Book an Appointment

DORA: Digital Operational Resilience in the Financial Sector

What Regulation (EU) 2022/2554 requires of financial entities and their ICT service providers – the five pillars, TLPT, the register of information and the oversight of critical third-party providers at a glance.

With the Digital Operational Resilience Act (DORA), the EU has for the first time created a unified legal framework for the digital operational resilience of the financial sector. Regulation (EU) 2022/2554 has applied since 17 January 2025 and consolidates requirements that were previously scattered across supervisory guidelines and national circulars – from the governance of ICT risk to the oversight of critical ICT third-party service providers. As a regulation, DORA applies directly in all Member States and is further specified by regulatory and implementing technical standards (RTS/ITS) issued by the European Supervisory Authorities. For CISOs and compliance officers, the focus is now shifting from initial implementation to resilient day-to-day operation: reporting processes, the register of information, testing programmes and third-party management have to work in everyday practice.

The Essentials at a Glance

01

Scope and the five pillars

DORA applies to a broad range of supervised financial entities – from credit institutions and insurers to payment and investment firms and certain crypto-asset service providers – as well as to ICT third-party service providers serving the financial sector. In substance, the regulation rests on five pillars: ICT risk management (Art. 5–16), management and reporting of ICT-related incidents (Art. 17–23), digital operational resilience testing including TLPT (Art. 24–27), management of ICT third-party risk including oversight (Art. 28–44), and arrangements for sharing information on cyber threats (Art. 45). The detailed requirements are specified at a second level by RTS and ITS, which apply directly as delegated and implementing regulations.

02

ICT risk management (Art. 5–16)

At its core is a documented ICT risk management framework for which the management body bears overall responsibility. It follows a lifecycle of identification, protection and prevention, detection, response and recovery, and learning and evolving – including backup and recovery procedures, communication plans and regular review. For certain smaller and less interconnected entities, Art. 16 provides for a simplified ICT risk management framework with reduced requirements.

03

ICT incident reporting (Art. 17–23)

Financial entities must record and classify ICT-related incidents following a defined process and report major incidents to the competent authority – in Germany, BaFin acts as the national reporting hub. The classification criteria are governed by Delegated Regulation (EU) 2024/1772; deadlines, content and templates are laid down in Delegated Regulation (EU) 2025/301 and Implementing Regulation (EU) 2025/302: the initial notification is generally due within four hours of classifying an incident as major and no later than 24 hours after becoming aware of it, the intermediate report within 72 hours of the initial notification, and the final report within one month. Significant cyber threats may additionally be reported on a voluntary basis.

04

Resilience testing and TLPT (Art. 24–27)

All financial entities other than microenterprises must operate a risk-based digital operational resilience testing programme, ranging from vulnerability assessments to scenario-based testing. Entities identified for this purpose by the authorities must in addition carry out threat-led penetration testing (TLPT) under Art. 26/27 at least every three years – on live production systems and covering several or all critical or important functions; the competent authority may adjust the frequency. Criteria, scope, methodology and requirements for internal and external testers are specified in Delegated Regulation (EU) 2025/1190 (the RTS on TLPT), applicable since 8 July 2025. The Eurosystem's TIBER-EU framework, which the ECB fully aligned with DORA and the RTS on 11 February 2025, serves as the implementation guide.

05

ICT third-party risk and the register of information (Art. 28–30)

Chapter V requires financial entities to manage the risks arising from ICT service contracts across their entire lifecycle: strategy and policies including exit strategies (Art. 28), assessment of ICT concentration risk (Art. 29), and minimum contractual provisions covering, for example, security, audit and termination rights (Art. 30). The central instrument is the register of information under Art. 28(3) covering all contractual arrangements with ICT third-party service providers; Implementing Regulation (EU) 2024/2956 prescribes binding standard templates for this purpose. The submitted registers also serve the supervisory authorities as a data basis – among other things for the designation of critical ICT third-party service providers.

06

Oversight of critical ICT third-party providers (Art. 31–44)

With DORA, the three European Supervisory Authorities EBA, EIOPA and ESMA (the ESAs) receive for the first time a direct oversight mandate over ICT third-party service providers designated as critical for the financial sector. On 18 November 2025, the ESAs designated the first 19 critical ICT third-party service providers, including major cloud, data centre and network providers; the criticality assessment was based on the registers of information submitted by financial entities. Each designated provider is assigned a Lead Overseer from among the ESAs, who can request information, conduct investigations and issue recommendations. Financial entities' own responsibility for their third-party risk remains unaffected.

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

Amtsblatt der EU / EUR-Lex · 2022

Verordnung (EU) 2022/2554 (DORA)

Full text of the regulation with the pillar structure Art. 5–16, 17–23, 24–27, 28–44 and 45; applicable since 17 January 2025.

Amtsblatt der EU / EUR-Lex · 2025

Delegierte Verordnung (EU) 2025/1190 (RTS zu TLPT)

Specifies the identification criteria, scope, methodology and tester requirements for TLPT under Art. 26 DORA; applicable since 8 July 2025.

Amtsblatt der EU / EUR-Lex · 2024

Durchführungsverordnung (EU) 2024/2956 (ITS zum Informationsregister)

Binding standard templates and completion instructions for the register of information under Art. 28(3) DORA.

Europäische Zentralbank / Eurosystem · 2025

TIBER-EU Framework

Fully aligned with DORA and the RTS on TLPT on 11 February 2025; serves as the unified implementation guide for DORA TLPT.

EBA / EIOPA / ESMA · 2025

European Supervisory Authorities designate critical ICT third-party providers under the Digital Operational Resilience Act

Press release on the designation of the first 19 critical ICT third-party service providers under DORA oversight on 18 November 2025.

BaFin · 2026

Meldung schwerwiegender IKT-bezogener Vorfälle und erheblicher Cyberbedrohungen

Continuously updated supervisory page; confirms BaFin's role as the central reporting hub for the German financial sector, submission via the MVP portal and the forwarding of reports under Art. 19(6) DORA.

Implementing DORA requirements in a structured way?

From gap analysis and the register of information to TLPT preparation: in a no-obligation initial consultation, we jointly assess where your organisation stands today.