Guide · Regulation

What DORA is, and who it binds.

Regulation · 8 min read · Updated July 2026

What is DORA? The Digital Operational Resilience Act is an EU regulation that sets one binding standard for how the financial sector — and the technology providers it depends on — withstands, responds to, and recovers from digital disruption. It has applied since January 2025, and because it is a regulation rather than a directive, it lands the same way in every member state. This guide covers who it binds, its five pillars, and how its requirements reach deep into third-party risk.

In one sentence

DORA — the Digital Operational Resilience Act, Regulation (EU) 2022/2554 — is an EU law in force since January 2025 that sets uniform requirements for the digital operational resilience of financial entities and the ICT third-party providers they rely on.

What DORA actually is

DORA is a European Union regulation — Regulation (EU) 2022/2554 — that entered into force in January 2023 and has applied since 17 January 2025. Its purpose is narrow to state and broad in effect: keep the financial system running through technology failures, cyberattacks, and outages. Before DORA, digital-resilience rules for financial firms were scattered across sectors and member states. DORA consolidates that patchwork into a single rulebook.

The word regulation is doing real work here. Unlike a directive — which each member state writes into its own national law — a regulation applies directly and identically across the EU. There is no national transposition to wait for and no twenty-seven-way variation to track: if you are in scope, the same text binds you in Dublin, Frankfurt, and Milan alike. That is the sharpest structural contrast with NIS2, which we return to below.

Who DORA covers

DORA covers a wide sweep of financial entities — around twenty categories — plus the technology providers they depend on. In scope, among others:

  • Banks, payment institutions, e-money institutions, and investment firms
  • Insurance and reinsurance undertakings, and insurance intermediaries
  • Crypto-asset service providers and issuers of asset-referenced tokens
  • Trading venues, central counterparties, central securities depositories, and trade repositories
  • Fund managers, credit-rating agencies, and more

Crucially, DORA reaches past the financial entities themselves to their ICT third-party service providers — cloud platforms, data and analytics services, software vendors. Providers judged systemically important can be designated critical ICT third-party providers and placed under a new EU-level oversight framework run by the European Supervisory Authorities. For the first time, a hyperscale cloud provider can be overseen directly for the resilience of the financial services it underpins. The reach is deliberate: a bank can be impeccably run and still be taken down by a provider three steps removed from its balance sheet, so DORA regulates the dependency, not only the entity.

The five pillars

DORA is usually described as five pillars. Together they turn resilience from an aspiration into a set of testable obligations:

  1. ICT risk management. A governance and control framework to identify, protect against, detect, respond to, and recover from ICT risk — owned and overseen by the management body, not delegated away.
  2. ICT incident management, classification, and reporting. Detect and classify ICT-related incidents against set criteria, and report major ones to your competent authority: an initial notification within roughly four hours of classification, then intermediate and final reports. This is ordinary cyber incident management with a statutory clock bolted on.
  3. Digital operational resilience testing. Test systems regularly; the most significant entities must run threat-led penetration testing at least every three years.
  4. ICT third-party risk management. Manage the risk your providers carry — including a register of every ICT arrangement and mandatory contractual terms. More on this below.
  5. Information sharing. Voluntary arrangements to exchange cyber-threat intelligence among financial entities.

The third-party angle: the register of information

For anyone in third-party risk, the fourth pillar is the centre of gravity. DORA requires every financial entity to keep a register of information: a structured record of all contractual arrangements for ICT services, maintained at entity, sub-consolidated, and consolidated levels, and shareable with regulators on request. It is, in effect, a mandated inventory of your entire technology supply chain.

DORA also dictates what those contracts must contain — service levels, access and audit rights, exit strategies, and the locations of data and processing — and expects you to scale scrutiny to how critical the function is. That maps cleanly onto exposure-based thinking: the provider running a critical-or-important function warrants full-depth diligence; a low-exposure tool does not. Building the register is where most firms discover they never had a complete list of who touches what — which is precisely why coverage has to be complete by construction, not sampled. DORA is equally alert to concentration risk — too many critical functions resting on a single provider — which only becomes visible once the register is complete and classified by criticality.

The timeline, and where it bites

The core dates are simple. DORA entered into force on 16 January 2023 and has applied since 17 January 2025; the technical standards that flesh it out (the RTS and ITS) have been arriving alongside. Firms in scope should already be maintaining the register, classifying incidents against DORA's criteria, and running their testing programmes.

One question comes up constantly: how does DORA relate to NIS2? Many financial entities technically fall within both, but DORA is lex specialis — the more specific law governs the ICT-resilience obligations it covers, so financial entities generally follow DORA rather than NIS2 on those points. The two are designed to interlock, not stack, and a firm that has mapped its ICT arrangements once should be able to satisfy both from the same underlying register.

This is an informational overview, not legal advice. Because DORA is a regulation it applies directly across the EU with no national transposition, but competent authorities and the detailed technical standards fill in specifics — verify the current text and any guidance for your entity type with qualified counsel. Last reviewed July 2026.

DORA, operationalised
Polestead makes the register complete by construction.

Its inside-out model ingests your whole vendor master and classifies every ICT arrangement by your own exposure — so the register of information is complete, not sampled. When a major incident is classified, CIIC keeps DORA's ~4-hour clock and drafts the reports.

How Polestead handles DORA →
FAQ

Common questions.

What is DORA?+

DORA — the Digital Operational Resilience Act, Regulation (EU) 2022/2554 — is an EU law, applying since 17 January 2025, that sets uniform requirements for the digital operational resilience of financial entities and their ICT third-party providers.

When does DORA apply?+

It entered into force on 16 January 2023 and has applied since 17 January 2025. Firms in scope should already meet its requirements, including maintaining the register of information and classifying incidents against DORA's criteria.

Does DORA apply to companies outside the EU?+

Directly, if they are EU financial entities. Indirectly and significantly, if they are ICT providers serving EU financial entities — DORA's third-party obligations flow through contracts, and critical providers can be placed under EU oversight regardless of where they are based.

What are DORA's five pillars?+

ICT risk management; ICT incident management, classification and reporting; digital operational resilience testing; ICT third-party risk management; and information sharing.

Keep reading
DORA vs NIS2
How the two EU regimes differ and overlap.
DORA incident reporting
The ~4-hour clock and the reports, in detail.
DORA on Polestead →
Register and incident clocks, covered.