Get Demo
↑

What Is DORA? Digital Operational Resilience Act Explained

Regulation (EU) 2022/2554 (DORA) sets binding ICT risk, incident, testing, third-party.

Published: September 2026 Compliance · DORA 8–12 min read

DORA — the Digital Operational Resilience Act, formally Regulation (EU) 2022/2554 — is a directly applicable EU regulation that requires in-scope financial entities to withstand, respond to, and recover from ICT-related disruptions. It entered into application on 17 January 2025.

Related: DORA hub · Five pillars · Who it applies to · CSA for DORA.

Five pillars: ICT risk management; ICT-related incident reporting; digital operational resilience testing; ICT third-party risk management; and information sharing. Incident clocks for major ICT-related incidents follow the Commission Delegated Regulation on reporting content and timelines — see reporting deadlines.

Why DORA Exists

Financial services depend on ICT and critical suppliers. DORA harmonises operational-resilience rules across the Union so supervisors can expect comparable ICT governance, major-incident reporting, testing, and third-party oversight — without relying only on fragmented national ICT circulars.

The Five Pillars (Map)

  1. ICT risk management — Articles 5–16 themes (governance through learning and evolution)
  2. Incident management & reporting — classification and major-incident notifications
  3. Digital operational resilience testing — including TLPT for significant entities
  4. ICT third-party risk — register of information, contractual keys, CTPP oversight
  5. Information sharing — voluntary cyber-threat intelligence arrangements

Deep dive: The 5 pillars of DORA explained.

DORA vs NIS2

DORA is a sectoral regulation for financial entities and their ICT providers. NIS2 is a horizontal cybersecurity directive for essential/important entities. Many banks sit under both conversations — see NIS2 vs DORA.

Where Programmes Usually Start

How CyberSilo Helps

Build a Pillar-Mapped DORA Programme

Map ICT risk, incident clocks, testing, and third-party evidence with CyberSilo CSA and ThreatHawk.

Frequently Asked Questions

Is DORA a directive or a regulation?

DORA is Regulation (EU) 2022/2554 — directly applicable across EU Member States without national transposition of the core text (RTS/ITS and national supervisory practice still matter).

When did DORA start applying?

DORA became applicable on 17 January 2025.

Does ISO 27001 replace DORA?

No. ISO 27001 helps evidencing ICT controls but does not replace DORA’s incident clocks, TLPT rules, register of information, or CTPP oversight — see DORA vs ISO 27001.

Hub · ICT risk (Arts 5–16) · RTS / ITS list · CSA

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!