Skip to content
atlas

DORA

Also known as: Digital Operational Resilience Act, Regulation (EU) 2022/2554

The EU law that makes banks, insurers and other financial firms able to keep running through IT failures and cyber attacks.

Draft - this entry has not been reviewed yet.

Formal

An EU regulation of 14 December 2022, applying directly in every member state from 17 January 2025, that sets one set of rules for the financial sector on IT risk management, incident reporting, testing, and control of IT suppliers such as cloud providers.

In plain English

Like fire rules that ask a bank not just to hang smoke alarms, but to prove in a drill that it can get everyone out, keep serving customers and tell the fire service what happened.

In practice

The IT risk manager at a Danish pension fund keeps a register of every IT supplier contract, tests switching over to the backup site each year and, after a major outage, sends the first report to the Danish financial supervisor within hours.

Why it matters

Payments, savings and trading now depend almost wholly on IT and a few shared cloud providers, so one failure can spread across the whole financial system; DORA makes firms plan for that and lets supervisors check.

Technical deep dive

Regulation (EU) 2022/2554 covers some twenty categories of financial entity listed in Art. 2, from credit institutions, investment firms and insurers to payment and e-money institutions, crypto-asset service providers, trading venues and central counterparties, and is accompanied by an amending directive (EU) 2022/2556 that aligns sectoral directives. Most of the operational detail sits in level-2 acts: Commission Delegated Regulation (EU) 2024/1774 on the ICT risk-management framework (including logging and log retention), 2024/1772 on incident classification criteria, 2025/301 on the content and timing of incident reports, and implementing standards for the register of information. Proportionality is built in via Art. 4, and Art. 16 gives small and non-interconnected entities a simplified risk-management framework; microenterprises are relieved of several requirements.

The regulation has five pillars. ICT risk management (Arts. 5-16) makes the management body ultimately responsible (Art. 5(2)) and requires an ICT risk-management framework covering identification of assets and dependencies, protection, detection, response and recovery, backup and restoration, and learning. Incident management (Arts. 17-23) requires classification of ICT-related incidents against quantitative and qualitative criteria (clients affected, duration, geographic spread, data losses, criticality of services, economic impact); for a major incident, the initial notification is due within four hours of classifying it as major and no later than 24 hours after becoming aware, the intermediate report within 72 hours of the initial notification, and the final report within one month of the latest intermediate report. Digital operational resilience testing (Arts. 24-27) requires a risk-based testing programme with at least yearly testing of critical systems, and threat-led penetration testing (TLPT) on live production systems at least every three years for entities selected by the competent authority, modelled on the TIBER-EU framework.

ICT third-party risk (Arts. 28-30) requires a register of information on all contractual arrangements with ICT providers, pre-contract due diligence, exit strategies, and the mandatory contract clauses in Art. 30, which are stricter for services supporting critical or important functions. The oversight framework (Arts. 31-44) lets the European Supervisory Authorities designate critical ICT third-party providers and oversee them through a Lead Overseer; the first list of 19 providers, including major hyperscalers, was published on 18 November 2025 and is to be updated yearly. The fifth pillar, Art. 45, allows voluntary cyber threat information sharing.

DORA is lex specialis to NIS2 for financial entities, and NIS2 Art. 4 defers to it, so a Danish bank reports major ICT incidents to Finanstilsynet under DORA rather than following NIS2 Art. 23 timelines. A common misreading is that DORA applies to cloud providers directly: it binds the financial entity, and only designated CTPPs are reached through ESA oversight; other suppliers are affected indirectly through the contract terms their customers must impose.

Relationships

A kind of
EU regulation
Don't confuse with
NIS2 Directive

Sources & further reading

Standards & official texts

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Mentioned in

Check yourself

Loading…

Atlas is in beta.