Compliance · EU
EU Regulation 2022/2554In force since January 2025

DORA

Plain-English definition

The Digital Operational Resilience Act is an EU regulation, directly applicable since January 17, 2025, requiring financial entities (banks, insurers, investment firms, and more) and their critical ICT third-party providers to build a formal ICT risk management framework, report major ICT incidents on tight timelines, and regularly test digital operational resilience, including threat-led penetration testing for significant entities.

Unlike most cybersecurity regulation, DORA explicitly extends obligations to critical ICT vendors, not just the regulated financial entities themselves.

Who needs it

EU-regulated financial entities including banks, insurers, investment firms, payment institutions, and crypto-asset service providers, plus their critical ICT third-party providers who are brought into scope through contractual and oversight requirements.

Key requirements

A documented ICT risk management framework, major-incident classification and reporting to regulators on defined timelines, regular digital operational resilience testing (including threat-led penetration testing for significant entities), and a register of information on all ICT third-party arrangements.

Cyber/privacy implications

Incident reporting timelines are tight and specific (initial notification, intermediate report, and final report each on defined windows), which means detection and escalation processes have to be fast enough to meet a regulatory clock, not just an internal SLA.

Assessment methodology

ICT risk management framework gap assessment, third-party ICT provider register build-out, incident classification and reporting process design, and resilience testing program scoping including threat-led penetration testing where applicable.

Implementation phases

01
Assess

Gap analysis against the ICT risk management framework and third-party register requirements.

02
Build

Implement incident classification/reporting processes and resilience testing program.

03
Test

Execute resilience testing, including threat-led penetration testing for significant entities.

Evidence & documentation requirements

ICT risk management framework documentation, the register of information on ICT third-party providers, incident classification and reporting records, and resilience testing results including any threat-led penetration testing reports.

Common mistakes

Treating DORA as purely an IT-department concern when it explicitly requires management-body accountability; under-documenting the ICT third-party register, which regulators specifically examine given DORA's focus on concentration risk from critical vendors.

Related standards

Expert review

Nitzan Levi
Nitzan Levi
Co-Founder, Cybecs · Co-Founder, RedRok · Executive Director, Privacy & GRC · CISM, CISSP, CDPSE, CCSK, CSA

FAQ

Are we in scope if we're an ICT vendor, not a financial entity?
If you're designated a critical ICT third-party provider to in-scope financial entities, yes, DORA extends obligations and regulatory oversight to you directly.
What counts as a 'major' ICT incident requiring reporting?
Determined by DORA's classification criteria covering factors like the number of clients affected, duration, geographic spread, and data losses; we help build the classification logic specific to your risk profile.
Do we need threat-led penetration testing?
Required specifically for entities designated as significant under DORA's criteria; smaller in-scope entities still need resilience testing, just not necessarily the TLPT variant.

Request a Gap Assessment

See where your ICT risk management framework stands against DORA's requirements.

Request a Gap Assessment →