EU Regulatory Center
DORA — digital operational resilience for finance
ICT risk management, incident reporting, resilience testing and third-party oversight for financial entities and their critical ICT providers.
Status
Law in force
Regulation (EU) 2022/2554
DORA has applied since 17 January 2025 and creates a harmonized framework for digital operational resilience across the EU financial sector, including banks, insurers, investment firms and their critical ICT third-party providers.
Scope at a glance
| Question | Answer |
|---|---|
| Who | Banks, insurers, investment firms and most other regulated financial entities, plus their critical ICT third-party providers. |
| What | ICT risk management, resilience testing, incident reporting and third-party risk oversight. |
| Reporting | Major ICT-related incidents must be reported to competent authorities within defined timelines. |
| Oversight | Critical ICT third-party providers can be designated for direct EU-level oversight. |
Core obligations
- Establish an ICT risk-management framework proportionate to the entity’s size and complexity.
- Conduct regular digital operational resilience testing, including for critical systems.
- Report major ICT-related incidents to competent authorities within the required timelines.
- Manage concentration and dependency risk across critical ICT third-party providers.
General guidance, not legal advice
This page summarizes publicly available regulatory status for general guidance only. Confirm applicability, scope and deadlines with qualified legal counsel before making compliance decisions.
How CYRKIL helps
The Financial Services industry view maps DORA obligations to controls and evidence, and Supply Chain Security tracks third-party concentration risk.
See Financial ServicesHow CYRKIL tracks this
Every regulatory page here runs through the Regulatory Truth Pipeline — official source, human and legal review, then publish, with the source, version and review date always shown.
See the pipeline