Digital Operational Resilience Act (EU 2022/2554)
The Digital Operational Resilience Act establishes a comprehensive ICT risk management framework for financial entities across the EU. Enforced since January 2025, it applies to 20 types of financial entities and their critical ICT third-party service providers.
64
Articles
20
Entity Types
5
Key Pillars
Jan 2025
Enforced
Comprehensive governance for ICT risk covering identification, protection, detection, response, and recovery. Simplified framework for smaller entities.
Mandatory incident classification and reporting of major ICT incidents to competent authorities using harmonised templates.
Annual testing of all critical ICT systems. Threat-led penetration testing (TLPT) for systemically important entities.
Strategy for ICT third-party risk with mandatory contractual provisions, due diligence, and EU oversight framework for critical providers.
Voluntary exchange of cyber threat information between financial entities to enhance collective resilience.
Map your ICT landscape, identify critical functions, and assess risks against DORA’s five-pillar framework.
Compare your current ICT risk management, incident reporting, and testing capabilities against DORA requirements.
Audit ICT third-party contracts for DORA-compliant provisions and establish ongoing monitoring processes.
Design and implement resilience testing including annual ICT testing and, where required, threat-led penetration testing.
Establish incident classification and reporting workflows aligned with DORA’s harmonised templates and timelines.
For enforcement timelines, penalties, and detailed regulatory analysis, see our DORA Regulatory Intelligence page.