Skip to content
EU Regulation 2022/2554

What is DORA?

Everything you need to know about the European regulation on digital operational resilience for the financial sector.

1Before DORA: a fragmented framework

The growing digitalisation of banks, insurers and investment firms has made the financial sector dependent on its IT systems — and therefore vulnerable to cyberattacks, technical failures and the failures of its technology providers. Before DORA, digital security requirements were scattered across sectoral rules (banking, insurance, markets) and non-harmonised national recommendations, creating gaps in maturity and supervision between Member States.

The key insight: an ICT incident at a major technology provider shared by several banks can now have a systemic effect on the entire European financial sector. DORA addresses this risk with a single, harmonised framework.

Are you affected by DORA?

Assess your level of readiness or check your obligations directly based on your organisation's profile.

2The DORA regulation (2022)

Regulation (EU) 2022/2554 (Digital Operational Resilience Act) was published in the Official Journal of the EU on 27 December 2022 and entered into force on 16 January 2023. After a two-year transition period, it has been fully applicable since 17 January 2025 in all Member States.

Regulation, not a directive
Directly applicable in all Member States, with no national transposition law — unlike NIS2.
Lex specialis for finance
For the entities it covers, DORA takes precedence over NIS2: the financial sector follows a dedicated cyber framework.
Principle of proportionality
Requirements are adapted to the size, risk profile and systemic importance of each entity.

The 5 pillars of DORA compliance

DORA structures its requirements around five complementary pillars covering the entire digital risk lifecycle.

1
ICT risk management
Establish a governance and risk management framework for information and communication technologies (ICT): asset mapping, protection, detection, and business continuity planning.
2
ICT-related incident management
Detect, classify and report ICT-related incidents according to harmonised criteria, with strict notification deadlines for major incidents to the competent authorities.
3
Digital operational resilience testing
Regularly test the resilience of systems, including through threat-led penetration testing (TLPT) for the most significant entities.
4
ICT third-party risk management
Contractually govern providers (cloud, hosting, SaaS...) and subject providers deemed critical to direct oversight by European authorities.
5
Information sharing
Encourage the voluntary exchange of information and intelligence on cyber threats between financial entities, to strengthen the sector's collective resilience.

Who is affected?

DORA applies to around twenty categories of financial entities defined in Article 2 of the regulation, as well as to their ICT service providers.

Financial entities covered
  • Credit institutions (banks)
  • Payment and e-money institutions
  • Investment firms
  • Crypto-asset service providers and issuers of tokens
  • Central securities depositories and central counterparties
  • Trading venues and trade repositories
  • Management companies and alternative investment fund managers
  • Insurance and reinsurance undertakings, intermediaries
  • Institutions for occupational retirement provision
  • Credit rating agencies and administrators of critical benchmarks
  • Crowdfunding service providers
  • ICT third-party service providers (including critical providers)
Proportionate regime and exemptions
  • Micro-enterprises and certain small, non-interconnected investment firms, under a simplified risk management regime (Article 16).
  • Small payment and e-money institutions exempted under the PSD2 directive.
  • Small institutions for occupational retirement provision (fewer than 15 members).
  • Insurance, reinsurance and ancillary insurance intermediaries qualifying as micro, small or medium-sized enterprises.

DORA and NIS2: what's the difference?

Both texts coexist, but DORA acts as lex specialis: a financial entity covered by DORA applies DORA rather than NIS2 for its cybersecurity.

CriterionDORANIS2
Type of textRegulation (EU) — directly applicable, no transpositionDirective (EU) — transposed by each Member State
Sector coveredFinancial sector only (~20 categories of entities)18 sectors (energy, health, transport, digital...)
RelationshipLex specialis: takes precedence over NIS2 for the entities it coversApplies by default, except for sectoral lex specialis
Resilience testingTLPT mandatory for significant entitiesNo harmonised TLPT requirement at this level
Third-party providersDirect oversight of critical ICT providersNo equivalent direct oversight framework