All frameworks
EU regulationEU financial sector

DORA

Digital Operational Resilience Act (EU) 2022/2554

DORA regulates ICT risk management, incident reporting, resilience testing and third-party risk for twenty types of financial entity, and reaches their ICT suppliers through mandatory contract terms and an oversight framework for critical providers. It has applied since 17 January 2025.

Who it reaches

  • Banks, payment and e-money institutions, investment firms, crypto-asset service providers, insurers, pension funds, trading venues and other financial entities in the EU.
  • ICT third-party providers to those entities: cloud, software, data and managed services.
  • Providers designated as critical by the European Supervisory Authorities, who are overseen directly.

What the audit checks

  1. 01Financial supervisors supervise entities; internal audit must cover the ICT risk framework.
  2. 02Supplier assurance: financial customers check the Article 30 contract clauses, audit rights, exit plans and testing participation.
  3. 03Threat-led penetration testing every three years for significant entities.

A typical engagement

Durations are ranges seen in practice for a mid-sized organisation starting from a working security function; a first-time programme runs longer, a mature one shorter.

PhaseWeeks
Scope, proportionality and function criticality2 to 4
ICT risk framework and board approval4 to 12
Register of information and contract remediation8 to 24
Testing programme and incident process4 to 12

Evidence to have ready

  • ICT risk management framework and board approval minutes
  • Mapping of ICT assets to critical or important functions
  • Incident classification procedure and reports filed
  • Testing programme, results and remediation tracking
  • Register of information in the prescribed format
  • Contracts checked against Article 30 clause by clause
  • Exit strategies for critical functions
  • Concentration risk analysis
  • Board training on ICT risk
  • TLPT scope and attestation where required

Dates

  • DORA applies
All regulatory deadlines

Questions people ask

Does DORA replace NIS2 for banks?
For ICT risk management, incident reporting and testing, yes: DORA is the specific law and applies instead of NIS2 to financial entities it covers.
What are the incident reporting deadlines?
Initial notification within four hours of classifying an incident as major and no later than 24 hours from awareness, an intermediate report within 72 hours, and a final report within one month.
I am a SaaS vendor to a bank. What do I have to do?
Accept the Article 30 contract terms: data locations, audit and access rights, incident assistance, exit and transition support, and, where you support a critical function, service levels and participation in testing. An ISO 27001 certificate or a SOC 2 report answers most of the register questions but not the contract terms.

Go deeper