Skip to content
Mandatory · lawEuropean UnionEUv2022/2554

DORA

Digital Operational Resilience Act (EU 2022/2554)

The EU regulation harmonising digital operational resilience for the financial sector. It mandates an ICT risk-management framework, incident management and reporting, resilience testing, and oversight of ICT third-party risk.

Official source ↗

Who it applies to

Financial entitiesEUICT third parties

Financial entities in the EU — banks, insurers, investment firms, payment and e-money institutions, crypto-asset service providers and more — and the critical ICT third-party providers that serve them.