What is DORA regulation?

DORA is the EU Digital Operational Resilience Act, Regulation (EU) 2022/2554. It requires banks, asset managers, insurers and most other financial firms to manage ICT risk, report major IT incidents, test their systems and control their IT providers. It applies since January 17, 2025, directly in every Member State.

DORA in brief

TermDORA stands for Digital Operational Resilience Act. German: Verordnung über die digitale operationale Resilienz im Finanzsektor.
Legal sourceRegulation (EU) 2022/2554 of December 14, 2022.
Applies sinceJanuary 17, 2025 (Article 64).
Scope20 types of financial entities in Article 2(1), from credit institutions to crowdfunding service providers, plus ICT third-party service providers.
SupervisorsBaFin in Germany, FMA in Austria. EBA, EIOPA and ESMA oversee critical ICT third-party service providers.
Testing cycleThreat-led penetration testing at least every 3 years for the entities that authorities identify (Article 26(1)).

Who does DORA regulation apply to?

DORA applies to 20 types of financial entities. For banks and asset managers, the list in Article 2(1) names credit institutions, investment firms, managers of alternative investment funds and management companies. It also covers payment and e-money institutions, insurers, trading venues, central counterparties, crypto-asset service providers and others. Article 2(3) exempts some small firms, such as insurance intermediaries that are micro, small or medium-sized enterprises.

Is DORA a regulation or a directive? It is a regulation. The text is "binding in its entirety and directly applicable in all Member States" (Article 64), so the same rules apply in Frankfurt and in Vienna without national transposition.

What are the 5 pillars of DORA regulation?

The 5 pillars of DORA are its Chapters II to VI. The chapter titles name the areas, and together they set the DORA compliance requirements for banks and the other financial entities. Chapter II asks for an ICT risk management framework.

ChapterAreaWhat a firm must do
IIICT risk managementRun an ICT risk management framework; the management body bears "the ultimate responsibility" (Article 5(2))
IIIICT-related incident management, classification and reportingReport major ICT-related incidents: initial notification, intermediate report, final report (Article 19(4))
IVDigital operational resilience testingTest systems; selected firms run threat-led penetration tests at least every 3 years (Article 26)
VManaging of ICT third-party riskKeep a register of all ICT service contracts (Article 28(3))
VIInformation-sharing arrangementsMay share cyber threat information with other financial entities (Article 45)

What is ICT risk in DORA?

ICT risk in DORA is "any reasonably identifiable circumstance in relation to the use of network and information systems" that may compromise the security of those systems, of operations or of the provision of services (Article 3(5)). The definition includes adverse effects "in the digital or physical environment".

A major ICT-related incident is one with "a high adverse impact" on the systems that support critical or important functions (Article 3(10)). Firms classify each incident and report the major ones to their competent authority.

What does DORA require for third-party risk management?

DORA third-party risk management starts with responsibility: a financial entity that uses ICT services stays "fully responsible" for compliance (Article 28(1)). Before it signs a contract, it assesses whether the service supports a critical or important function and identifies the risks, including concentration risk (Article 28(4)). It reports new ICT arrangements to its authority at least yearly (Article 28(3)).

Among the DORA requirements for ICT providers, the strictest apply to critical ones. The European Supervisory Authorities, EBA, EIOPA and ESMA, designate the ICT third-party service providers that are critical for financial entities and appoint one of the three as Lead Overseer for each (Article 31). The Lead Overseer can impose a daily penalty of up to 1% of the provider's average daily worldwide turnover to enforce its measures (Article 35(8)).

What is the main purpose of the DORA regulation in Europe?

The main purpose of DORA is "a high common level of digital operational resilience" in the EU financial sector, through uniform requirements for the security of the network and information systems of financial entities (Article 1(1)).

DORA vs NIS2: Directive (EU) 2022/2555 (NIS2) sets cybersecurity rules for many sectors. For financial entities that NIS2 classifies as essential or important, DORA is the sector-specific Union act (Article 1(2)); recital 16 calls DORA "lex specialis" to NIS2.

DORA in Germany, Austria and Switzerland

As a regulation, DORA is law in Germany without a national act of transposition, and BaFin supervises it. BaFin states that financial firms of all sectors have had to apply DORA since January 17, 2025, and it receives the reports of major ICT-related incidents. EIOPA, one of the three European Supervisory Authorities that designate critical ICT third-party providers and act as their Lead Overseers, has its seat at Westhafenplatz 1 in Frankfurt am Main. The three authorities published their first list of designated critical providers on November 18, 2025. In Austria the DORA-Vollzugsgesetz (BGBl. I Nr. 112/2024) names the FMA as the competent authority under Article 46 of DORA (§ 2) and regulates its cooperation with the Oesterreichische Nationalbank (§ 5).

Switzerland is outside the EU, so DORA does not apply there. FINMA Circular 2023/1 "Operational risks and resilience: banks" has applied since January 1, 2024. It covers ICT, critical data and cyber risks and adopts the Basel Committee principles on operational resilience of March 2021. This page gives no legal advice.

Sources

About Finance Loop: DORA

Finance Loop is the meeting place for IT risk managers and information security officers at banks, insurers and asset managers. It connects the finance, IT and AI communities in Frankfurt, seat of EIOPA, one of the three European authorities that oversee critical ICT providers under DORA.

Finance Loop is built in collaboration with TechQuartier, the fintech hub in Frankfurt, where many events on DORA take place. Finance Loop also announced KI Exchange 2026 in Hamburg on June 23, 2026, whose program listed DORA compliance.

Let's stay in touch

4,000+ members in finance and tech. Become a Network Member for free.

Get updates for free!

Exclusive event invitations, member perks and news from the network. Unsubscribe at any time.

By submitting you agree to the terms.