Who it applies to
DORA applies to most EU financial entities, including banks, insurers, investment firms, payment and electronic money institutions and crypto asset service providers. It also reaches the ICT providers that serve them, through contract requirements and, for critical providers, direct oversight by EU authorities.
The five pillars
DORA is organised around five areas: ICT risk management, classification and reporting of ICT related incidents, digital operational resilience testing, management of ICT third party risk, and sharing of threat information.
What changes for ICT providers
Financial entities must keep a register of information on all their ICT contracts and include specific clauses on security, audit rights and exit strategies. Providers are increasingly asked to show evidence of their own controls during procurement.
Testing
All entities must test their resilience regularly. Some must also run threat led penetration testing (TLPT), based on the TIBER-EU framework, every three years.




