DORA Compliance — operationalising Regulation (EU) 2022/2554
As at 25 July 2026, the Digital Operational Resilience Act — Regulation (EU) 2022/2554, applicable since 17 January 2025 — sets uniform ICT risk requirements across EU financial entities. In Luxembourg the CSSF supervises its application. The regulation is well documented; what is missing everywhere is the bridge from the article to the artifact. That bridge is what this hub, and these tools, are for.
The five pillars, in practice
- ICT risk management — a governed framework, owned by the management body, with a maintained risk view (not a slide once a year).
- ICT-related incident management & reporting — classify incidents and notify the competent authority within the required windows.
- Digital operational resilience testing — a proportionate testing programme, with threat-led penetration testing (TLPT) for entities in scope.
- ICT third-party risk — a register of ICT service providers and contractual safeguards for critical or important functions.
- Information sharing — voluntary exchange of cyber threat intelligence.
Article numbers, thresholds and deadlines change with the regulatory technical standards; confirm specifics against the current consolidated text before relying on them.
From requirement to artifact
- Dora Compliance Checker — Start with a gap read across the five pillars — where you are against what DORA expects — so the rest of the work is targeted rather than boil-the-ocean.
- Dora Engine — Work the requirements in depth: map the articles to concrete obligations for an entity of your size and role.
- Control Mapper — Avoid duplicating effort — map DORA obligations onto controls you already run for ISO 27001 or NIS2, so one control satisfies several regimes.
- Policy Templates — Produce the written artifacts the regulation expects — policies and procedures — from a structured starting point rather than a blank page.
- Risk Register — Maintain the ICT risk view that the risk-management pillar requires, in a form you can show a supervisor.
- Incident Report Generator — When an ICT-related incident hits the reporting thresholds, assemble the notification against the required structure and timeline.
- Board Pack — Resilience is a management-body responsibility under DORA — turn the posture into a board-ready pack that evidences oversight.
Where teams get it wrong
- Treating DORA as a document exercise. The regulation is about demonstrable operational resilience, tested — not a binder of policies.
- Rebuilding controls per regime. Most DORA controls already exist under ISO 27001 or NIS2; map once, evidence many.
- An incomplete third-party register. The register is a named deliverable a supervisor can ask for; a spreadsheet missing fields is a finding.
FAQ
When did DORA start applying?
Regulation (EU) 2022/2554 has applied since 17 January 2025 across EU financial entities; in Luxembourg the CSSF is the competent authority.
Is this legal advice?
No. These are practitioner tools and summaries, dated and jurisdiction-scoped. Confirm obligations against the current text and your supervisor's guidance.