Skip to content
GlanceDeskJurisdiction

Home › Law library › DORA

EU

DORA

Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA)

Sourced. Last verified 9 October 2026

European Union Cybersecurity

Status
Applies since 17 January 2025.
Who it applies to
20 types of EU financial entities (banks, insurers, investment firms, payment/e-money institutions, crypto-asset service providers, etc.) and the ICT third-party service providers that serve them; critical ICT providers face direct EU oversight.
Size thresholds
None — applies to in-scope financial entities regardless of size.
Regulator
National financial supervisors; European Supervisory Authorities (EBA, EIOPA, ESMA) oversee critical ICT third-party providers
Breach or incident reporting
Major ICT incidents: initial notice within 4h of classifying as major and no later than 24h after awareness; intermediate report within 72h of initial notice; final report within 1 month of the latest intermediate report.
Data protection officer
No named officer; the management body bears ultimate responsibility for ICT risk management.
Maximum penalty
Set by Member States for financial entities. Critical ICT providers: periodic penalty payments up to 1% of average daily worldwide turnover.

Facts marked “Being verified” are still being confirmed and are not given as answers.

What you must do

Recent changes

Incident-reporting RTS (Delegated Regulation 2025/301) and register-of-information rules apply; ESAs began designating critical ICT third-party providers in 2025.

Sources

Information only, not legal advice. Laws change; confirm with the regulator or a qualified lawyer before relying on this page. Spotted an error? Email [email protected].