By regulation

DORA

The Digital Operational Resilience Act. Applicable since 17 January 2025 to financial entities and the critical ICT third-party providers that support them.

What DORA is

Regulation (EU) 2022/2554 — the Digital Operational Resilience Act (DORA) — creates a single EU framework for the operational resilience of the financial sector. It entered into force on 16 January 2023 and became applicable on 17 January 2025. Its rules are directly binding and are supplemented by technical standards from the European Supervisory Authorities (ESAs) covering ICT risk management, incident classification and reporting, resilience testing, and third-party risk.

Who it catches

DORA applies to financial entities: credit institutions, investment firms, payment and e-money institutions, insurance and reinsurance undertakings, asset managers, central counterparties, trading venues and others listed in the regulation. It also applies to critical ICT third-party providers (CTPPs) that are designated by the EU Lead Overseer and provide services that financial entities depend on for their ICT systems. Non-critical ICT providers are affected indirectly through contractual flow-down.

The five pillars

DORA is organised around five pillars that together define operational resilience:

  • ICT risk management. Financial entities must maintain a comprehensive and well-documented ICT risk-management framework, covering identification, protection, detection, response and recovery, with governance and internal controls proportionate to their size and risk profile.
  • Incident reporting and classification. Significant ICT-related incidents must be classified according to ESA criteria and reported to the lead supervisor through a harmonised process. The materiality thresholds, timelines and reporting templates are set in the technical standards.
  • Digital operational resilience testing. Entities must test their ICT systems and protocols regularly. Threat-led penetration testing (TLPT) based on the TIBER-EU framework is required for significant entities at a frequency set by supervisors, and proportionate testing is required for others.
  • ICT third-party risk management. Entities must manage concentration risk, perform due diligence and oversight of ICT providers, and ensure contractual rights to audit, reporting and exit. The Register of Information required by Article 28 captures the full ICT third-party ecosystem.
  • Information sharing. DORA permits financial entities to share cyber-threat information and intelligence within trusted communities, subject to confidentiality and competition-law safeguards.

From readiness to evidence

In the first year of application, supervisory attention moved from whether entities had read the regulation to whether they could produce evidence that it was implemented. Boards, risk functions and CIOs are now expected to show documented decision trails, test results, supplier registers and incident classifications that stand up to examination.

How CYBERVETTER helps

We work with financial entities and ICT providers on the parts of DORA that require independent assurance and disciplined preparation:

  • Gap assessment and programme design against the five pillars and ESA technical standards.
  • TLPT scoping and readiness support, including threat-intelligence and purple-team preparation.
  • Register of Information design, data collection and maintenance workflows.
  • ICT third-party risk management, due diligence and contractual assurance.
  • Incident classification and reporting procedures aligned with supervisory expectations.
  • Board and management-body briefings on DORA accountability.

Build DORA evidence

We help financial entities and ICT providers turn DORA requirements into documented programmes, test results and supplier registers that supervisors can read.

DORA programme service