Bibba TechBibba Tech
Powered byBibba TechBibba Tech© 2026 -DISCLAIMER

About DORA

Regulation (EU) 2022/2554 — Digital Operational Resilience Act

What is DORA?Who does it apply to?The five pillars of the DORA regulationRegulatory Technical StandardsReporting: the Register of InformationOfficial Sources

What is DORA?

The Digital Operational Resilience Act — officially Regulation (EU) 2022/2554 of the European Parliament and of the Council — establishes a unified legal framework for ICT risk management in the EU financial sector. It was published in the Official Journal of the European Union on 27 December 2022, entered into force on 16 January 2023, and became directly applicable across all EU member states on 17 January 2025.

DORA replaces a patchwork of national guidelines and sector-specific rules with a single, binding standard. Its core goal is to ensure that financial entities can withstand, respond to, and recover from all ICT-related disruptions and threats.

Who does it apply to?

DORA applies broadly to regulated financial entities operating in the EU. This includes credit institutions, payment institutions, electronic money institutions, investment firms, crypto-asset service providers (CASPs), insurance and reinsurance undertakings, insurance intermediaries, institutions for occupational retirement provision (pension funds), management companies, alternative investment fund managers, central counterparties, trade repositories, and several other categories. ICT third-party service providers designated as critical by the supervisory authorities are also brought within scope.

The regulation applies a proportionality principle (Article 4): microenterprises and certain smaller entities may apply a simplified ICT risk management framework under Article 16.

The five pillars of the DORA regulation

The DORA regulation itself doesn't use the word "pillar" — the regulation organizes these requirements into Chapters II through VI. "Pillar" is the shorthand the industry has settled on for describing them, and we use it here for readability.

Pillar 1 — ICT Risk Management (Chapter II, Arts. 5–16)

The broadest pillar. Financial entities must maintain a comprehensive ICT risk management framework approved at board level. This covers governance and accountability, ICT asset identification, protection and prevention controls, anomaly detection, incident response and recovery, backup and restoration, and a continuous learning and improvement cycle.

Pillar 2 — ICT-Related Incident Management (Chapter III, Arts. 17–23)

Entities must establish a structured process for detecting, managing, and classifying ICT incidents. Major incidents must be reported to the relevant competent authority using standardised templates and timelines (initial notification, intermediate report, final report). Significant cyber threats may be voluntarily notified.

Pillar 3 — Digital Operational Resilience Testing (Chapter IV, Arts. 24–27)

Entities must run a programme of regular resilience tests proportionate to their size and risk profile. Significant entities are additionally required to conduct Threat-Led Penetration Testing (TLPT) at least every three years, carried out by certified external testers.

Pillar 4 — ICT Third-Party Risk Management (Chapter V, Arts. 28–44)

Entities must adopt a strategy for managing ICT third-party risk, maintain a register of all ICT service arrangements, conduct due diligence before and during contracts, and ensure contracts include mandatory provisions on access rights, audit rights, service levels, and exit strategies. The regulation also establishes an Oversight Framework under which the ESAs can designate critical ICT third-party providers and subject them to direct supervisory oversight.

Pillar 5 — Information and Intelligence Sharing (Chapter VI, Art. 45)

Financial entities may voluntarily participate in cyber threat information and intelligence sharing arrangements. DORA creates the legal basis for such schemes and encourages competent authorities to facilitate them.

Regulatory Technical Standards

The three European Supervisory Authorities — EBA, ESMA, and EIOPA — have jointly developed a comprehensive set of Level 2 measures (RTS and ITS) that flesh out DORA's requirements. These cover the ICT risk management framework, incident classification criteria, reporting templates, the register of information on ICT third-party arrangements, TLPT requirements, and oversight fees for critical ICT providers. Final standards were published in the Official Journal across 2024 and 2025, with the last major RTS (on threat-led penetration testing) published in June 2025.

Reporting: the Register of Information

Under Article 28(3) of DORA, financial entities must maintain and keep up to date a register of information covering every contractual arrangement they have with ICT third-party service providers — at entity level, and at sub-consolidated and consolidated level for groups. The register must distinguish arrangements that support critical or important functions from those that don't.

Entities must report on their register at least yearly to their competent authority, covering new arrangements entered into, the categories of ICT providers used, the type of contractual arrangements, and the services and functions involved. The full register — or specific sections of it — must be made available to the competent authority on request.

The standard templates financial entities must use are set out in Commission Implementing Regulation (EU) 2024/2956, the Implementing Technical Standards developed under the Article 28(9) mandate. The ESAs use the aggregated registers collected across the EU to monitor ICT concentration risk and to identify Critical ICT Third-Party Providers (CTPPs) that fall under the DORA Oversight Framework.

Need help with your reporting of the DORA register of information?

Official Sources

The links below are to official EU institutions and regulatory bodies.

Regulation (EU) 2022/2554 — full text

Full text of the regulation as published in the Official Journal of the EU, available in all official languages of the EU.

European Commission — Digital operational resilience (DORA) overview

Commission overview, delegated acts, and implementing technical standards

European Commission — Delegated and implementing acts for DORA

Delegated and implementing acts adopted under DORA

European Banking Authority (EBA) — DORA

EBA's DORA hub: RTS, ITS, consultations, and Q&A

European Securities and Markets Authority (ESMA) — DORA

ESMA's DORA hub and technical standards for investment firms and market infrastructure

European Insurance and Occupational Pensions Authority (EIOPA) — DORA

EIOPA's DORA hub for the insurance and pensions sector

ENISA (EU Agency for Cybersecurity) — Finance sector

ENISA's work on cybersecurity for the finance sector

Commission Implementing Regulation (EU) 2024/2956 — register of information templates

Official Journal text of the ITS establishing the standard templates for the DORA register of information

EBA — DORA register of information reporting

EBA's guidance, tools and reporting framework for submitting the register of information