DORA applies to a broad range of supervised financial entities – from credit institutions and insurers to payment and investment firms and certain crypto-asset service providers – as well as to ICT third-party service providers serving the financial sector. In substance, the regulation rests on five pillars: ICT risk management (Art. 5–16), management and reporting of ICT-related incidents (Art. 17–23), digital operational resilience testing including TLPT (Art. 24–27), management of ICT third-party risk including oversight (Art. 28–44), and arrangements for sharing information on cyber threats (Art. 45). The detailed requirements are specified at a second level by RTS and ITS, which apply directly as delegated and implementing regulations.
DORA: Digital Operational Resilience in the Financial Sector
What Regulation (EU) 2022/2554 requires of financial entities and their ICT service providers – the five pillars, TLPT, the register of information and the oversight of critical third-party providers at a glance.
With the Digital Operational Resilience Act (DORA), the EU has for the first time created a unified legal framework for the digital operational resilience of the financial sector. Regulation (EU) 2022/2554 has applied since 17 January 2025 and consolidates requirements that were previously scattered across supervisory guidelines and national circulars – from the governance of ICT risk to the oversight of critical ICT third-party service providers. As a regulation, DORA applies directly in all Member States and is further specified by regulatory and implementing technical standards (RTS/ITS) issued by the European Supervisory Authorities. For CISOs and compliance officers, the focus is now shifting from initial implementation to resilient day-to-day operation: reporting processes, the register of information, testing programmes and third-party management have to work in everyday practice.
DORA milestones
From applicability to oversight – tap a milestone for details.
DORA applies
Regulation (EU) 2022/2554 has applied since 17 January 2025 and, as a regulation, applies directly in all Member States.
TIBER-EU aligned with DORA
The ECB fully aligns the Eurosystem's TIBER-EU framework with DORA and the RTS – it serves as the implementation guide for TLPT.
RTS on TLPT applicable
Delegated Regulation (EU) 2025/1190 specifies criteria, scope, methodology and requirements for internal and external testers.
First 19 critical providers designated
The ESAs designate the first 19 critical ICT third-party service providers, including major cloud, data centre and network providers; each is assigned a Lead Overseer from among the ESAs.
The Essentials at a Glance
Six topic blocks – tap to expand.
The five pillars of DORA
Pick a pillar – articles, core obligations and the legal acts that specify them at a glance.
- A documented ICT risk management framework for which the management body bears overall responsibility.
- Lifecycle of identification, protection and prevention, detection, response and recovery, and learning and evolving.
- Art. 16 provides for a simplified framework with reduced requirements for certain smaller and less interconnected entities.
- Record and classify ICT-related incidents following a defined process; report major incidents to the competent authority – in Germany, BaFin acts as the national reporting hub.
- Initial notification generally within four hours of classification as major and no later than 24 hours after becoming aware; intermediate report within 72 hours of the initial notification, final report within one month.
- Significant cyber threats may additionally be reported on a voluntary basis.
- Risk-based testing programme for all financial entities other than microenterprises – from vulnerability assessments to scenario-based testing.
- Identified entities carry out TLPT under Art. 26/27 at least every three years – on live production systems; the competent authority may adjust the frequency.
- The RTS on TLPT ((EU) 2025/1190) has applied since 8 July 2025; TIBER-EU serves as the implementation guide.
- Management across the entire contract lifecycle: exit strategies (Art. 28), ICT concentration risk (Art. 29), minimum contractual provisions (Art. 30).
- The register of information under Art. 28(3) covers all contractual arrangements with ICT third-party providers – with binding standard templates from Implementing Regulation (EU) 2024/2956.
- EBA, EIOPA and ESMA oversee critical providers directly for the first time; the first 19 were designated on 18 November 2025.
- Fifth pillar: arrangements for sharing information on cyber threats.
DORA Reality Check — Third-Party Risk & Agentic AI
Eighteen months of DORA in one CISO whitepaper: year-one supervisory findings, the supply-chain cascade and the new risks introduced by AI agents — as an actionable roadmap.
Third-party cascade
How Art. 28–30 reaches thousands of “indirectly regulated” suppliers, and why certificates alone fall short.
Agentic AI as ICT risk
AI agents under DORA, shadow AI, the agentic attack surface and the controls that actually hold.
AI-accelerated attackers
The time-to-exploit collapse, AI offense and defense, and what it means for TLPT logic.
12-move playbook
Twelve concrete moves for the next twelve months — plus the 2026–28 compliance calendar.
English-language whitepaper · direct download after a short request.
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
Verordnung (EU) 2022/2554 (DORA)
Full text of the regulation with the pillar structure Art. 5–16, 17–23, 24–27, 28–44 and 45; applicable since 17 January 2025.
Delegierte Verordnung (EU) 2025/1190 (RTS zu TLPT)
Specifies the identification criteria, scope, methodology and tester requirements for TLPT under Art. 26 DORA; applicable since 8 July 2025.
Durchführungsverordnung (EU) 2024/2956 (ITS zum Informationsregister)
Binding standard templates and completion instructions for the register of information under Art. 28(3) DORA.
TIBER-EU Framework
Fully aligned with DORA and the RTS on TLPT on 11 February 2025; serves as the unified implementation guide for DORA TLPT.
European Supervisory Authorities designate critical ICT third-party providers under the Digital Operational Resilience Act
Press release on the designation of the first 19 critical ICT third-party service providers under DORA oversight on 18 November 2025.
Meldung schwerwiegender IKT-bezogener Vorfälle und erheblicher Cyberbedrohungen
Continuously updated supervisory page; confirms BaFin's role as the central reporting hub for the German financial sector, submission via the MVP portal and the forwarding of reports under Art. 19(6) DORA.
Implementing DORA requirements in a structured way?
From gap analysis and the register of information to TLPT preparation: in a no-obligation initial consultation, we jointly assess where your organisation stands today.