← Glossary

Regulation & Compliance

DORA (Digital Operational Resilience Act)

Also: Digital Operational Resilience Act · Regulation (EU) 2022/2554 · DORA regulation · TLPT · ICT third-party risk

Last reviewed: — regulation changes; check the primary source below before relying on a date or a threshold.

In one sentence

DORA is the EU regulation, applicable since 17 January 2025, that makes financial entities and their critical ICT providers prove they can withstand, respond to and recover from ICT disruptions and cyberattacks.

Why it matters

Before DORA, ICT risk in finance was spread across national guidance, EBA outsourcing guidelines and supervisors' circulars — in Luxembourg, a stack of CSSF circulars. DORA replaces that patchwork with one directly applicable regulation (no national transposition) for roughly twenty types of financial entity: banks, investment firms, insurers, payment and e-money institutions, crypto-asset service providers, fund managers, trading venues and more.

Two things make it bite. Supervisors can fine entities and, for the first time, critical ICT third-party providers (the big cloud and core-banking vendors) fall under a direct EU oversight regime. And it is prescriptive where ISO 27001 is not: DORA says what the ICT risk framework must contain, when an incident must be reported and how often resilience must be tested.

The five pillars

  1. ICT risk management (Articles 5–16). A documented framework, owned by the management body, covering identification, protection, detection, response and recovery, backup, learning and communication. Article 16 gives a simplified framework to small and non-interconnected entities.
  2. ICT-related incident management and reporting (Articles 17–23). Classify incidents against the RTS criteria (clients affected, duration, geographic spread, data losses, criticality of services, economic impact). Major incidents go to the competent authority in three steps: an initial notification within four hours of classifying the incident as major and no later than 24 hours after becoming aware of it, an intermediate report within 72 hours, and a final report within one month. Significant cyber threats may be reported voluntarily.
  3. Digital operational resilience testing (Articles 24–27). Annual testing of critical systems for everyone; threat-led penetration testing (TLPT) at least every three years for entities the supervisor designates, run under the TIBER-EU style framework with red-team providers meeting Article 27 requirements.
  4. ICT third-party risk (Articles 28–44). A register of information listing every ICT contract, mandatory contract clauses (Article 30: audit rights, exit strategies, service levels, incident support), concentration-risk assessment, and the EU oversight framework for critical providers.
  5. Information sharing (Article 45). A legal basis for entities to exchange cyber threat intelligence among themselves.

The Regulation is fleshed out by regulatory and implementing technical standards (RTS/ITS) from the three European Supervisory Authorities — these hold the actual classification thresholds, report templates and register format.

Try it yourself hands-on

You are the information security officer of a Luxembourg payment institution and the board wants to know where you stand before the next CSSF review.

  1. Open the DORA Compliance Checker. It walks the five pillars question by question, with the CSSF specifics called out. Answer honestly — partial with a note beats a hopeful yes.
  2. Take the incident pillar. The question "Can you produce an initial notification within four hours of classification?" is where most first assessments fail, not because detection is slow but because classification is nobody's job. Mark it partial and note "no named classifier on the on-call rota".
  3. Take the third-party pillar. "Is the register of information complete and in the ESA format?" If your contracts live in a shared drive, that is a no. The ICT Provider Register page gives the structure the register must follow.
  4. Export the gap report. Each gap is tied to an article number, which is what the board pack and the CSSF conversation need. Tick "Keep my progress in this browser" to come back next quarter and show movement; the encrypted export lets you carry the assessment to another machine.
  5. Simulate the clock: draft a major-incident initial notification in the Incident Report Generator against a tabletop scenario and time it. The CSSF incident notification page lists the fields the initial notification must contain.

Common misreadings

  • DORA is a regulation, not a directive. It applied on 17 January 2025 in every member state as written; there is no national version to wait for. National law only adds the supervisor and the penalty regime.
  • ISO 27001 does not satisfy DORA on its own. It is an excellent foundation, but DORA's reporting deadlines, register of information and TLPT obligations are not Annex A controls.
  • "We are too small" needs checking, not assuming. The simplified framework (Article 16) narrows obligations; it does not remove the entity from scope.