AI Compliance Vendors

What is DORA?

Regulation (EU) 2022/2554 (DORA) governs digital operational resilience for the EU financial sector. It applies to financial entities — including credit institutions, payment insti

Last updated September 21, 2026 · Every fact traceable to a public source

Regulation (EU) 2022/2554 (DORA) governs digital operational resilience for the EU financial sector. It applies to financial entities — including credit institutions, payment institutions, investment firms, crypto-asset service providers, insurance and reinsurance undertakings, and 20+ other entity types — and to ICT third-party service providers serving them. Financial entities must implement an ICT risk management framework, an ICT incident management process, digital operational resilience testing, and third-party ICT risk management. The regulation applies from 17 January 2025.

What does DORA actually require?

Key obligations include: Establish an internal governance and control framework ensuring effective and prudent management of ICT risk; Maintain a sound, comprehensive, well-documented ICT risk management framework as part of the overall risk management system; Define and implement an ICT-related incident management process to detect, manage, and notify ICT-related incidents; Report major ICT-related incidents to the relevant competent authority; Establish and maintain a digital operational resilience testing programme (non-microenterprises); Carry out threat-led penetration testing at least every 3 years for entities identified under the Regulation.

Who is in scope of DORA?

DORA is in_force in European Union. Scope attaches based on jurisdiction and the role a company plays in the AI supply chain. See /frameworks/dora for the full scope note and source links.

When does DORA take effect?

The primary enforcement date is 2025-01-17. Some provisions may phase in earlier or later — see the framework brief for the full timeline.

What are the penalties?

Maximum penalties: For critical ICT third-party service providers, periodic penalty payments of up to 1% of average daily worldwide turnover in the preceding business year (Regulation (EU) 2022/2554).. Enforcement is carried out by the designated authorities in the jurisdiction.

Related

Editorial independence

This FAQ is editorial. No vendor can pay to be highlighted or ranked in answers, and the written commentary on this page is payment-free. Featured slots in directory listings are always labeled where they appear. Read our methodology for details.