Compliance & regulation
The EU law that makes banks, insurers and other financial firms able to keep running through IT failures and cyber attacks.
Formal
An EU regulation of 14 December 2022, applying directly in every member state from 17 January 2025, that sets one set of rules for the financial sector on IT risk management, incident reporting, testing, and control of IT suppliers such as cloud providers.
In plain English
Like fire rules that ask a bank not just to hang smoke alarms, but to prove in a drill that it can get everyone out, keep serving customers and tell the fire service what happened.
In practice
The IT risk manager at a Danish pension fund keeps a register of every IT supplier contract, tests switching over to the backup site each year and, after a major outage, sends the first report to the Danish financial supervisor within hours.
Why it matters
Payments, savings and trading now depend almost wholly on IT and a few shared cloud providers, so one failure can spread across the whole financial system; DORA makes firms plan for that and lets supervisors check.