HomeFrameworksFinancial ServicesDORA

Framework  Financial Services

DORA

The Digital Operational Resilience Act, Regulation (EU) 2022/2554, is the EU rule that makes financial firms prove they can keep operating through ICT failures and cyber attacks.

It applies directly in every member state from January 17, 2025 and covers five areas: ICT risk management, ICT incident reporting, digital operational resilience testing, management of ICT third-party risk, and information sharing. It also brings the largest ICT providers to the financial sector under direct oversight by the European Supervisory Authorities.

On paper, a financial entity needs a documented ICT risk management framework approved by its management body and reviewed at least once a year, an ICT business continuity policy and response and recovery plans, an incident classification and reporting procedure, a testing program, a policy on the use of ICT third-party services, and a register of information listing every ICT contract.

Smaller entities may use the simplified framework, but the documents still have to exist.

AI-compiled
Share
Sponsored
DORA
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Comply the Modern WayFind help with DORA
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here

Who has to comply

Around twenty categories of EU financial entities including credit institutions, payment and e-money institutions, investment firms, crypto-asset service providers, central securities depositories, trading venues, insurers and reinsurers, insurance intermediaries above the size threshold, and fund managers.

ICT third-party providers designated as critical fall under the ESAs' oversight framework.

What the assessor asks to see

Supervisors ask for the management-body-approved ICT risk management framework and evidence of its annual review, the ICT asset inventory and business impact analysis, the ICT business continuity policy and tested response and recovery plans, the incident classification procedure and incident log with reports filed, the testing program and results, the ICT third-party policy, the register of information with contract clauses, exit strategies for critical providers, and training records for the management body.

Where the requirement sits: DORA Arts 5-16, 17-23, 24-27, 28-30

Key dates

Adopted December 14, 2022; published in the Official Journal December 27, 2022; applies from January 17, 2025. Regulatory and implementing technical standards on incident classification, the register of information, and subcontracting were finalized in 2024 and 2025. First annual submissions of registers of information ran through national authorities in 2025.

Assessors

Who assesses DORA

National competent authorities for each entity type (for example BaFin, the CSSF, the Central Bank of Ireland, the AMF and ACPR) supervise and enforce. The ESAs act as lead overseers for critical ICT third-party providers. There is no certification scheme; supervision is by regulator review and inspection.

Supervisory authority is set out in the regulation and national implementing law.

No firm has claimed a DORA assessor listing yet. Claim yours →

Consultants

Who helps with DORA

A large consulting market of Big Four practices, cyber and GRC consultancies, and law firms. Engagements typically run a gap assessment, draft the ICT risk framework and third-party policy, build the register of information, and set up the incident classification process. Threat-led penetration testing must be run by qualified testers under the TIBER-EU style framework.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

No firm has claimed a DORA consultant listing yet. Claim yours →

Related reading

  1. The EU's Digital Operational Resilience Act (DORA) - 2024 UpdateCovers scope, the contract terms firms must renegotiate with ICT providers, and the board-level duties DORA creates.Skadden, Arps, Slate, Meagher & Flom
  2. Cybersecurity in the Financial Sector: EU's Digital Operational Resilience Act Takes EffectBreaks DORA into its pillars and names the documents in scope, from the information security policy to the register of information.Mayer Brown

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for DORA

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Not sure where to start?

Get Help with DORA

Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

[email protected]
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

[email protected]
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.