Praeferre/Frameworks/DORA
Security, Resilience & Assurance · European Union

Digital Operational Resilience Act

An EU regulation requiring financial entities and their critical ICT providers to build and prove digital operational resilience — covering risk management, incident reporting, resilience testing and third-party oversight in a single harmonised framework.

REGULATOREuropean Supervisory Authorities (EBA, ESMA, EIOPA) REGIONEuropean Union EFFECTIVE17 January 2025

Who it applies to

  • Banks, insurers, investment firms and most other regulated financial entities in the EU
  • ICT third-party service providers supporting critical or important financial functions
  • Critical ICT providers designated for direct EU-level oversight

Key requirements

  • A board-approved ICT risk management framework
  • Classification and reporting of major ICT-related incidents
  • Regular digital operational resilience testing, including threat-led penetration testing
  • A structured register of information covering all ICT third-party arrangements
  • Contractual provisions covering audit, exit and sub-outsourcing for critical ICT providers

Maximum penaltyDetermined at Member State level; periodic penalty payments of up to 1% of average daily worldwide turnover for critical ICT providers under direct oversight

Go to the source

Official resources

Praeferre's summary is a starting point, not legal advice. For the authoritative text and current guidance, go directly to the governing body.

Start your compliance journey

See how Praeferre automates DORA compliance

Continuous monitoring, evidence and reporting for DORA — alongside every other framework you need to satisfy.