Formally Regulation (EU) 2022/2554, it has applied since 17 January 2025 and is directly applicable in EU Member States.
DORA is concerned with whether a financial entity can continue delivering important services through ICT disruption — not only whether it can prevent cyberattacks. It applies to a wide range of regulated financial entities, including banks, payment and electronic-money institutions, investment firms, insurers, many pension and fund-management entities, crypto-asset service providers, trading venues, and other categories defined in Article 2. Some small or specialized entities are excluded or subject to simplified requirements, so scope must be assessed against the legal text and applicable sector rules.
Key points
ICT risk managementManagement bodies have defined governance duties. Financial entities must maintain a documented framework covering identification, protection and prevention, detection, response and recovery, backup and restoration, learning, communication, and continuous improvement.
Incident management and reportingEntities must classify ICT-related incidents and report those meeting the criteria for a major incident to the relevant competent authority. The current process requires an initial notification within four hours after classification as major and no later than 24 hours after awareness, an intermediate report within 72 hours of the initial notification, and a final report within one month of the intermediate or latest updated intermediate report. DORA also provides for voluntary notification of significant cyber threats.
Resilience testingThe testing program must be risk-based and cover relevant systems and controls. Certain entities identified by competent authorities must perform threat-led penetration testing at least every three years, subject to the detailed legal and technical requirements. A competent authority may adjust that frequency according to the entity’s risk profile and operational circumstances.
ICT third-party riskFinancial entities remain responsible when they use external ICT services. DORA requires due diligence, contractual provisions, exit planning, concentration-risk consideration, and a register of contractual arrangements. Stronger requirements apply where services support critical or important functions.
Critical provider oversightThe European Supervisory Authorities can designate certain ICT third-party service providers as critical and oversee them at EU level. This oversight does not replace each financial entity’s responsibility for its own providers and arrangements.
Information sharingFinancial entities may exchange cyber-threat information within trusted communities when the arrangements protect confidentiality, personal data, and sensitive business information.