DORA: the Digital Operational Resilience Act in practice
Ten original guides on Regulation (EU) 2022/2554 — written for boards, risk committees, compliance leaders and ICT risk teams who have to evidence compliance rather than describe it.
DORA has applied since 17 January 2025. It replaces a patchwork of national operational resilience expectations with one directly applicable EU regulation covering ICT risk management, incident reporting, resilience testing, third-party risk and threat intelligence sharing.
This hub organises the full series into a reading order. Start with the foundations if you are scoping a programme; go directly to the register of information or the testing programme if you are closing a specific gap.
1. Foundations and scope
What Regulation (EU) 2022/2554 requires, and how the ICT risk framework is assessed in review.
- Governance & GRCDORA in Practice: What Financial Entities Must Actually Evidence
Regulation (EU) 2022/2554 has applied since January 2025. This is what supervisors now expect to see in the file — across ICT risk, incident reporting, testing, third parties and information sharing.
- Governance & GRCBuilding an ICT Risk Management Framework That Survives Review
DORA's ICT risk pillar asks for a documented, board-approved framework covering identification, protection, detection, response, recovery and learning. Most frameworks fail on identification.
2. Incidents and reporting
Classification thresholds, reporting clocks and the evidence trail supervisors ask for after the event.
- Governance & GRCDORA Incident Reporting: Classification, Clocks and the Initial Report
Major ICT-related incidents trigger a three-report sequence against tight deadlines. The hard part is not the reporting — it is deciding, under pressure and without full information, whether the threshold is met.
3. Third-party risk and oversight
The register of information, contractual requirements and the EU oversight regime for critical providers.
- Governance & GRCThe Register of Information: DORA's Hardest Operational Deliverable
Every in-scope entity must maintain a register of all contractual arrangements for ICT services, submitted to its competent authority. Assembling it once is achievable. Keeping it accurate is the real obligation.
- Governance & GRCThe Oversight Framework for Critical ICT Third-Party Providers
DORA does something unprecedented: it gives European supervisors direct oversight powers over technology companies that are not financial institutions. Here is how designation and oversight work, and what it means downstream.
4. Resilience testing
Building a risk-based testing programme, and running threat-led penetration testing under TIBER-EU.
- Governance & GRCDesigning a DORA Testing Programme That Proves Something
DORA requires a risk-based testing programme covering all critical ICT systems at least annually. Most programmes test what is easy to test rather than what would actually fail.
- Banking RiskThreat-Led Penetration Testing Under DORA: TIBER-EU in Practice
Designated entities must conduct advanced threat-led penetration testing on live production systems at least every three years. The scoping and the red-team engagement are the visible parts; the purple-team learning is where value sits.
5. Governance and sector application
Board accountability, cross-border regime alignment and what DORA means for insurers specifically.
- CRO & Compliance LeadershipWhat the Board Owns Under DORA — and How to Evidence It
DORA places ultimate responsibility for ICT risk on the management body and makes it non-delegable. The obligations are specific, and most of them are evidenced in minutes rather than in policy.
- Governance & GRCDORA, NIS2 and the UK Regime: One Control Set, Three Rulebooks
Groups operating across the EU and UK face three overlapping operational resilience regimes with different scopes, thresholds and vocabularies. Running them as three programmes is expensive and produces inconsistent evidence.
- Insurance RiskDORA for Insurers: Where the Regulation Meets Solvency II Reality
Insurance and reinsurance undertakings and intermediaries are squarely in DORA's scope, but their operating models — heavy delegated authority, legacy policy administration, actuarial model estates — create obligations banks do not face in the same shape.
Frequently asked questions
- Who is in scope of DORA?
- DORA applies to a broad set of EU financial entities — credit institutions, payment and e-money institutions, investment firms, crypto-asset service providers, insurance and reinsurance undertakings and intermediaries, pension funds, fund managers, trading venues, credit rating agencies and others — plus ICT third-party service providers designated as critical. Proportionality applies to smaller entities, but scope exclusion is rare.
- When did DORA start applying?
- Regulation (EU) 2022/2554 entered into force in January 2023 and has applied since 17 January 2025. There is no transitional grace period for the core obligations, so supervisors expect a documented framework, a maintained register of information and a working incident reporting process to already be in place.
- What are the five pillars of DORA?
- ICT risk management, ICT-related incident management and reporting, digital operational resilience testing, management of ICT third-party risk, and information and intelligence sharing on cyber threats. Each pillar carries its own evidence expectations, and the board retains ultimate, non-delegable responsibility across all of them.
- What is the register of information?
- It is a structured inventory of every contractual arrangement for ICT services, submitted to the competent authority at entity, sub-consolidated and consolidated level. It must map providers, functions supported, criticality assessments, subcontracting chains and exit arrangements — and stay accurate as contracts change, which is the harder problem.
- How does DORA differ from NIS2 and the UK operational resilience regime?
- The three regimes share a control set but differ in scope, thresholds and vocabulary: DORA is a directly applicable EU regulation for financial entities, NIS2 is a directive covering a wider set of essential and important entities, and the UK regime works through important business services and impact tolerances set by the FCA, PRA and Bank of England. Most groups run one control library mapped to three rulebooks.
- Who is accountable for DORA compliance inside the firm?
- The management body. DORA makes responsibility for the ICT risk framework explicit and non-delegable, requiring board approval of the framework and strategy, adequate ICT risk knowledge, and documented oversight. In practice that accountability is evidenced in committee minutes and challenge records rather than in policy documents alone.
About the author
Jonas Adam Mohamed Osman Abdelghafour is a Chief Risk Officer, Risk & Compliance Director and governance and financial risk expert working across banking, insurance and regulated financial services — covering GRC, AML, enterprise, model, market and liquidity risk.