Framework Financial Services
DORA
The Digital Operational Resilience Act, Regulation (EU) 2022/2554, is the EU rule that makes financial firms prove they can keep operating through ICT failures and cyber attacks.
It applies directly in every member state from January 17, 2025 and covers five areas: ICT risk management, ICT incident reporting, digital operational resilience testing, management of ICT third-party risk, and information sharing. It also brings the largest ICT providers to the financial sector under direct oversight by the European Supervisory Authorities.
On paper, a financial entity needs a documented ICT risk management framework approved by its management body and reviewed at least once a year, an ICT business continuity policy and response and recovery plans, an incident classification and reporting procedure, a testing program, a policy on the use of ICT third-party services, and a register of information listing every ICT contract.
Smaller entities may use the simplified framework, but the documents still have to exist.
help
Who has to comply
Around twenty categories of EU financial entities including credit institutions, payment and e-money institutions, investment firms, crypto-asset service providers, central securities depositories, trading venues, insurers and reinsurers, insurance intermediaries above the size threshold, and fund managers.
ICT third-party providers designated as critical fall under the ESAs' oversight framework.
What the assessor asks to see
Supervisors ask for the management-body-approved ICT risk management framework and evidence of its annual review, the ICT asset inventory and business impact analysis, the ICT business continuity policy and tested response and recovery plans, the incident classification procedure and incident log with reports filed, the testing program and results, the ICT third-party policy, the register of information with contract clauses, exit strategies for critical providers, and training records for the management body.
Where the requirement sits: DORA Arts 5-16, 17-23, 24-27, 28-30
Key dates
Adopted December 14, 2022; published in the Official Journal December 27, 2022; applies from January 17, 2025. Regulatory and implementing technical standards on incident classification, the register of information, and subcontracting were finalized in 2024 and 2025. First annual submissions of registers of information ran through national authorities in 2025.
Assessors
Who assesses DORA
National competent authorities for each entity type (for example BaFin, the CSSF, the Central Bank of Ireland, the AMF and ACPR) supervise and enforce. The ESAs act as lead overseers for critical ICT third-party providers. There is no certification scheme; supervision is by regulator review and inspection.
Supervisory authority is set out in the regulation and national implementing law.
No firm has claimed a DORA assessor listing yet. Claim yours →
Consultants
Who helps with DORA
A large consulting market of Big Four practices, cyber and GRC consultancies, and law firms. Engagements typically run a gap assessment, draft the ICT risk framework and third-party policy, build the register of information, and set up the incident classification process. Threat-led penetration testing must be run by qualified testers under the TIBER-EU style framework.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
No firm has claimed a DORA consultant listing yet. Claim yours →
Software
Tools for DORA
Tools that name this framework in their own material.
Related reading
- The EU's Digital Operational Resilience Act (DORA) - 2024 UpdateCovers scope, the contract terms firms must renegotiate with ICT providers, and the board-level duties DORA creates.Skadden, Arps, Slate, Meagher & Flom
- Cybersecurity in the Financial Sector: EU's Digital Operational Resilience Act Takes EffectBreaks DORA into its pillars and names the documents in scope, from the information security policy to the register of information.Mayer Brown
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for DORA
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
Not sure where to start?
Get Help with DORA
Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.