DORA – Digital Operational Resilience Act
What Is DORA?
The Digital Operational Resilience Act (DORA) is an EU regulation ensuring that financial-sector
entities can withstand, respond to, and recover from ICT (Information and Communication
Technology) disruptions and cyber threats.
Who Does It Apply To?
DORA applies to banks, insurers, investment firms, payment institutions, crypto-asset service
providers, credit rating agencies, crowdfunding platforms, and critical ICT third-party providers.
Key Components of DORA
1. ICT Risk Management
Entities must implement governance, monitoring, incident detection, business continuity, and
disaster recovery plans.
2. Incident Reporting
Major ICT incidents must be reported quickly and consistently to regulators.
3. Digital Operational Resilience Testing
Includes vulnerability assessments, penetration tests, and for key institutions, threat-led penetration
testing (TLPT).
4. ICT Third-Party Risk Management
Strong oversight of ICT vendors is required, including cloud services, contractual standards, and
continuous monitoring.
5. Information Sharing
Organizations may share cyber threat intelligence to increase resilience, following data protection
laws.
Why DORA Matters
DORA strengthens cybersecurity, enhances operational resilience, improves oversight of ICT risks,
and ensures continuity of vital financial services across the EU.