EU Regulatory Center

DORA — digital operational resilience for finance

ICT risk management, incident reporting, resilience testing and third-party oversight for financial entities and their critical ICT providers.

Status

Law in force
Regulation (EU) 2022/2554
DORA has applied since 17 January 2025 and creates a harmonized framework for digital operational resilience across the EU financial sector, including banks, insurers, investment firms and their critical ICT third-party providers.
Reviewed 2026-06 · Source: Official Journal of the European Union

Scope at a glance

QuestionAnswer
WhoBanks, insurers, investment firms and most other regulated financial entities, plus their critical ICT third-party providers.
WhatICT risk management, resilience testing, incident reporting and third-party risk oversight.
ReportingMajor ICT-related incidents must be reported to competent authorities within defined timelines.
OversightCritical ICT third-party providers can be designated for direct EU-level oversight.

Core obligations

General guidance, not legal advice
This page summarizes publicly available regulatory status for general guidance only. Confirm applicability, scope and deadlines with qualified legal counsel before making compliance decisions.
How CYRKIL helps

The Financial Services industry view maps DORA obligations to controls and evidence, and Supply Chain Security tracks third-party concentration risk.

See Financial Services
How CYRKIL tracks this

Every regulatory page here runs through the Regulatory Truth Pipeline — official source, human and legal review, then publish, with the source, version and review date always shown.

See the pipeline

Get a readiness review against this regulation.