Security
Regulation (EU) 2022/2554
DORA
Digital Operational Resilience Act
Banks, insurers and investment firms — and the ICT firms they lean on — must be able to take a cyber hit and keep running, with contracts, tests and an EU-level look at critical tech vendors.
Does this hit me?
You should see fewer ‘systems down’ days at your bank or insurer, not a new form to fill. Complaints still go to the firm and the financial supervisor, not a Union helpdesk.
Check in the wizardPick a country in the header to see who enforces this at home. Union text is not the last word for directives.
How it rolls in
Jan 2023
Entered into force.
Jan 2025
Main duties apply, with regulatory technical standards.
Why it exists
Finance already had capital rules. It did not have a single playbook for when the cloud, the payments rail or the core banking system goes down. DORA is that playbook.
What actually changes
- ICT risk sits with the board, not only the CISO: inventory, classification, incident clocks, and a tested response.
- Threat-led penetration testing for the larger firms, on a cycle.
- Written ICT third-party contracts with audit, exit and location terms — including intra-group and hyperscalers.
- Critical ICT third-party providers can be overseen at Union level, not only via the bank that hired them.
How it hits you
You should see fewer ‘systems down’ days at your bank or insurer, not a new form to fill. Complaints still go to the firm and the financial supervisor, not a Union helpdesk.
For citizens
What this does to everyday life
Rights, bills, and what you can ignore. You are usually not the one who files — companies and states are.
Your bank should still work after a cyber hit
DORA is a firm-level resilience law. You might notice fewer outages; you do not get a new dashboard. Outage complaints still go to the bank and the financial ombudsman.
Rights you actually get
- No new personal right under DORA. Ordinary payment and deposit protections still apply.
Costs and trade-offs
- None as a filing. Indirectly, banks’ IT costs sit in fees.
What you can do
- If a banking app is down, use the bank’s incident path and the national ombudsman if money is stuck.
What you can ignore
- You do not notify ESAs. The bank does.
If something goes wrong
The bank first, then the national financial ombudsman / NCA.
More citizen notes across files: For people
Heard this? Not quite.
Claim: This is just NIS2 for banks.
NIS2 is the horizontal cyber law. DORA is lex specialis for financial entities and their ICT chain — deeper contracts, testing and Union oversight of critical providers.
Latest official statements
All EU NewsNo tagged Commission, Parliament or Council statement in the current feeds.
Board one-pager
Board one-pager
Who this is for: EU critical entities and ICT providers. Regulation (EU) 2022/2554. Applies since 17 January 2025.
Scope
- You are a bank, insurer, investment firm, payment or e-money institution, trading venue, or another listed financial entity.
- You provide ICT services that a financial entity cannot easily replace.
First 90 days
- Week 1: Confirm entity type and simplified-regime eligibility.
- Week 2: Stand up the ICT-service register (including intra-group).
- Month 1: Gap the top 10 vendor contracts against the RTS clauses.
- This quarter: Incident taxonomy and 24h/72h clocks aligned with the RTS.
Penalties: Supervisory measures and fines under sector law; critical ICT providers face ESA oversight and periodic penalties.
For companies
How to stay on the right side of this file
Practical order of work, not a substitute for counsel. Financial entities in the Union and the ICT third-party providers they depend on.
You are probably
In if you are a financial entity in the Union, or an ICT third party to one — especially if you are critical.
Effort
A year-one programme, not a policy swap.
Budget
Ops + security + legal. The clauses fight is a commercial cost.
Roles in this file
The same company can wear more than one hat. Classify before you buy a tool.
Financial entity
Bank, insurer, investment firm, certain others in the DORA list.
Register, incident reporting, resilience tests, board accountability, vendor clauses.
Critical ICT third party
Designated at Union level.
Oversight by the ESAs, not only a customer contract.
Are you in scope?
Act now- You are a bank, insurer, investment firm, payment or e-money institution, trading venue, or another listed financial entity.
- You provide ICT services that a financial entity cannot easily replace.
Usually not, if
- A non-financial company that only has a business bank account.
- Purely internal IT with no financial-entity customer.
First moves
- Week 1Confirm entity type and simplified-regime eligibility.Legal / risk
- Week 2Stand up the ICT-service register (including intra-group).CIO
- Month 1Gap the top 10 vendor contracts against the RTS clauses.Procurement + legal
- This quarterIncident taxonomy and 24h/72h clocks aligned with the RTS.CISO
- If you are a small payment firm, use the simplified framework honestly — it is not a pass.
- If you sell SaaS to banks, expect to complete their DORA annex even if you are not ‘critical’.
If you skip this
- A supervisor asking for the ICT register you do not have.
- A cloud contract with no DORA exit and audit rights.
- Incident clocks missed because it was ‘only a vendor outage’.
Done looks like
- An ICT asset and vendor register the board has seen.
- Playbooks that match the clocks.
- A short list of truly critical vendors with DORA clauses signed.
Keep this evidence
- ICT register
- Incident logs
- TLPT scope if designated
- Board minutes on ICT risk
Ask vendors
- Will you contract the DORA mandatory terms (audit, access, exit, subcontracting)?
- Where is production data processed and by which sub-processors?
Where programmes usually break
- Register that omits intra-group and licensed software.
- Incident clocks that start when comms is ready, not when you knew.
Call counsel when
- You might be in scope as a small entity with a proportionate regime.
- Multi-regulated group.
- A designation as critical third party.
Enforcement
Supervisory measures and fines under sector law; critical ICT providers face ESA oversight and periodic penalties.
National competent authorities; EBA, ESMA, EIOPA; Lead Overseer for critical ICT third parties.
Need a stack, not one file? Open the company desk
Professional briefing
Legal architecture and duties
For counsel, compliance, and policy teams. Not advice. The Official Journal still wins.
- Instrument
- Regulation
- Legal basis
- Art 114 TFEU · Regulation (EU) 2022/2554
- Application
- Directly applicable since 17 January 2025, with RTS/ITS filling the clocks and templates.
Lex specialis for operational resilience in finance. NIS2 remains the horizontal cyber law; DORA goes deeper on ICT third parties, testing, and Union oversight of critical providers. Boards own the register.
How the file is built
Subject matter (Arts 1–4)
ICT risk management, incident reporting, digital operational resilience testing, and ICT third-party risk, including an Oversight Framework for critical ICT third-party providers.
Proportionality
A simplified ICT-risk framework exists for specified smaller entities. It is not a waiver of incident reporting or of third-party hygiene.
Operators
| Role | Who | Core duties |
|---|---|---|
| Financial entity | Listed in Art 2 — banks, insurers, investment firms, payments, trading venues, and others. | ICT risk framework, register, incidents, testing, third-party contracts. |
| ICT third-party provider | Cloud, software, data centres used by financial entities. | Contractual terms; if designated critical, ESA oversight. |
Scope
Financial entities in the Union; ICT providers wherever they sit if they serve those entities. Critical providers can be non-EU and still overseen.
In
- ICT services supporting financial functions
- Intra-group ICT
- Sub-outsourced chains
Out, or narrower than assumed
- Some very small entities via simplified regime — check Art 16 and the RTS
- Non-financial corporates with no financial-entity licence
Operative provisions
| Anchor | Rule | What it does in practice |
|---|---|---|
| Arts 5–16 | ICT risk management framework; simplified option for some. | Board approval and review cycles; inventory is the operational heart. |
| Arts 17–23 | Incident classification and reporting to competent authorities. | Align clocks with the ITS; do not invent a private severity scale. |
| Arts 24–27 | Testing, including TLPT for specified entities. | Threat-led tests are scoped with the supervisor, not a vanity red-team. |
| Arts 28–44 | Third-party risk, register, and Oversight Framework. | Mandatory contractual elements; designation of critical providers at Union level. |
Secondary law and guidance
- RTS/ITS on ICT risk, incidents, TLPT, register templates
- ESA joint guidelines
National layer. Authorisation and day-to-day supervision remain national NCAs. Designation of critical ICT providers is Union-level.
How it sits with other files
DORA is lex specialis for financial entities; do not double-report blindly — map the incident to both regimes.
Personal-data incidents still have a 72-hour DPA clock alongside DORA ICT-incident reporting.
Product security of software used in finance sits under CRA; DORA sits on the entity using it.
Enforcement and private rights
Who
NCAs; ESAs; Lead Overseer for critical ICT.
Tools
Supervisory measures, fines under sector law, periodic penalty payments on critical providers.
Private rights
Contractual; no special DORA damages action.
Risk register
| Risk | Signal | Control |
|---|---|---|
| Uncontracted hyperscaler | MSA missing DORA mandatory terms | Negotiation programme with fallback architecture. |
| Late incident | Clock starts at comms approval | Operational definition of ‘detection’ in the playbook. |
Open issues
- How aggressively ESAs designate non-EU hyperscalers.
- Overlap friction with NIS2 reporting in Member States.
Primary sources
Banks, insurers, investment firms and their critical ICT suppliers must survive a cyber hit — with contracts, tests, and Union oversight for the biggest providers.
You feel it now
Applies since 17 January 2025.
Next
Oversight of critical third parties and the second round of TLPT.
Where it lands
| Channel | People | Companies |
|---|---|---|
| Your account | Fewer unexplained outages. Complaints stay with the bank and the ombudsman, not DORA as a citizen form. | ICT risk register, incident clocks, threat-led tests for the significant, contractual clauses that vendors will hate. |
Who gains
Customers of firms that can fail over; boards that can show the register.
Who pays
ICT vendors who refused the clauses and still want bank logos.
Who pays
Financial groups and the ICT vendors they cannot live without.
Who benefits
Depositors and policyholders, if the tests are real.
Read the official text