What is Digital Operational Resilience Act (DORA)?
The digital operational resilience regulation known as DORA is Regulation (EU) 2022/2554, a directly applicable European Union framework for financial-sector digital resilience. It applies from 17 January 2025 to defined financial entities and establishes EU oversight arrangements for critical ICT third-party service providers. Its connected pillars address ICT risk management, incident classification and reporting, operational-resilience testing, ICT third-party risk, oversight, and voluntary threat-intelligence sharing. DORA aligns governance and technical resilience rather than treating outages, cyber incidents, and supplier dependencies as separate concerns. Scope and duties depend on the entity, proportionality provisions, and applicable regulatory technical standards. This summary is educational and does not replace legal or supervisory interpretation.
What is Digital Operational Resilience Act (DORA) used for?
In-scope organizations use DORA to structure management-body accountability, ICT asset and dependency visibility, protection and detection, recovery, major-incident handling, testing, and supervisory evidence. Certain entities must conduct threat-led penetration testing under defined conditions. Third-party governance includes contractual requirements, concentration and exit risk, registers of information, and oversight-related cooperation. Business Continuity Plan (BCP), Disaster Recovery Plan (DRP), and Incident Response Plan (IRP) practices can support the operating model, but no framework alone proves compliance. Leaders should integrate resilience into Governance, Risk, and Compliance (GRC), procurement, architecture, operations, and crisis decision-making. Applicability, reporting thresholds, testing frequency, and detailed evidence requirements must be assessed against the official regulation plus relevant delegated and implementing acts.