DORA

Digital Operational Resilience Act

Verordnung über die digitale operationale Resilienz im Finanzsektor

DORA is EU Regulation (EU) 2022/2554 for the digital operational resilience of the financial sector. As a regulation it applies directly in all member states — unlike NIS2, no national transposition is required. It obliges financial entities and their ICT service providers to maintain ICT risk management, incident reporting, resilience testing and strict third-party risk governance.

History. Before DORA, financial institutions managed operational risk mainly through capital buffers, while ICT risk was fragmented and regulated differently across nations. DORA was adopted on 14 December 2022, entered into force in early 2023 and has been binding since 17 January 2025 after a two-year transition. Financial entities are largely exempt from NIS2 and regulated by DORA instead. Facts. DORA rests on several pillars: ICT risk management with board-level accountability, classification and reporting of major ICT incidents, resilience testing, and management of ICT third-party risk including oversight of critical providers. Its most demanding instrument is Threat-Led Penetration Testing (TLPT) under Art. 26-27: significant entities must run intelligence-led attack tests against their live systems at least every three years, methodologically aligned with the TIBER-EU framework. Outlook & recommendation. DORA pulls ICT service providers with financial clients directly into scope — well beyond classic banking. Entities subject to TLPT should plan threat intelligence and red-team capacity early, as suitable testers and lead times are scarce. The ongoing detection-and-response capability that makes a TLPT meaningfully testable in the first place is a precondition — not the test result itself.
DORA — Digital Operational Resilience Act