Skip to content
EU Regulation 2022/2554

The DORA regulation made accessible

Understand, comply, train. CyberDORA helps financial sector companies navigate the requirements of the European regulation on digital operational resilience, without unnecessary jargon.

5

Pillars of DORA compliance

~20

Types of financial entities covered (Art. 2)

17 Jan 2025

Date DORA became fully applicable

1%

Max. daily penalty for a critical ICT provider

Why this site?

DORA is a major European regulation for the financial sector's cybersecurity. Yet its requirements are often seen as complex and reserved for experts. CyberDORA's mission is to make them understandable and actionable for every organisation concerned.

Timeline

Where do we stand?

DORA's timeline in Europe

Adopted
December 2022
Adoption of the European regulation
The DORA regulation (EU) 2022/2554 is published in the Official Journal of the EU.
Adopted
January 2023
Entry into force
DORA enters into force on 16 January 2023, opening a two-year transition period for the entities concerned.
Adopted
2024
Publication of technical standards
The European Supervisory Authorities (EBA, ESMA, EIOPA) publish the RTS/ITS standards detailing DORA's operational requirements.
In force
17 January 2025
DORA fully applicable
DORA is now fully applicable across all Member States: compliance controls and obligations are now in effect.

Ready to get compliant?

Follow our maturity test to assess your organisation's level of readiness for DORA's requirements.

Start the maturity test