Glossary · DORA
DORA
The Digital Operational Resilience Act, Regulation (EU) 2022/2554, the EU's ICT security law for the financial sector, applicable since 17 January 2025.
Explained in depth: DORA overview
DORA sets harmonised requirements for the digital operational resilience of the EU financial sector. It applies to over 20 categories of financial entities, including banks, insurers, investment firms, payment and e-money institutions, crypto-asset service providers, and, uniquely, to the critical ICT third-party providers that serve them. As a regulation, DORA applies directly in every member state without national transposition. DORA rests on five pillars: ICT risk management, ICT-related incident reporting, digital operational resilience testing (including TLPT for the most significant entities), management of ICT third-party risk (including the register of information and mandatory contract clauses), and information sharing. It became applicable on 17 January 2025.
Why it matters
For financial entities, DORA is lex specialis to NIS2: they follow DORA's requirements instead. For everyone selling ICT services to the financial sector, DORA arrives through customer contracts, whether or not the vendor is directly regulated.
