What DORA is
Regulation (EU) 2022/2554 — the Digital Operational Resilience Act (DORA) — creates a single EU framework for the operational resilience of the financial sector. It entered into force on 16 January 2023 and became applicable on 17 January 2025. Its rules are directly binding and are supplemented by technical standards from the European Supervisory Authorities (ESAs) covering ICT risk management, incident classification and reporting, resilience testing, and third-party risk.
Who it catches
DORA applies to financial entities: credit institutions, investment firms, payment and e-money institutions, insurance and reinsurance undertakings, asset managers, central counterparties, trading venues and others listed in the regulation. It also applies to critical ICT third-party providers (CTPPs) that are designated by the EU Lead Overseer and provide services that financial entities depend on for their ICT systems. Non-critical ICT providers are affected indirectly through contractual flow-down.
The five pillars
DORA is organised around five pillars that together define operational resilience:
- ICT risk management. Financial entities must maintain a comprehensive and well-documented ICT risk-management framework, covering identification, protection, detection, response and recovery, with governance and internal controls proportionate to their size and risk profile.
- Incident reporting and classification. Significant ICT-related incidents must be classified according to ESA criteria and reported to the lead supervisor through a harmonised process. The materiality thresholds, timelines and reporting templates are set in the technical standards.
- Digital operational resilience testing. Entities must test their ICT systems and protocols regularly. Threat-led penetration testing (TLPT) based on the TIBER-EU framework is required for significant entities at a frequency set by supervisors, and proportionate testing is required for others.
- ICT third-party risk management. Entities must manage concentration risk, perform due diligence and oversight of ICT providers, and ensure contractual rights to audit, reporting and exit. The Register of Information required by Article 28 captures the full ICT third-party ecosystem.
- Information sharing. DORA permits financial entities to share cyber-threat information and intelligence within trusted communities, subject to confidentiality and competition-law safeguards.
From readiness to evidence
In the first year of application, supervisory attention moved from whether entities had read the regulation to whether they could produce evidence that it was implemented. Boards, risk functions and CIOs are now expected to show documented decision trails, test results, supplier registers and incident classifications that stand up to examination.
How CYBERVETTER helps
We work with financial entities and ICT providers on the parts of DORA that require independent assurance and disciplined preparation:
- Gap assessment and programme design against the five pillars and ESA technical standards.
- TLPT scoping and readiness support, including threat-intelligence and purple-team preparation.
- Register of Information design, data collection and maintenance workflows.
- ICT third-party risk management, due diligence and contractual assurance.
- Incident classification and reporting procedures aligned with supervisory expectations.
- Board and management-body briefings on DORA accountability.