# What is the Digital Operational Resilience Act (DORA)?

> The Digital Operational Resilience Act (DORA) is the European Union regulation that establishes a common framework for managing information and communication technology risk in the financial sector.

- Canonical URL: https://yellowcube.eu/glossary/digital-operational-resilience-act/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

Formally Regulation (EU) 2022/2554, it has applied since 17 January 2025 and is directly applicable in EU Member States.

DORA is concerned with whether a financial entity can continue delivering important services through ICT disruption — not only whether it can prevent cyberattacks. It applies to a wide range of regulated financial entities, including banks, payment and electronic-money institutions, investment firms, insurers, many pension and fund-management entities, crypto-asset service providers, trading venues, and other categories defined in Article 2. Some small or specialized entities are excluded or subject to simplified requirements, so scope must be assessed against the legal text and applicable sector rules.

### Key points

- **ICT risk management:** Management bodies have defined governance duties. Financial entities must maintain a documented framework covering identification, protection and prevention, detection, response and recovery, backup and restoration, learning, communication, and continuous improvement.
- **Incident management and reporting:** Entities must classify ICT-related incidents and report those meeting the criteria for a major incident to the relevant competent authority. The current process requires an initial notification within four hours after classification as major and no later than 24 hours after awareness, an intermediate report within 72 hours of the initial notification, and a final report within one month of the intermediate or latest updated intermediate report. DORA also provides for voluntary notification of significant cyber threats.
- **Resilience testing:** The testing program must be risk-based and cover relevant systems and controls. Certain entities identified by competent authorities must perform threat-led penetration testing at least every three years, subject to the detailed legal and technical requirements. A competent authority may adjust that frequency according to the entity’s risk profile and operational circumstances.
- **ICT third-party risk:** Financial entities remain responsible when they use external ICT services. DORA requires due diligence, contractual provisions, exit planning, concentration-risk consideration, and a register of contractual arrangements. Stronger requirements apply where services support critical or important functions.
- **Critical provider oversight:** The European Supervisory Authorities can designate certain ICT third-party service providers as critical and oversee them at EU level. This oversight does not replace each financial entity’s responsibility for its own providers and arrangements.
- **Information sharing:** Financial entities may exchange cyber-threat information within trusted communities when the arrangements protect confidentiality, personal data, and sensitive business information.

### Related terms

[NIS2 Directive](<https://yellowcube.eu/glossary/nis2-directive/>) · [Incident response (IR)](<https://yellowcube.eu/glossary/incident-response/>) · [Cyber Resilience Act (CRA)](<https://yellowcube.eu/glossary/cyber-resilience-act/>)

### Sources

[EUR-Lex: Regulation (EU) 2022/2554](https://eur-lex.europa.eu/eli/reg/2022/2554/oj) · [Delegated Regulation (EU) 2025/301: Incident reporting](https://eur-lex.europa.eu/eli/reg_del/2025/301/oj) · [European Commission: Guidelines on NIS2 Article 4](https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX%3A52023XC0918%2801%29) · [European Banking Authority: Operational Resilience](https://www.eba.europa.eu/regulation-and-policy/operational-resilience)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

