DORA
Regulation (EU) 2022/2554 on digital operational resilience (DORA)
DORA is the EU regulation imposing uniform requirements on the financial sector for ICT risk management, incident reporting, digital resilience testing and oversight of third-party ICT providers. It has applied directly since 17 January 2025.
Who it applies to
- Credit institutions, payment institutions, account information service providers and electronic money institutions.
- Investment firms, central counterparties, central securities depositories and trading venues.
- Managers of alternative investment funds, insurance and reinsurance undertakings, and institutions for occupational retirement provision.
- Credit rating agencies.
- Third-party ICT service providers, with critical providers supervised at EU level.
Key obligations
- An ICT risk management framework with management body accountability.
- Classification and reporting of ICT-related incidents against harmonised thresholds and timelines.
- A digital operational resilience testing programme.
- Advanced threat-led penetration testing (TLPT) at least every three years for designated entities, on live production systems (Article 26).
- Third-party ICT risk management, including contractual provisions and a register of information.
- Voluntary cyber threat information sharing.
Penalties
For critical third-party ICT providers, periodic penalty payments of up to 1% of average daily worldwide turnover in the preceding business year, applied daily for up to six months (Article 35). For financial entities the regulation sets no EU-wide amounts — these are set by Member States.
Status in Slovenia
Slovenia adopted a decree implementing DORA (Official Gazette RS No. 25/25). The competent authorities are the Bank of Slovenia, the Securities Market Agency and the Insurance Supervision Agency, while URSIV has tasks relating to TLPT. National fines for legal entities range from EUR 25,000 to EUR 250,000, and up to EUR 500,000 for medium and large companies.
Important notice
This is general information, not legal advice. The content is verified against primary sources (EUR-Lex, Official Gazette RS), but regulations change and their application depends on each organization's circumstances. Consult a legal professional for a binding assessment.
Sources and standards
- 01Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA)EUR-Lex, 2022
- 02Slovenian decree implementing DORA, Official Gazette RS No. 25/25Uradni list RS, 2025
- 03TIBER-EU framework for threat intelligence-based ethical red teamingEuropean Central Bank
Ready to strengthen security across your organization?
Contact us to see how our turnkey solutions can build a safer, more resilient organization.
