01Scope and the five pillars
DORA applies to a broad range of supervised financial entities – from credit institutions and insurers to payment and investment firms and certain crypto-asset service providers – as well as to ICT third-party service providers serving the financial sector. In substance, the regulation rests on five pillars: ICT risk management (Art. 5–16), management and reporting of ICT-related incidents (Art. 17–23), digital operational resilience testing including TLPT (Art. 24–27), management of ICT third-party risk including oversight (Art. 28–44), and arrangements for sharing information on cyber threats (Art. 45). The detailed requirements are specified at a second level by RTS and ITS, which apply directly as delegated and implementing regulations.
02ICT risk management (Art. 5–16)
At its core is a documented ICT risk management framework for which the management body bears overall responsibility. It follows a lifecycle of identification, protection and prevention, detection, response and recovery, and learning and evolving – including backup and recovery procedures, communication plans and regular review. For certain smaller and less interconnected entities, Art. 16 provides for a simplified ICT risk management framework with reduced requirements.
03ICT incident reporting (Art. 17–23)
Financial entities must record and classify ICT-related incidents following a defined process and report major incidents to the competent authority – in Germany, BaFin acts as the national reporting hub. The classification criteria are governed by Delegated Regulation (EU) 2024/1772; deadlines, content and templates are laid down in Delegated Regulation (EU) 2025/301 and Implementing Regulation (EU) 2025/302: the initial notification is generally due within four hours of classifying an incident as major and no later than 24 hours after becoming aware of it, the intermediate report within 72 hours of the initial notification, and the final report within one month. Significant cyber threats may additionally be reported on a voluntary basis.
04Resilience testing and TLPT (Art. 24–27)
All financial entities other than microenterprises must operate a risk-based digital operational resilience testing programme, ranging from vulnerability assessments to scenario-based testing. Entities identified for this purpose by the authorities must in addition carry out threat-led penetration testing (TLPT) under Art. 26/27 at least every three years – on live production systems and covering several or all critical or important functions; the competent authority may adjust the frequency. Criteria, scope, methodology and requirements for internal and external testers are specified in Delegated Regulation (EU) 2025/1190 (the RTS on TLPT), applicable since 8 July 2025. The Eurosystem's TIBER-EU framework, which the ECB fully aligned with DORA and the RTS on 11 February 2025, serves as the implementation guide.
05ICT third-party risk and the register of information (Art. 28–30)
Chapter V requires financial entities to manage the risks arising from ICT service contracts across their entire lifecycle: strategy and policies including exit strategies (Art. 28), assessment of ICT concentration risk (Art. 29), and minimum contractual provisions covering, for example, security, audit and termination rights (Art. 30). The central instrument is the register of information under Art. 28(3) covering all contractual arrangements with ICT third-party service providers; Implementing Regulation (EU) 2024/2956 prescribes binding standard templates for this purpose. The submitted registers also serve the supervisory authorities as a data basis – among other things for the designation of critical ICT third-party service providers.
06Oversight of critical ICT third-party providers (Art. 31–44)
With DORA, the three European Supervisory Authorities EBA, EIOPA and ESMA (the ESAs) receive for the first time a direct oversight mandate over ICT third-party service providers designated as critical for the financial sector. On 18 November 2025, the ESAs designated the first 19 critical ICT third-party service providers, including major cloud, data centre and network providers; the criticality assessment was based on the registers of information submitted by financial entities. Each designated provider is assigned a Lead Overseer from among the ESAs, who can request information, conduct investigations and issue recommendations. Financial entities' own responsibility for their third-party risk remains unaffected.