Financial district office towers

REGULATION — DORA

DORA is a test of how you operate, not a mapping exercise.

The Digital Operational Resilience Act has applied to a broad range of financial entities across the EU since 17 January 2025 — and, for the first time, brings their critical ICT third-party providers under EU-level oversight.

WHAT IT DEMANDS

Five areas, one regulation.

DORA — Regulation (EU) 2022/2554 — pulls the pieces of operational resilience into a single, directly applicable rulebook. Its requirements fall into five areas.

  1. An ICT risk-management framework owned by the management body. Resilience is the board's responsibility, not something delegated wholesale to IT.
  2. ICT incident management, classification and major-incident reporting. A defined process to detect, classify and report the incidents that matter.
  3. Digital operational resilience testing, including threat-led penetration testing (TLPT) for significant entities. Regular testing, with TLPT expected of the entities that carry the most weight.
  4. ICT third-party risk management, including a maintained register of information. A single register covering all ICT third-party arrangements, kept current.
  5. Information and intelligence sharing. Arrangements to exchange cyber threat information across the sector.
City of London skyline at dusk

Supervisors want proof it works, not proof it was written down.

WHERE FIRMS TRIP

HOW WE HELP

RELATED

Built into how the firm runs, DORA stops being an annual scramble.

Start a conversation