Digital Operational Resilience Act (EU)

European UnionFinancial Services2022
ByDecipherU Editorial

DORA (Regulation (EU) 2022/2554) is an EU regulation establishing uniform cybersecurity and operational resilience requirements for the financial sector. Effective January 17, 2025, it applies to banks, insurance companies, investment firms, payment providers, crypto-asset service providers, and their critical ICT third-party service providers. DORA mandates ICT risk management frameworks, incident reporting, digital operational resilience testing, and oversight of critical third-party ICT providers.

Quick Reference

EnactedDecember 14, 2022; effective January 17, 2025
Enforcement BodyEuropean Supervisory Authorities (EBA, ESMA, EIOPA) and national competent authorities
PenaltiesMember states set penalties; critical third-party ICT providers face periodic penalty payments up to 1% of average daily worldwide turnover for each day of non-compliance, for up to 6 months
Applicable ToFinancial entities (banks, insurers, investment firms, payment institutions, crypto-asset service providers) and critical ICT third-party service providers operating in the EU

Key Requirements

Article 6 (ICT Risk Management Framework)

Financial entities must implement and maintain a sound, documented ICT risk management framework including identification, protection, detection, response, and recovery capabilities

Article 19 (ICT-related Incident Reporting)

Financial entities must classify ICT-related incidents using criteria defined by the ESAs, report major incidents to competent authorities, and notify clients when the incident impacts their financial interests

Article 26 (Digital Operational Resilience Testing)

Financial entities must conduct regular digital operational resilience testing including vulnerability assessments, network security testing, and threat-led penetration testing (TLPT) for significant entities at least every 3 years

Article 28 (Third-party ICT Risk Management)

Financial entities must manage ICT third-party risk through maintained registers of ICT service contracts, pre-contractual due diligence, contractual requirements, and ongoing monitoring of provider performance

How Does EU DORA Affect Cybersecurity Careers?

DORA creates significant demand for cybersecurity professionals in European financial services. GRC analysts must build DORA compliance programs covering ICT risk management, incident reporting, and third-party oversight. Penetration testers must understand TLPT (Threat-Led Penetration Testing) frameworks like TIBER-EU. Third-party risk management roles are growing as financial institutions must oversee their critical ICT service providers under DORA.

How Does EU DORA Affect Cybersecurity Sales?

DORA drives cybersecurity spending across the entire EU financial sector. ICT risk management platforms, incident reporting tools, penetration testing services, third-party risk management solutions, and operational resilience testing platforms all serve DORA compliance needs. The regulation's scope includes crypto-asset service providers, expanding the addressable market beyond traditional financial services.

Cybersecurity Roles That Work With EU DORA

Related Cybersecurity Certifications

Related Cybersecurity Laws

Read the full text of EU DORA at the official source: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022R2554

Frequently Asked Questions

DORA (Regulation (EU) 2022/2554) is an EU regulation establishing uniform cybersecurity and operational resilience requirements for the financial sector. Effective January 17, 2025, it applies to banks, insurance companies, investment firms, payment providers, crypto-asset service providers, and their critical ICT third-party service providers. DORA mandates ICT risk management frameworks, incident reporting, digital operational resilience testing, and oversight of critical third-party ICT providers.

DORA creates significant demand for cybersecurity professionals in European financial services. GRC analysts must build DORA compliance programs covering ICT risk management, incident reporting, and third-party oversight. Penetration testers must understand TLPT (Threat-Led Penetration Testing) frameworks like TIBER-EU. Third-party risk management roles are growing as financial institutions must oversee their critical ICT service providers under DORA.

Member states set penalties; critical third-party ICT providers face periodic penalty payments up to 1% of average daily worldwide turnover for each day of non-compliance, for up to 6 months

Last verified: April 2026?Report an inaccuracy

Explore Related Cybersecurity Resources

Was this page helpful?