Built to Scale|Индивидуальное программное обеспечение · ИИ · Автоматизация
IN FORCE SINCE 17 JAN 2025 – Mandatory for finance & IT providers

DORA Regulation
Digital Operational Resilience
EU 2022/2554

The DORA Regulation requires the entire financial sector – and its ICT service providers – to demonstrate digital operational resilience. Anyone delivering critical IT services to banks, insurers, or payment providers falls directly within its scope.

Already in force

DORA has applied directly since 17 January 2025 – with no national transposition needed. Supervisors are already actively reviewing. Those without a complete resilience strategy should act now.

Regulation

EU Regulation 2022/2554

17 Jan 2025

In force since

5 pillars

Core pillars

within 4h

Report major incidents

20+ types

Entity types affected

dora

Who is affected by DORA?

DORA applies to financial entities and to the ICT third-party providers delivering critical services to the financial sector. Software and cloud vendors are therefore in scope too.

Financial Entities

  • Banks & credit institutions
  • Insurers & reinsurers
  • Investment firms
  • Payment service providers
  • Crypto-asset providers (MiCA)
  • Fund & asset managers
  • Trading venues & CSDs
🏭

ICT Providers to the Financial Sector

  • Cloud providers
  • Software & SaaS vendors
  • Data centers & hosting
  • Managed service providers
  • IT security service providers
  • Data analytics & AI services
  • Critical third parties (CTPP)

Scope: DORA applies in principle to all supervised financial entities regardless of size, with a simplified risk framework foreseen for micro and small entities. For IT vendors, what matters is not their own size but whether they deliver critical ICT services to the financial sector. Providers designated as critical (CTPP) are subject to direct EU oversight.

What does DORA specifically require?

DORA rests on five pillars and defines binding requirements for ICT risk management, incident reporting, resilience testing, third-party oversight, and governance.

ICT risk-management framework

A documented framework to identify, protect, and monitor all ICT assets. An inventory of critical systems and dependencies is mandatory.

Incident classification & reporting

Major ICT-related incidents must be classified and reported to supervisors – an initial notification within hours of classification, followed by intermediate and final reports.

Resilience testing incl. TLPT

Regular digital operational resilience testing. Significant entities must conduct threat-led penetration testing (TLPT) that simulates real-world attacks.

ICT third-party risk management

A register of all ICT service providers, mandatory contractual clauses, exit strategies, and ongoing monitoring of critical suppliers.

Business continuity & recovery

Contingency and recovery plans, backup strategies, and defined recovery objectives (RTO/RPO), tested on a regular basis.

Governance & board accountability

The management body holds ultimate responsibility for ICT risk management. Roles, responsibilities, and reporting lines must be clearly defined.

Deadlines & Timeline

The DORA timeline – from adoption to ongoing supervision.

1
December 2022

DORA adopted

EU Regulation 2022/2554 enters into force, followed by a 24-month transition period for preparation.

2
2023–2024

Technical standards (RTS/ITS)

The ESAs detail DORA through regulatory technical standards on risk management, incident reporting, and third-party oversight.

3
17 January 2025

DORA applies directly

From this date all requirements are binding. Financial entities and their ICT providers must be fully compliant.

Act now
4
Ongoing from 2025

Oversight & CTPP designation

Supervisors review implementation. Critical third-party providers are designated and placed under direct EU oversight.

How we help you with DORA

From the scope and gap analysis to ongoing support – we guide you through the entire DORA process in three clearly structured phases.

Phase 1

Analysis & Gap Assessment

We clarify your scope and compare your current posture against the DORA requirements – including a full inventory of your ICT assets and providers.

  • Scope & applicability check
  • Gap analysis against DORA
  • ICT asset & dependency mapping
  • Critical supplier inventory
2–4 weeks · report included
Phase 2

Implementation & Build

We build out all DORA components in a practical, documented way – from the risk framework to the contract register.

  • Establish ICT risk framework
  • Incident reporting & classification process
  • Prepare testing program incl. TLPT
  • Build the contract register
  • Set up business continuity management
6–12 weeks · complete documentation
Phase 3

Support & Operations

DORA is an ongoing commitment. We support you with recurring tests, reporting processes, and supplier oversight.

  • Testing cycles & resilience tests
  • Supervisory & reporting processes
  • Ongoing supplier oversight
  • Audits & continuous adaptation
Ongoing · monthly reports

Frequently Asked Questions about DORA

Is your company DORA-ready?

Let us check together whether and how DORA affects you – and which measures you need to implement now. Free initial consultation, concrete assessment.

Schedule free initial consultation

We will get back to you within 24 hours.

© 2025 THE BARK — Vedat EGE · Oberhausen · the-bark.de