Book an Appointment

DORA: Digital Operational Resilience in the Financial Sector

What Regulation (EU) 2022/2554 requires of financial entities and their ICT service providers – the five pillars, TLPT, the register of information and the oversight of critical third-party providers at a glance.

Last updated: July 2026 · Valeri Milke, ISO 27001 & ISO 42001 Lead Auditor

5pillars of Regulation (EU) 2022/2554
4 hinitial notification – generally after classification as major
3years: minimum TLPT cycle for identified entities
19critical ICT third-party providers designated on 18 Nov 2025

With the Digital Operational Resilience Act (DORA), the EU has for the first time created a unified legal framework for the digital operational resilience of the financial sector. Regulation (EU) 2022/2554 has applied since 17 January 2025 and consolidates requirements that were previously scattered across supervisory guidelines and national circulars – from the governance of ICT risk to the oversight of critical ICT third-party service providers. As a regulation, DORA applies directly in all Member States and is further specified by regulatory and implementing technical standards (RTS/ITS) issued by the European Supervisory Authorities. For CISOs and compliance officers, the focus is now shifting from initial implementation to resilient day-to-day operation: reporting processes, the register of information, testing programmes and third-party management have to work in everyday practice.

DORA milestones

From applicability to oversight – tap a milestone for details.

The Essentials at a Glance

Six topic blocks – tap to expand.

The five pillars of DORA

Pick a pillar – articles, core obligations and the legal acts that specify them at a glance.

Art. 5–16
  • A documented ICT risk management framework for which the management body bears overall responsibility.
  • Lifecycle of identification, protection and prevention, detection, response and recovery, and learning and evolving.
  • Art. 16 provides for a simplified framework with reduced requirements for certain smaller and less interconnected entities.
management bodybackup & recoverycommunication planssimplified framework (Art. 16)
In-depth whitepaper

DORA Reality Check — Third-Party Risk & Agentic AI

Eighteen months of DORA in one CISO whitepaper: year-one supervisory findings, the supply-chain cascade and the new risks introduced by AI agents — as an actionable roadmap.

Third-party cascade

How Art. 28–30 reaches thousands of “indirectly regulated” suppliers, and why certificates alone fall short.

Agentic AI as ICT risk

AI agents under DORA, shadow AI, the agentic attack surface and the controls that actually hold.

AI-accelerated attackers

The time-to-exploit collapse, AI offense and defense, and what it means for TLPT logic.

12-move playbook

Twelve concrete moves for the next twelve months — plus the 2026–28 compliance calendar.

Download the whitepaper (free)

English-language whitepaper · direct download after a short request.

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

Amtsblatt der EU / EUR-Lex · 2022

Verordnung (EU) 2022/2554 (DORA)

Full text of the regulation with the pillar structure Art. 5–16, 17–23, 24–27, 28–44 and 45; applicable since 17 January 2025.

Amtsblatt der EU / EUR-Lex · 2025

Delegierte Verordnung (EU) 2025/1190 (RTS zu TLPT)

Specifies the identification criteria, scope, methodology and tester requirements for TLPT under Art. 26 DORA; applicable since 8 July 2025.

Amtsblatt der EU / EUR-Lex · 2024

Durchführungsverordnung (EU) 2024/2956 (ITS zum Informationsregister)

Binding standard templates and completion instructions for the register of information under Art. 28(3) DORA.

Europäische Zentralbank / Eurosystem · 2025

TIBER-EU Framework

Fully aligned with DORA and the RTS on TLPT on 11 February 2025; serves as the unified implementation guide for DORA TLPT.

EBA / EIOPA / ESMA · 2025

European Supervisory Authorities designate critical ICT third-party providers under the Digital Operational Resilience Act

Press release on the designation of the first 19 critical ICT third-party service providers under DORA oversight on 18 November 2025.

BaFin · 2026

Meldung schwerwiegender IKT-bezogener Vorfälle und erheblicher Cyberbedrohungen

Continuously updated supervisory page; confirms BaFin's role as the central reporting hub for the German financial sector, submission via the MVP portal and the forwarding of reports under Art. 19(6) DORA.

Implementing DORA requirements in a structured way?

From gap analysis and the register of information to TLPT preparation: in a no-obligation initial consultation, we jointly assess where your organisation stands today.