Regulation (EU) 2022/2554
DORA explained: what the Digital Operational Resilience Act actually requires
DORA replaced a patchwork of national outsourcing guidance with one binding set of ICT resilience rules for EU financial entities. This guide sets out who is in scope, what the five pillars oblige you to do, who supervises you, and what changed when the first critical ICT providers were designated. Written for people who are not lawyers.
Digital Operational Resilience Act · Applies since 17 January 2025 · Financial services
Verified as at . Positions change as bills pass and implementing acts land, so treat dates as a starting point for verification, not as authority. This is reference material, not legal advice.
- Instrument
- Regulation (EU) 2022/2554
- Applies since
- 17 January 2025
- Legal form
- Regulation — directly applicable, no national transposition needed
- Who is in scope
- Roughly 20 categories of EU financial entity, plus their ICT suppliers
- Supervisor
- Your existing prudential or markets supervisor — no new authority
- Incident clock
- Initial notification within hours · intermediate 72 hours · final within a month
Who DORA applies to
DORA covers roughly twenty categories of EU financial entity: banks, insurers, investment firms, payment and e-money institutions, crypto-asset service providers, trading venues, central securities depositories and others, plus the ICT suppliers they depend on. It replaces a patchwork of national outsourcing guidance with one binding set of rules across five areas.
The important consequence of that breadth is that scope is not a question you answer once for a group. A banking licence, an insurance licence and a crypto-asset service provider authorisation held by three entities in the same group each bring their own supervisor and their own filing route, even though the underlying obligations are identical.
The five pillars
DORA is usually described in five limbs. They are not five separate projects — the evidence produced by one feeds the next — but they are the shape a supervisor will use when they examine you.
- ICT risk management framework. The management body approves it and remains answerable for it, so accountability cannot be pushed down to the CISO.
- Incident classification and reporting. Major ICT incidents go to the national competent authority on a fixed clock: initial notification within hours, an intermediate report within 72 hours, and a final report within a month.
- Resilience testing. Annual testing of critical systems, and threat-led penetration testing at least every three years for larger entities.
- Third-party risk. A Register of Information covering every contractual arrangement with an ICT provider, submitted annually to the supervisor, plus mandatory contract terms on audit rights, subcontracting, data location and exit.
- Threat intelligence sharing. Voluntary.
| Obligation | Cadence | Goes to |
|---|---|---|
| Major incident notification | Initial within hours, intermediate at 72 hours, final within a month | National competent authority |
| Register of Information | Annually | Supervisor, in ESA templates, as structured data |
| Testing of critical systems | Annually | Held as evidence, examined on inspection |
| Threat-led penetration testing | At least every three years, larger entities | Held as evidence, examined on inspection |
What it looks like in practice
In practice DORA is performed continuously rather than annually. The board signs off the framework, the first line runs the controls, risk and internal audit test them independently, and the register is filed as structured data in the templates set by the European Supervisory Authorities.
The binding standard is documentary
If a control is not evidenced, cited to a source and reproducible for an examiner, it does not exist as far as the supervisor is concerned. That is the sentence most programmes underestimate: the deliverable is not the policy, it is the proof that the policy operated.
Country status, and why there is no transposition table
DORA is a regulation, not a directive. It applies directly and identically in all 27 member states with no national implementing law required, which is exactly why it landed on time while NIS2 did not. There is no per-country variation in the obligations themselves.
What does vary by country is who supervises you and how they collect the paperwork. DORA does not create a new authority. Your existing prudential supervisor picks it up, so the answer is entity-specific rather than country-specific: a significant bank answers to the ECB under the SSM, a smaller bank or an insurer to its national supervisor, an investment firm or CASP to its national markets authority.
Register of Information collection mechanics also differ. Belgium's FSMA, for example, gathers registers through its FiMiS survey and forwards them to the ESAs, and narrowed the 2026 round so that only a limited set of entities must resubmit, with the rest simply confirming no change.
A handful of states are still legislating national adaptation measures that designate authorities and set sanctioning powers. France is doing this in Title III of the loi Résilience, which as at August 2026 has not been enacted. DORA binds French financial entities today regardless; only the domestic enforcement plumbing is outstanding.
The oversight layer that is genuinely new
On 18 November 2025 the ESAs published the first list of designated critical ICT third-party providers, naming 19 firms across hyperscale cloud, data centre operations, network infrastructure and financial-sector technology. Designated providers come under direct EU-level oversight with powers of investigation and on-site inspection, including at material subcontractors. The list is reassessed annually.
Designation does not transfer any responsibility away from the financial entity. It intensifies scrutiny of whether that entity governs the relationship properly — which means the contract terms, the audit rights, the subcontracting chain and the exit plan all become more, not less, likely to be examined.
How DORA sits alongside NIS2 and MiCA
DORA is lex specialis for financial entities, so a bank satisfies the ICT risk and incident limbs of NIS2 through DORA rather than doing the work twice. In the other direction, MiCA routes crypto-asset service providers straight into DORA for ICT resilience — MiCA sets the authorisation and conduct regime, DORA supplies the operational resilience layer underneath it.
None of this collapses three programmes into one. It means the same evidence can serve more than one supervisor, provided it is produced in a form that survives examination by any of them.
Common questions
Does DORA have to be transposed into national law?
No. DORA is a regulation, not a directive, so it applies directly and identically in all 27 member states with no national implementing law required. That is exactly why it landed on time while NIS2 did not. There is no per-country variation in the obligations themselves.
Who supervises us under DORA?
DORA does not create a new authority — your existing prudential supervisor picks it up. The answer is therefore entity-specific rather than country-specific: a significant bank answers to the ECB under the SSM, a smaller bank or an insurer to its national supervisor, and an investment firm or crypto-asset service provider to its national markets authority.
What are the DORA incident reporting deadlines?
Major ICT incidents go to the national competent authority on a fixed clock: an initial notification within hours, an intermediate report within 72 hours, and a final report within a month.
What is the Register of Information?
It is a register covering every contractual arrangement with an ICT provider, submitted annually to the supervisor as structured data in the templates set by the European Supervisory Authorities. Collection mechanics differ by country: Belgium's FSMA, for example, gathers registers through its FiMiS survey and forwards them to the ESAs.
How often do we have to test resilience?
Critical systems are tested annually. Larger entities additionally run threat-led penetration testing at least every three years.
Our cloud provider was designated critical. Does that reduce our obligations?
No. Designation does not transfer any responsibility away from the financial entity. It brings the provider under direct EU-level oversight, with powers of investigation and on-site inspection including at material subcontractors, and it intensifies scrutiny of whether you govern the relationship properly.
Does DORA replace NIS2 for a bank?
For the ICT risk and incident limbs, effectively yes. DORA is lex specialis for financial entities, so a bank satisfies those parts of NIS2 through DORA rather than doing the work twice.
The other two guides
Directive (EU) 2022/2555
NIS2 — Network and Information Security Directive
A directive, so what binds you is your member state's law and not the directive text. Ten minimum security measures, a three-stage reporting clock, personal liability for management — and 27 national timetables that do not line up.
Read the NIS2 guideRegulation (EU) 2023/1114
MiCA — Markets in Crypto-Assets Regulation
A single EU authorisation regime for crypto, split across issuers of ordinary tokens, asset-referenced tokens and e-money tokens, plus crypto-asset service providers. Every transitional window closed on 1 July 2026.
Read the MiCA guideProducing the evidence is the part that does not stop
ComplianceOS checks your policies, contracts and registers against the official regulatory text and returns findings with verbatim citations, page references and a confidence score — cross-checked by a second model and challenged by an adversarial reviewer. Built for firms that have to prove a control operated, repeatedly, on a supervisor's schedule.
Sources and status
These guides summarise publicly available primary sources including Regulation (EU) 2022/2554, Directive (EU) 2022/2555, Commission Implementing Regulation (EU) 2024/2690 and Regulation (EU) 2023/1114, together with national gazette publications and regulator announcements. The source texts are the binding authority. Nothing here is legal advice or a substitute for counsel in your jurisdiction.
Spotted something out of date? [email protected].