Skip to content

DORA Glossary

Clear, accessible definitions of the technical terms related to DORA and financial sector cybersecurity.

Business continuity plan (BCP/DRP)
The arrangements that allow a financial entity to maintain or resume its critical activities after an ICT incident.
DORA
Digital Operational Resilience Act — EU Regulation (EU) 2022/2554 on digital operational resilience for the financial sector.
Financial entity
Any organisation listed in Article 2 of DORA: bank, insurer, investment firm, crypto-asset provider...
European Supervisory Authorities (ESAs)
EBA, ESMA and EIOPA — the three authorities that draft DORA's technical standards and oversee critical ICT providers.
ICT risk management
DORA's first pillar: the governance, protection and continuity framework every financial entity must put in place.
Major ICT-related incident
An ICT incident whose severity exceeds defined thresholds, triggering an obligation to notify the authorities.
Lead Overseer
The European authority designated to directly oversee a critical third-party ICT provider.
Lex specialis
The legal principle by which DORA takes precedence over the NIS2 directive for the financial entities it covers.
NIS2
The European cybersecurity directive, for which DORA is the specialised track for the financial sector.
Third-party ICT provider
Any external provider (cloud, hosting, SaaS...) that a financial entity relies on for its ICT functions.
Principle of proportionality
The way DORA's requirements are adapted to the size, risk profile and systemic importance of each entity.
Register of information
The document listing all of a financial entity's contracts with its ICT service providers.
Digital operational resilience
A financial entity's ability to prevent, withstand, respond to and recover from an ICT-related disruption.
RTS / ITS
Regulatory and implementing technical standards that specify how DORA's requirements are applied in practice.
ICT
Information and Communication Technologies — the systems, software and networks whose resilience DORA regulates.
TLPT
Threat-Led Penetration Testing — penetration tests based on real threats, mandatory for the most significant financial entities.