Digital Operational Resilience Act (DORA)

The Digital Operational Resilience Act (DORA) is an EU regulation that entered into force on 16 January 2023 and will apply as of 17 January 2025. It aims at strengthening the information and communication technology (ICT) security of financial entities in the remit of the 3 ESAs and making sure that the financial sector in Europe is able to stay resilient in the event of a severe operational digital disruption. DORA brings harmonisation of the rules relating to digital operational resilience for the financial sector applying to more than 20 different types of financial entities, of which 12 are in the remit of ESMA.

Why is DORA needed?

The financial sector is increasingly dependent on information and communication technology (ICT) tools and systems to deliver its financial services, for which they increasingly rely on ICT service providers. This may expose financial entities to potential ICT (third-party) risk because the delivery of their financial services relies on entities who are not directly supervised nor subject to the same regulatory frameworks (i.e. when the ICT service providers are not financial entities themselves).

When not managed properly, ICT risks can lead to disruptions of financial service delivery. This can have an impact on other financial entities, sectors and even on the rest of the economy, which underlines the importance of the digital operational resilience of the financial sector. 

primary_grey_background
ICT risk management
ICT risk management

A framework setting principles and requirements on ICT risk management.

white_background
ICT third-party risk management
ICT third-party risk management

Mitigation of ICT third-party risk; Key contractual provisions.

white_background
Digital operational resilience testing
Digital operational resilience testing

Operational resilience testing programme encompassing a range of tests, including advanced testing.

white_background
ICT-related incidents
ICT-related incidents

Management of ICT-related incidents, and notification of major ones and of significant cyber threats to competent authorities.

white_background
Information sharing
Information sharing

Exchange of information and intelligence on cyber threats.

white_background
Oversight of critical third-party providers
Oversight of critical third-party providers

Oversight framework for ICT third-party providers that are designated as critical by the ESAs for the financial sector.

white_background

Links to DORA policy requirements

DORA requirements are set out across Level 1 legislation, Level 2 technical standards and delegated regulations and Level 3 supervisory guidance. The table below provides an overview of the relevant policy requirements by topic, as well as relevant supervisory material.

primary_grey_background

Level 1 

Directive (EU) 2022/2556 as regards digital operational resilience for the financial sector

Regulation (EU) 2022/2554 on digital operational resilience for the financial sector

Level 2

Regulatory Technical Standards (RTS)

Implementing Technical Standards (ITS)

Commission delegated regulation (CDR)

Level 3 & additional material

Guidelines and relevant material

Risk Management 

Arts. 5-16; 26-30 

Incident reporting 

Arts. 17-23 

Oversight Framework 

Arts. 31-44 

Other relevant links: 

white_background