TIBER-EU-aligned methodology, using testers meeting defined qualification requirements and covering critical third-party providers where relevant.

4. ICT third-party risk (Articles 28-44)

Entities must maintain a register of information covering all contractual arrangements with ICT providers and submit it to regulators on request. Contracts for services supporting critical or important functions must include mandatory provisions: full service descriptions, data location, audit and access rights, exit strategies, and termination rights. Concentration risk must be assessed before signing. Providers designated as critical are supervised directly by a lead overseer (EBA, ESMA, or EIOPA), which can issue recommendations and impose periodic penalty payments of up to 1% of the provider's average daily worldwide turnover for non-cooperation.

5. Information sharing (Article 45)

DORA encourages, but does not require, participation in trusted arrangements for exchanging cyber threat intelligence between financial entities.

Penalties and enforcement

Unlike GDPR, DORA does not set a single EU-wide maximum fine for financial entities. Member states define the administrative penalties and remedial measures, which must be effective, proportionate, and dissuasive; national regimes vary and can include substantial fines, public reprimands, and orders to cease conduct. Supervision runs through each entity's existing competent authority (banking, securities, or insurance supervisor).

The concrete EU-level financial penalty in the text applies to critical ICT third-party providers: periodic penalty payments of up to 1% of average daily worldwide turnover, applied daily for up to six months, for failure to comply with the lead overseer. For financial entities, the practical risk is supervisory action, remediation orders, and the management body's personal accountability for ICT risk governance.

Timeline

January 16, 2023

DORA entered into force, starting the two-year implementation period.

2023 to 2024

The European Supervisory Authorities delivered the regulatory and implementing technical standards that operationalize incident classification, the register of information, TLPT, and subcontracting rules.

January 17, 2025

DORA applies in full. Financial entities must comply and submit registers of information; designation of critical ICT third-party providers and their direct oversight followed.

Where to start

  1. Map critical or important functions and the ICT assets and vendors that support them; this classification drives most other obligations.
  2. Build the register of information for all ICT contracts in the ESA template; regulators are actively collecting it.
  3. Remediate contracts supporting critical functions to include the Article 30 mandatory provisions, including audit rights and exit plans.
  4. Stand up incident classification and reporting workflows that can hit the 4-hour and 24-hour initial deadlines, including out-of-hours coverage.
  5. Schedule the testing program: yearly testing of critical systems for everyone, and TLPT scoping if you are likely to be designated significant.
  6. Reuse existing frameworks. DORA overlaps heavily with EBA outsourcing guidelines, ISO 27001, and NIS2 controls; map what you already have before building new processes.

Related guides

Assess your DORA readiness

BD Emerson helps financial entities map critical functions, remediate ICT contracts, and build incident reporting and testing programs that meet DORA's deadlines.