Category: DORA
The Digital Operational Resilience Act is an EU Regulation requiring financial entities to withstand, respond to and recover from ICT disruption. Because it is a Regulation rather than a Directive, it applies directly and identically across every member state, with no national transposition. It has applied since 17 January 2025.
Its scope is unusually broad: banks, insurers, investment firms, payment institutions, crypto-asset service providers and more — and, critically, the ICT third-party providers that serve them. Providers designated as critical are overseen directly at EU level, which is a genuine novelty in financial regulation.
Five pillars structure the obligations: ICT risk management, ICT incident management and reporting, digital operational resilience testing, ICT third-party risk management, and information sharing. For entities designated as significant, testing includes threat-led penetration testing.
Where DORA and NIS2 could both apply to a financial entity, DORA takes precedence as lex specialis on the matters it covers.
The guides below cover what DORA is, who it applies to, the five pillars, the register of information for third-party arrangements, the documentation you must hold, and how DORA compares with NIS2.