Skip to content
Digital Operational Resilience Act

Resiliencestopped beinga policy andbecame a duty.

DORA has applied since 17 January 2025. It takes what used to be internal IT governance and makes it a supervised obligation, with named deadlines, a register a regulator can ask for, and an oversight regime that reaches past the financial entity to the providers it depends on.
In force
16 January 2023
Applies from
17 January 2025
Binds
21 types of financial entity
Reaches
Their ICT third-party providers
Who it binds

Twenty-one kinds of financial entity, and the providers behind them.

Banks, insurers and intermediaries, investment firms, payment and e-money institutions, crypto-asset service providers, trading venues, fund managers and more. The obligation is the entity's, but the Regulation does not stop at its perimeter: it reaches the ICT providers the entity depends on, and it establishes a Union oversight framework for those designated critical.

What it requires

Chapter II

An ICT risk framework the board owns

The management body carries the responsibility and cannot delegate it away. The framework has to be documented, reviewed, and tested against the entity's own dependencies rather than a template.

Art. 19

A major incident is reported on the clock

Major ICT-related incidents are classified and notified to the competent authority. The technical standards set the timing: an initial notification within four hours of the incident being classified as major and no later than 24 hours from becoming aware of it, an intermediate report within 72 hours of that notification, and a final report within one month.

Art. 26

Threat-led penetration testing, at least every three years

Entities identified by their authority carry out advanced testing on live production systems. Significant institutions use external red team testers; an entity testing with its own people has to bring external testers in every third test.

Art. 27

The testers themselves must be insured

Testers must be certified, possess the necessary expertise and suitability, and hold professional indemnity insurance. It is one of the few places where a European regulation names insurance as a condition of doing the work at all.

Art. 28(3)

A register of every ICT arrangement

A register of information on all contractual arrangements with ICT third-party service providers, maintained at entity, sub-consolidated and consolidated level, in the format set by Commission Implementing Regulation (EU) 2024/2956. It is the document that turns 'we use a cloud provider' into a supervisable fact.

Art. 31

Critical providers are supervised directly

ICT third-party providers designated critical fall under a Union oversight framework with a lead overseer, alongside the supervision of the entities using them. Concentration in a handful of providers became a regulatory subject rather than a market observation.

Where insurance appears in the text

Article 27 makes cover a precondition, not a mitigation.

Art. 27
Most regulation treats insurance as something a firm may hold. DORA, in the requirements for testers, treats it as something a tester must hold before the work can be commissioned. For anyone selling penetration testing into European financial entities, professional indemnity cover stopped being commercial prudence on 17 January 2025 and became a qualification.

Source

Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector. Article numbers refer to the Regulation as published in the Official Journal; the reporting deadlines named above are set by the regulatory technical standards adopted under it. Nothing on this page is legal advice.
Technology

Underwriting isan informationproblem. We treatit as one.