Digital Operational Resilience Act (Regulation (EU) 2022/2554)
The Digital Operational Resilience Act (DORA) is a European Union regulation designed to ensure that the financial sector can withstand, respond to, and recover from ICT-related disruptions. It shifts the focus from traditional financial solvency to operational resilience, ensuring that critical services remain available during cyberattacks or system failures.
Who it applies to
- Credit institutions and payment institutions.
- Insurance and reinsurance undertakings.
- Investment firms and alternative investment fund managers.
- Crypto-asset service providers.
- Critical third-party ICT providers, such as cloud computing services.
How it works
DORA is structured around five pillars: ICT risk management, incident reporting, digital operational resilience testing, ICT third-party risk management, and information sharing. Unlike a voluntary certification, DORA is a regulation that establishes mandatory legal requirements for entities operating within the EU financial market.
Compliance is verified through supervisory reviews conducted by national competent authorities and European Supervisory Authorities (ESAs). Assessment focuses on whether an organization has implemented a robust ICT risk management framework, maintains an accurate register of third-party dependencies, and can demonstrate resilience through mandated testing cycles.
Getting started
- Perform a gap analysis to compare current ICT risk frameworks against the specific requirements of Regulation (EU) 2022/2554.
- Update corporate governance structures to ensure that management bodies are formally accountable for managing ICT risks.
- Create a comprehensive inventory of all third-party ICT providers and categorize them based on their criticality to business functions.
- Implement a standardized incident classification system to identify "major" ICT incidents as defined by the regulation.
- Develop a multi-year testing program that includes vulnerability assessments and, for critical entities, threat-led penetration testing (TLPT).
Controls & requirements
- Art. 2 Who is in scope: financial entities and ICT providers
- Art. 4 Proportionality: how DORA scales with size and risk
- Art. 5 Management body responsibility for ICT risk
- Arts. 5–16 The ICT risk-management framework
- Arts. 17–23 ICT incident classification and reporting
- Arts. 24–27 Resilience testing and threat-led penetration testing
- Arts. 28–30 ICT third-party risk and contractual provisions
- Art. 28(3) The register of information
- Arts. 31–44 Oversight of critical ICT third-party providers
- Art. 45 Cyber threat information sharing
Common misconceptions
- DORA is often viewed as an IT project; however, it is a regulatory mandate requiring board-level oversight and legal integration into business contracts.
- Some assume DORA replaces other frameworks like NIS2 or GDPR, but it actually complements them by providing specific resilience requirements for the financial sector.