Article cluster

DORA: the Digital Operational Resilience Act in practice

Ten original guides on Regulation (EU) 2022/2554 — written for boards, risk committees, compliance leaders and ICT risk teams who have to evidence compliance rather than describe it.

DORA has applied since 17 January 2025. It replaces a patchwork of national operational resilience expectations with one directly applicable EU regulation covering ICT risk management, incident reporting, resilience testing, third-party risk and threat intelligence sharing.

This hub organises the full series into a reading order. Start with the foundations if you are scoping a programme; go directly to the register of information or the testing programme if you are closing a specific gap.

1. Foundations and scope

What Regulation (EU) 2022/2554 requires, and how the ICT risk framework is assessed in review.

2. Incidents and reporting

Classification thresholds, reporting clocks and the evidence trail supervisors ask for after the event.

3. Third-party risk and oversight

The register of information, contractual requirements and the EU oversight regime for critical providers.

4. Resilience testing

Building a risk-based testing programme, and running threat-led penetration testing under TIBER-EU.

5. Governance and sector application

Board accountability, cross-border regime alignment and what DORA means for insurers specifically.

Frequently asked questions

Who is in scope of DORA?
DORA applies to a broad set of EU financial entities — credit institutions, payment and e-money institutions, investment firms, crypto-asset service providers, insurance and reinsurance undertakings and intermediaries, pension funds, fund managers, trading venues, credit rating agencies and others — plus ICT third-party service providers designated as critical. Proportionality applies to smaller entities, but scope exclusion is rare.
When did DORA start applying?
Regulation (EU) 2022/2554 entered into force in January 2023 and has applied since 17 January 2025. There is no transitional grace period for the core obligations, so supervisors expect a documented framework, a maintained register of information and a working incident reporting process to already be in place.
What are the five pillars of DORA?
ICT risk management, ICT-related incident management and reporting, digital operational resilience testing, management of ICT third-party risk, and information and intelligence sharing on cyber threats. Each pillar carries its own evidence expectations, and the board retains ultimate, non-delegable responsibility across all of them.
What is the register of information?
It is a structured inventory of every contractual arrangement for ICT services, submitted to the competent authority at entity, sub-consolidated and consolidated level. It must map providers, functions supported, criticality assessments, subcontracting chains and exit arrangements — and stay accurate as contracts change, which is the harder problem.
How does DORA differ from NIS2 and the UK operational resilience regime?
The three regimes share a control set but differ in scope, thresholds and vocabulary: DORA is a directly applicable EU regulation for financial entities, NIS2 is a directive covering a wider set of essential and important entities, and the UK regime works through important business services and impact tolerances set by the FCA, PRA and Bank of England. Most groups run one control library mapped to three rulebooks.
Who is accountable for DORA compliance inside the firm?
The management body. DORA makes responsibility for the ICT risk framework explicit and non-delegable, requiring board approval of the framework and strategy, adequate ICT risk knowledge, and documented oversight. In practice that accountability is evidenced in committee minutes and challenge records rather than in policy documents alone.

About the author

Jonas Adam Mohamed Osman Abdelghafour is a Chief Risk Officer, Risk & Compliance Director and governance and financial risk expert working across banking, insurance and regulated financial services — covering GRC, AML, enterprise, model, market and liquidity risk.