GlossaryDORA

DORA

Short answer

DORA (Regulation (EU) 2022/2554) is the EU regulation on digital operational resilience for the financial sector. In force since 17 January 2025, it requires financial entities to manage ICT risk, report major incidents, test their resilience and control the risk from their ICT providers.

Who it applies to

DORA applies to most EU financial entities, including banks, insurers, investment firms, payment and electronic money institutions and crypto asset service providers. It also reaches the ICT providers that serve them, through contract requirements and, for critical providers, direct oversight by EU authorities.

The five pillars

DORA is organised around five areas: ICT risk management, classification and reporting of ICT related incidents, digital operational resilience testing, management of ICT third party risk, and sharing of threat information.

What changes for ICT providers

Financial entities must keep a register of information on all their ICT contracts and include specific clauses on security, audit rights and exit strategies. Providers are increasingly asked to show evidence of their own controls during procurement.

Testing

All entities must test their resilience regularly. Some must also run threat led penetration testing (TLPT), based on the TIBER-EU framework, every three years.

Related terms

Keep reading on this topic

The Digital Operational Resilience Act for financial entities and their ICT providers: risk management, incident classification, testing and third-party oversight.

Go to the topic hub