EUImpact
All laws

Security

Regulation (EU) 2022/2554

DORA

Digital Operational Resilience Act

In force nowApplies since 17 January 2025

Banks, insurers and investment firms — and the ICT firms they lean on — must be able to take a cyber hit and keep running, with contracts, tests and an EU-level look at critical tech vendors.

Does this hit me?

You should see fewer ‘systems down’ days at your bank or insurer, not a new form to fill. Complaints still go to the firm and the financial supervisor, not a Union helpdesk.

Check in the wizard

Pick a country in the header to see who enforces this at home. Union text is not the last word for directives.

How it rolls in

  1. Jan 2023

    Entered into force.

  2. Jan 2025

    Main duties apply, with regulatory technical standards.

Why it exists

Finance already had capital rules. It did not have a single playbook for when the cloud, the payments rail or the core banking system goes down. DORA is that playbook.

What actually changes

  • ICT risk sits with the board, not only the CISO: inventory, classification, incident clocks, and a tested response.
  • Threat-led penetration testing for the larger firms, on a cycle.
  • Written ICT third-party contracts with audit, exit and location terms — including intra-group and hyperscalers.
  • Critical ICT third-party providers can be overseen at Union level, not only via the bank that hired them.

How it hits you

You should see fewer ‘systems down’ days at your bank or insurer, not a new form to fill. Complaints still go to the firm and the financial supervisor, not a Union helpdesk.

Everyday people2/5
Organisations5/5

For citizens

What this does to everyday life

Rights, bills, and what you can ignore. You are usually not the one who files — companies and states are.

Your bank should still work after a cyber hit

DORA is a firm-level resilience law. You might notice fewer outages; you do not get a new dashboard. Outage complaints still go to the bank and the financial ombudsman.

Rights you actually get

  • No new personal right under DORA. Ordinary payment and deposit protections still apply.

Costs and trade-offs

  • None as a filing. Indirectly, banks’ IT costs sit in fees.

What you can do

  • If a banking app is down, use the bank’s incident path and the national ombudsman if money is stuck.

What you can ignore

  • You do not notify ESAs. The bank does.

If something goes wrong

The bank first, then the national financial ombudsman / NCA.

More citizen notes across files: For people

Heard this? Not quite.

Claim: This is just NIS2 for banks.

NIS2 is the horizontal cyber law. DORA is lex specialis for financial entities and their ICT chain — deeper contracts, testing and Union oversight of critical providers.

Latest official statements

All EU News

No tagged Commission, Parliament or Council statement in the current feeds.

Read the official text