Home › Law library › DORA
EU
DORA
Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA)
Sourced. Last verified 9 October 2026
European Union Cybersecurity
- Status
- Applies since 17 January 2025.
- Who it applies to
- 20 types of EU financial entities (banks, insurers, investment firms, payment/e-money institutions, crypto-asset service providers, etc.) and the ICT third-party service providers that serve them; critical ICT providers face direct EU oversight.
- Size thresholds
- None — applies to in-scope financial entities regardless of size.
- Regulator
- National financial supervisors; European Supervisory Authorities (EBA, EIOPA, ESMA) oversee critical ICT third-party providers
- Breach or incident reporting
- Major ICT incidents: initial notice within 4h of classifying as major and no later than 24h after awareness; intermediate report within 72h of initial notice; final report within 1 month of the latest intermediate report.
- Data protection officer
- No named officer; the management body bears ultimate responsibility for ICT risk management.
- Maximum penalty
- Set by Member States for financial entities. Critical ICT providers: periodic penalty payments up to 1% of average daily worldwide turnover.
Facts marked “Being verified” are still being confirmed and are not given as answers.
What you must do
- Maintain a board-approved ICT risk management framework.
- Classify ICT incidents and report major ones within 4h/24h, 72h and 1 month.
- Keep a register of all ICT third-party contracts and include DORA-mandated contract terms.
- Test digital resilience regularly; large firms run threat-led penetration tests.
- Plan exit strategies for critical ICT providers.
Recent changes
Incident-reporting RTS (Delegated Regulation 2025/301) and register-of-information rules apply; ESAs began designating critical ICT third-party providers in 2025.
Sources
- Primary source: https://www.eiopa.europa.eu/digital-operational-resilience-act-dora_en
- Second source: https://advisera.com/cdr-2025-301/time-limits-for-the-initial-notification-and-for-the-intermediate-and-final-reports/
- Regulator: National financial supervisors; European Supervisory Authorities (EBA, EIOPA, ESMA) oversee critical ICT third-party providers
Information only, not legal advice. Laws change; confirm with the regulator or a qualified lawyer before relying on this page. Spotted an error? Email [email protected].