DORA Compliance — operationalising Regulation (EU) 2022/2554

As at 25 July 2026, the Digital Operational Resilience Act — Regulation (EU) 2022/2554, applicable since 17 January 2025 — sets uniform ICT risk requirements across EU financial entities. In Luxembourg the CSSF supervises its application. The regulation is well documented; what is missing everywhere is the bridge from the article to the artifact. That bridge is what this hub, and these tools, are for.

The five pillars, in practice

  • ICT risk management — a governed framework, owned by the management body, with a maintained risk view (not a slide once a year).
  • ICT-related incident management & reporting — classify incidents and notify the competent authority within the required windows.
  • Digital operational resilience testing — a proportionate testing programme, with threat-led penetration testing (TLPT) for entities in scope.
  • ICT third-party risk — a register of ICT service providers and contractual safeguards for critical or important functions.
  • Information sharing — voluntary exchange of cyber threat intelligence.

Article numbers, thresholds and deadlines change with the regulatory technical standards; confirm specifics against the current consolidated text before relying on them.

From requirement to artifact

  1. Dora Compliance Checker — Start with a gap read across the five pillars — where you are against what DORA expects — so the rest of the work is targeted rather than boil-the-ocean.
  2. Dora Engine — Work the requirements in depth: map the articles to concrete obligations for an entity of your size and role.
  3. Control Mapper — Avoid duplicating effort — map DORA obligations onto controls you already run for ISO 27001 or NIS2, so one control satisfies several regimes.
  4. Policy Templates — Produce the written artifacts the regulation expects — policies and procedures — from a structured starting point rather than a blank page.
  5. Risk Register — Maintain the ICT risk view that the risk-management pillar requires, in a form you can show a supervisor.
  6. Incident Report Generator — When an ICT-related incident hits the reporting thresholds, assemble the notification against the required structure and timeline.
  7. Board Pack — Resilience is a management-body responsibility under DORA — turn the posture into a board-ready pack that evidences oversight.

Where teams get it wrong

  • Treating DORA as a document exercise. The regulation is about demonstrable operational resilience, tested — not a binder of policies.
  • Rebuilding controls per regime. Most DORA controls already exist under ISO 27001 or NIS2; map once, evidence many.
  • An incomplete third-party register. The register is a named deliverable a supervisor can ask for; a spreadsheet missing fields is a finding.

FAQ

When did DORA start applying?

Regulation (EU) 2022/2554 has applied since 17 January 2025 across EU financial entities; in Luxembourg the CSSF is the competent authority.

Is this legal advice?

No. These are practitioner tools and summaries, dated and jurisdiction-scoped. Confirm obligations against the current text and your supervisor's guidance.