Glossary
DORA (Regulation (EU) 2022/2554)
DORA is the EU regulation on digital operational resilience for the financial sector, requiring financial entities to manage ICT risk, report incidents, test their resilience and govern their ICT third-party providers.
Unlike a directive, a regulation applies directly in all Member States and requires no transposition; the detail is set by delegated and implementing acts and by technical standards from the European supervisory authorities. A broad range of financial entities is covered — credit institutions, payment and electronic money institutions, investment firms, insurance and reinsurance undertakings and intermediaries, fund managers, trading venues, central securities depositories and central counterparties, crypto-asset service providers, crowdfunding providers, credit rating agencies and occupational pension institutions — together with ICT service providers designated as critical, who fall under a dedicated EU oversight framework. Proportionality applies, with a simplified framework for smaller and less complex entities.
The regulation rests on five pillars. The first is an ICT risk management framework with defined roles, a strategy, an inventory of assets and dependencies, and provisions for protection, detection, response and recovery. The second is the management, classification and reporting of ICT-related incidents according to materiality criteria and in several steps. The third is a digital operational resilience testing program, ranging from vulnerability scanning and scenario-based testing to threat-led penetration testing for entities that meet the criteria.
The fourth pillar is management of ICT third-party risk: prescribed contractual content, access and audit rights, exit strategies and alternative arrangements, monitoring of concentration risk, and maintaining a register of information on contractual arrangements. The fifth pillar covers voluntary arrangements for sharing cyber threat information between financial entities.
Responsibility rests explicitly with the management body, which approves the framework, allocates resources and must maintain adequate knowledge. The regulation specifically requires an ICT business continuity policy, response and recovery plans, backup and restoration procedures, and post-incident review with the resulting improvements. For financial entities DORA is the more specific regime relative to the general NIS2 requirements, which does not remove other obligations such as those under data protection law.
Ready to strengthen security across your organization?
Contact us to see how our turnkey solutions can build a safer, more resilient organization.
