About DORA
Regulation (EU) 2022/2554 — Digital Operational Resilience Act
What is DORA?
The Digital Operational Resilience Act — officially Regulation (EU) 2022/2554 of the European Parliament and of the Council — establishes a unified legal framework for ICT risk management in the EU financial sector. It was published in the Official Journal of the European Union on 27 December 2022, entered into force on 16 January 2023, and became directly applicable across all EU member states on 17 January 2025.
DORA replaces a patchwork of national guidelines and sector-specific rules with a single, binding standard. Its core goal is to ensure that financial entities can withstand, respond to, and recover from all ICT-related disruptions and threats.
Who does it apply to?
DORA applies broadly to regulated financial entities operating in the EU. This includes credit institutions, payment institutions, electronic money institutions, investment firms, crypto-asset service providers (CASPs), insurance and reinsurance undertakings, insurance intermediaries, institutions for occupational retirement provision (pension funds), management companies, alternative investment fund managers, central counterparties, trade repositories, and several other categories. ICT third-party service providers designated as critical by the supervisory authorities are also brought within scope.
The regulation applies a proportionality principle (Article 4): microenterprises and certain smaller entities may apply a simplified ICT risk management framework under Article 16.
The five pillars of the DORA regulation
The DORA regulation itself doesn't use the word "pillar" — the regulation organizes these requirements into Chapters II through VI. "Pillar" is the shorthand the industry has settled on for describing them, and we use it here for readability.
Pillar 1 — ICT Risk Management (Chapter II, Arts. 5–16)
The broadest pillar. Financial entities must maintain a comprehensive ICT risk management framework approved at board level. This covers governance and accountability, ICT asset identification, protection and prevention controls, anomaly detection, incident response and recovery, backup and restoration, and a continuous learning and improvement cycle.
Pillar 2 — ICT-Related Incident Management (Chapter III, Arts. 17–23)
Entities must establish a structured process for detecting, managing, and classifying ICT incidents. Major incidents must be reported to the relevant competent authority using standardised templates and timelines (initial notification, intermediate report, final report). Significant cyber threats may be voluntarily notified.
Pillar 3 — Digital Operational Resilience Testing (Chapter IV, Arts. 24–27)
Entities must run a programme of regular resilience tests proportionate to their size and risk profile. Significant entities are additionally required to conduct Threat-Led Penetration Testing (TLPT) at least every three years, carried out by certified external testers.
Pillar 4 — ICT Third-Party Risk Management (Chapter V, Arts. 28–44)
Entities must adopt a strategy for managing ICT third-party risk, maintain a register of all ICT service arrangements, conduct due diligence before and during contracts, and ensure contracts include mandatory provisions on access rights, audit rights, service levels, and exit strategies. The regulation also establishes an Oversight Framework under which the ESAs can designate critical ICT third-party providers and subject them to direct supervisory oversight.
Pillar 5 — Information and Intelligence Sharing (Chapter VI, Art. 45)
Financial entities may voluntarily participate in cyber threat information and intelligence sharing arrangements. DORA creates the legal basis for such schemes and encourages competent authorities to facilitate them.
Regulatory Technical Standards
The three European Supervisory Authorities — EBA, ESMA, and EIOPA — have jointly developed a comprehensive set of Level 2 measures (RTS and ITS) that flesh out DORA's requirements. These cover the ICT risk management framework, incident classification criteria, reporting templates, the register of information on ICT third-party arrangements, TLPT requirements, and oversight fees for critical ICT providers. Final standards were published in the Official Journal across 2024 and 2025, with the last major RTS (on threat-led penetration testing) published in June 2025.
Reporting: the Register of Information
Under Article 28(3) of DORA, financial entities must maintain and keep up to date a register of information covering every contractual arrangement they have with ICT third-party service providers — at entity level, and at sub-consolidated and consolidated level for groups. The register must distinguish arrangements that support critical or important functions from those that don't.
Entities must report on their register at least yearly to their competent authority, covering new arrangements entered into, the categories of ICT providers used, the type of contractual arrangements, and the services and functions involved. The full register — or specific sections of it — must be made available to the competent authority on request.
The standard templates financial entities must use are set out in Commission Implementing Regulation (EU) 2024/2956, the Implementing Technical Standards developed under the Article 28(9) mandate. The ESAs use the aggregated registers collected across the EU to monitor ICT concentration risk and to identify Critical ICT Third-Party Providers (CTPPs) that fall under the DORA Oversight Framework.
Need help with your reporting of the DORA register of information?
Official Sources
The links below are to official EU institutions and regulatory bodies.
Regulation (EU) 2022/2554 — full text
Full text of the regulation as published in the Official Journal of the EU, available in all official languages of the EU.
European Commission — Digital operational resilience (DORA) overview
Commission overview, delegated acts, and implementing technical standards
European Commission — Delegated and implementing acts for DORA
Delegated and implementing acts adopted under DORA
European Banking Authority (EBA) — DORA
EBA's DORA hub: RTS, ITS, consultations, and Q&A
European Securities and Markets Authority (ESMA) — DORA
ESMA's DORA hub and technical standards for investment firms and market infrastructure
European Insurance and Occupational Pensions Authority (EIOPA) — DORA
EIOPA's DORA hub for the insurance and pensions sector
ENISA (EU Agency for Cybersecurity) — Finance sector
ENISA's work on cybersecurity for the finance sector
Commission Implementing Regulation (EU) 2024/2956 — register of information templates
Official Journal text of the ITS establishing the standard templates for the DORA register of information
EBA — DORA register of information reporting
EBA's guidance, tools and reporting framework for submitting the register of information