What is Digital Operational Resilience Act (DORA)?
The EU regulation, (EU) 2022/2554, that sets ICT risk management, incident reporting, resilience testing and third-party risk rules for financial entities. It has applied since 17 January 2025.
How it works
DORA applies to banks, insurers, investment firms, payment institutions, crypto-asset service providers and many others, plus critical ICT third-party providers designated by EU supervisors.
It is built around five areas: ICT risk management, ICT incident reporting, digital operational resilience testing (including threat-led penetration testing for some firms), ICT third-party risk and information sharing.
Key points
- Applies to EU financial entities since 17 January 2025
- Five pillars covering risk, incidents, testing, suppliers and sharing
- Requires a register of ICT third-party arrangements
- Some firms must run threat-led penetration tests
Common questions
Does DORA override NIS2?
For financial entities, DORA is the sector-specific law and takes precedence where the two overlap.
What is TLPT?
Threat-led penetration testing: an intelligence-driven red team exercise required of certain financial entities under DORA.
Talk to someone who does this every day
Questions about DORA? Our team will give you a straight answer.