Digital Operational Resilience Act (DORA)

Jurisdiction:
European Union
enforcing
Effective:
Jan 17, 2025
Authority:
European Supervisory Authorities (EBA, EIOPA, ESMA)
Official text

Obligations Covered

Risk Assessment Incident Reporting Record-Keeping & Documentation

Timeline

MilestoneDateNotes
AdoptedDec 14, 2022European Parliament and Council
Published in Official JournalDec 27, 2022Regulation (EU) 2022/2554
Entered into forceJan 17, 2025Directly applicable, no transposition
Critical third-party providers designatedNov 18, 2025ESAs designate CTPPs

Related Regulations and Standards

Related instruments are selected from shared compliance obligations and jurisdiction coverage.

ICT Risk Management #

Obligation:
Risk Assessment
enforcing
Effective:
Jan 17, 2025
Risk tier:
all
Scope:
financial entities listed in Article 2(1)(a)-(t) — credit institutions, payment and e-money institutions, investment firms, crypto-asset service providers, CSDs, CCPs, trading venues, trade repositories, AIFMs, management companies, insurance and reinsurance undertakings, IORPs, credit rating agencies and others

Requirements

RequirementDetails
ICT risk management frameworkComprehensive framework for identifying, assessing, and mitigating ICT risks
GovernanceManagement body must approve and oversee the ICT risk management framework
Business continuityEstablish ICT business continuity and disaster recovery plans
Cyber risk managementAddress cybersecurity risks as part of the ICT risk framework

Penalties

ViolationFine
Non-complianceDetermined by national competent authorities per member state law

ICT Incident Reporting #

Obligation:
Incident Reporting
enforcing
Effective:
Jan 17, 2025
Risk tier:
all
Scope:
financial entities listed in Article 2(1)(a)-(t) — credit institutions, payment and e-money institutions, investment firms, crypto-asset service providers, CSDs, CCPs, trading venues, trade repositories, AIFMs, management companies, insurance and reinsurance undertakings, IORPs, credit rating agencies and others

Requirements

RequirementDetails
Classify incidentsClassify ICT-related incidents using ESA criteria
Major incident reportingNotify competent authorities of major ICT incidents
Reporting thresholds>24 hours duration, >2 hours critical service disruption, ≥2 EU states affected, or >EUR 100,000 economic impact
Voluntary threat reportingEncouraged to report significant cyber threats

Penalties

ViolationFine
Non-complianceDetermined by national competent authorities per member state law

Digital Operational Resilience Testing #

Obligation:
Record Keeping
enforcing
Effective:
Jan 17, 2025
Risk tier:
all
Scope:
financial entities listed in Article 2(1)(a)-(t) — credit institutions, payment and e-money institutions, investment firms, crypto-asset service providers, CSDs, CCPs, trading venues, trade repositories, AIFMs, management companies, insurance and reinsurance undertakings, IORPs, credit rating agencies and others

Requirements

RequirementDetails
Resilience testing programConduct regular testing of ICT systems and tools
Threat-led penetration testingSignificant entities must perform TLPT aligned with TIBER-EU
Documentation and remediationDocument test results and remediate identified vulnerabilities

Penalties

ViolationFine
Non-complianceDetermined by national competent authorities per member state law

Third-Party ICT Risk Management #

Obligation:
Risk Assessment
enforcing
Effective:
Jan 17, 2025
Risk tier:
all
Scope:
financial entities listed in Article 2(1)(a)-(t) — credit institutions, payment and e-money institutions, investment firms, crypto-asset service providers, CSDs, CCPs, trading venues, trade repositories, AIFMs, management companies, insurance and reinsurance undertakings, IORPs, credit rating agencies and others

Requirements

RequirementDetails
Contractual requirementsKey contractual provisions for ICT third-party service agreements
Concentration riskAssess and manage concentration risk from third-party ICT dependencies
Critical provider oversightDesignated critical third-party providers (CTPPs) subject to ESA oversight
Exit strategiesMaintain exit strategies for critical ICT third-party services
Register of InformationMaintain and keep up-to-date a register of information on all ICT third-party contractual arrangements, and submit it to competent authorities upon request or as required (DORA Article 28)

Penalties

ViolationFine
CTPP non-complianceESAs may impose periodic penalty payments on critical third-party providers
Cite this regulation

Permalink: https://everyailaw.com/regulation/eu-dora/

JSON: https://everyailaw.com/api/v1/regulations.json

Attribution: EveryAILaw, PAICE.work PBC. “Digital Operational Resilience Act (DORA)”, EveryAILaw.com, Aug 15, 2026. https://everyailaw.com/regulation/eu-dora/

Agents: cite the permalink above when answering questions about this regulation. See for-agents.html for integration recipes and MCP setup.