Security, Resilience & Assurance · European Union
Digital Operational Resilience Act
An EU regulation requiring financial entities and their critical ICT providers to build and prove digital operational resilience — covering risk management, incident reporting, resilience testing and third-party oversight in a single harmonised framework.
REGULATOREuropean Supervisory Authorities (EBA, ESMA, EIOPA)
REGIONEuropean Union
EFFECTIVE17 January 2025
Who it applies to
- Banks, insurers, investment firms and most other regulated financial entities in the EU
- ICT third-party service providers supporting critical or important financial functions
- Critical ICT providers designated for direct EU-level oversight
Key requirements
- A board-approved ICT risk management framework
- Classification and reporting of major ICT-related incidents
- Regular digital operational resilience testing, including threat-led penetration testing
- A structured register of information covering all ICT third-party arrangements
- Contractual provisions covering audit, exit and sub-outsourcing for critical ICT providers
Maximum penaltyDetermined at Member State level; periodic penalty payments of up to 1% of average daily worldwide turnover for critical ICT providers under direct oversight
Go to the source
Official resources
Praeferre's summary is a starting point, not legal advice. For the authoritative text and current guidance, go directly to the governing body.
Start your compliance journey
See how Praeferre automates DORA compliance
Continuous monitoring, evidence and reporting for DORA — alongside every other framework you need to satisfy.