Compliance

What is Digital Operational Resilience Act (DORA)?

Definition

The EU regulation, (EU) 2022/2554, that sets ICT risk management, incident reporting, resilience testing and third-party risk rules for financial entities. It has applied since 17 January 2025.

How it works

DORA applies to banks, insurers, investment firms, payment institutions, crypto-asset service providers and many others, plus critical ICT third-party providers designated by EU supervisors.

It is built around five areas: ICT risk management, ICT incident reporting, digital operational resilience testing (including threat-led penetration testing for some firms), ICT third-party risk and information sharing.

Key points

  • Applies to EU financial entities since 17 January 2025
  • Five pillars covering risk, incidents, testing, suppliers and sharing
  • Requires a register of ICT third-party arrangements
  • Some firms must run threat-led penetration tests

Common questions

Does DORA override NIS2?

For financial entities, DORA is the sector-specific law and takes precedence where the two overlap.

What is TLPT?

Threat-led penetration testing: an intelligence-driven red team exercise required of certain financial entities under DORA.

Talk to someone who does this every day

Questions about DORA? Our team will give you a straight answer.

Contact us