Regulation (EU) 2022/2554 (DORA) governs digital operational resilience for the EU financial sector. It applies to financial entities — including credit institutions, payment institutions, investment firms, crypto-asset service providers, insurance and reinsurance undertakings, and 20+ other entity types — and to ICT third-party service providers serving them. Financial entities must implement an ICT risk management framework, an ICT incident management process, digital operational resilience testing, and third-party ICT risk management. The regulation applies from 17 January 2025.
What does DORA actually require?
Key obligations include: Establish an internal governance and control framework ensuring effective and prudent management of ICT risk; Maintain a sound, comprehensive, well-documented ICT risk management framework as part of the overall risk management system; Define and implement an ICT-related incident management process to detect, manage, and notify ICT-related incidents; Report major ICT-related incidents to the relevant competent authority; Establish and maintain a digital operational resilience testing programme (non-microenterprises); Carry out threat-led penetration testing at least every 3 years for entities identified under the Regulation.
Who is in scope of DORA?
DORA is in_force in European Union. Scope attaches based on jurisdiction and the role a company plays in the AI supply chain. See /frameworks/dora for the full scope note and source links.
When does DORA take effect?
The primary enforcement date is 2025-01-17. Some provisions may phase in earlier or later — see the framework brief for the full timeline.
What are the penalties?
Maximum penalties: For critical ICT third-party service providers, periodic penalty payments of up to 1% of average daily worldwide turnover in the preceding business year (Regulation (EU) 2022/2554).. Enforcement is carried out by the designated authorities in the jurisdiction.