DORA: explained for the people who have to keep the systems running.
Digital Operational Resilience Act
Direct answer
The Digital Operational Resilience Act (DORA), Regulation (EU) 2022/2554, is the EU law that requires financial entities to withstand, respond to, and recover from information and communication technology (ICT) disruptions. It applies from 17 January 2025 across five areas: ICT risk management, ICT-related incident reporting, digital operational resilience testing, ICT third-party risk, and information sharing. It covers most regulated financial entities in the EU and extends supervision to the critical ICT providers they rely on.
Why DORA exists
Before DORA, operational resilience for EU financial services was governed by a patchwork of national rules and sector guidance. DORA replaces that with a single, directly applicable regulation, so a bank, an insurer, and an investment firm are held to the same baseline for surviving a technology failure or a cyber attack. The shift in mindset is the important part: DORA treats ICT disruption not as an IT problem but as a threat to financial stability, and it makes the board answerable for managing it.
The five pillars
DORA is organised around five areas. Read together they describe a full lifecycle: govern the risk, detect and report what goes wrong, prove your resilience by testing it, control the third parties you depend on, and share what you learn.
| Pillar | What it requires |
|---|---|
| ICT risk management | A documented framework, owned by the management body, covering identification, protection, detection, response, and recovery. |
| ICT incident management and reporting | Classify incidents by severity and report major ones to the competent authority within set deadlines. |
| Digital operational resilience testing | A testing programme, including advanced threat-led penetration testing for significant entities. |
| ICT third-party risk | A register of ICT contractual arrangements and mandatory contractual terms, with stricter rules for critical or important functions. |
| Information sharing | Optional participation in cyber threat information-sharing arrangements between financial entities. |
Who DORA applies to
DORA covers a broad range of financial entities established in the EU, and it reaches beyond them to the technology providers they depend on. Scope is wide by design, so the safer assumption for an EU financial entity is that you are in scope until you have confirmed otherwise. A separate oversight regime applies to ICT third-party providers designated as critical, who become subject to direct supervision by a lead overseer.
| Category | Examples |
|---|---|
| Financial entities | Credit institutions, payment and e-money institutions, investment firms, insurers and intermediaries, crypto-asset service providers, fund managers, and more. |
| ICT third-party providers | Cloud platforms, software and data providers, and other technology suppliers, with a dedicated oversight regime for those designated critical. |
The ICT third-party register
DORA requires every financial entity to keep a register of information on all its contractual arrangements for the use of ICT services. The register has to be maintained at entity and, where relevant, group level, kept current as arrangements change, and made available to the competent authority on request. In practice it is the single hardest thing to keep honest, because it only stays accurate if it is tied to the vendor relationships it describes rather than maintained as a separate document. Acuna keeps that register live against your third-party risk management vendor inventory, which is the tightest fit between DORA and the platform.
Resilience testing and TLPT
Every in-scope entity runs a digital operational resilience testing programme sized to its risk profile. Entities identified as significant go further and perform threat-led penetration testing (TLPT) at least every three years, carried out by qualified testers against live production systems, drawing on the TIBER-EU framework. TLPT is the demanding end of the testing obligation and is scoped and validated with the competent authority.
Why the board is on the hook
DORA is explicit that the management body holds final responsibility for managing ICT risk. It must approve and oversee the ICT risk management framework, and it cannot delegate the accountability away. This is the practical reason DORA cannot live only inside the security team: the people who sign off have to be able to see that the framework is real and maintained, which is exactly what a running system, rather than a set of documents, provides.
How DORA relates to NIS2 and ISO 27001
DORA does not sit alone. Much of its ICT risk management substance overlaps with NIS2 and with ISO 27001, and its third-party requirements echo the supplier controls in both. For an entity already running one of those, the efficient path is to map the shared controls once and reuse them, rather than stand up a parallel DORA programme. That reuse is the argument for treating DORA as one framework on a multi-framework core rather than a standalone project.
When it applies
DORA entered into force in January 2023 and applies from 17 January 2025. The detailed technical standards that sit beneath it, the regulatory and implementing technical standards developed by the European Supervisory Authorities, fill in the specifics of areas such as incident classification, the register, and testing. Because those standards continue to be finalised and updated, verify the current detail of any specific technical requirement against the latest published standard before you rely on it.
EXPLORE
DORA
The regulation, its scope, and what it changes for financial entities.
The testing programme every in-scope entity must run.
The Article 28 register of information, and how to keep it current.
Classifying major ICT incidents and reporting them to your authority.
The advanced testing significant entities must perform.
Which financial entities and ICT providers are in scope.
DORA: common questions.
Related answers
Questions practitioners ask.
DORA is the first time a regulator has told financial firms, in plain terms, that keeping the lights on is a board responsibility, not an IT chore.
Acuna practitioner team
The register of information is where DORA programmes quietly fall apart. It is accurate the day you build it and wrong the week a contract changes, unless it lives with the vendor relationships it describes.
Acuna practitioner team
Most of DORA is not new work if you already run ISO 27001 or NIS2. The mistake is treating it as a separate project instead of one more framework on the same controls.
Acuna practitioner team