Digital Operational Resilience Act
Regulation (EU) 2022/2554 (DORA) governs digital operational resilience for the EU financial sector. It applies to financial entities — including credit institutions, payment institutions, investment firms, crypto-asset service providers, insurance and reinsurance undertakings, and 20+ other entity types — and to ICT third-party service providers serving them. Financial entities must implement an ICT risk management framework, an ICT incident management process, digital operational resilience testing, and third-party ICT risk management. The regulation applies from 17 January 2025.
Jurisdiction
European Union
Enforcement
January 17, 2025
Maximum penalty
For critical ICT third-party service providers, periodic penalty payments of up to 1% of average daily worldwide turnover in the preceding business year (Regulation (EU) 2022/2554).
Key obligations
- 01Establish an internal governance and control framework ensuring effective and prudent management of ICT risk
- 02Maintain a sound, comprehensive, well-documented ICT risk management framework as part of the overall risk management system
- 03Define and implement an ICT-related incident management process to detect, manage, and notify ICT-related incidents
- 04Report major ICT-related incidents to the relevant competent authority
- 05Establish and maintain a digital operational resilience testing programme (non-microenterprises)
- 06Carry out threat-led penetration testing at least every 3 years for entities identified under the Regulation
- 07Maintain a register of information on all contractual arrangements with ICT third-party service providers
- 08Perform pre-contract due diligence and risk assessment of prospective ICT third-party service providers
- 09Put in place exit strategies for ICT services supporting critical or important functions
- 10Include ICT security awareness and digital operational resilience training as compulsory staff modules
Vendors that support DORA
Sorted by coverage level. Full coverage shown first.
0 vendors
Compare across industries
See which vendors support DORA in your sector.
Last verified September 21, 2026. Informational summary only — not legal advice. Consult qualified counsel for specific obligations.