What is DORA? The Digital Operational Resilience Act is an EU regulation that sets one binding standard for how the financial sector — and the technology providers it depends on — withstands, responds to, and recovers from digital disruption. It has applied since January 2025, and because it is a regulation rather than a directive, it lands the same way in every member state. This guide covers who it binds, its five pillars, and how its requirements reach deep into third-party risk.
DORA — the Digital Operational Resilience Act, Regulation (EU) 2022/2554 — is an EU law in force since January 2025 that sets uniform requirements for the digital operational resilience of financial entities and the ICT third-party providers they rely on.
DORA is a European Union regulation — Regulation (EU) 2022/2554 — that entered into force in January 2023 and has applied since 17 January 2025. Its purpose is narrow to state and broad in effect: keep the financial system running through technology failures, cyberattacks, and outages. Before DORA, digital-resilience rules for financial firms were scattered across sectors and member states. DORA consolidates that patchwork into a single rulebook.
The word regulation is doing real work here. Unlike a directive — which each member state writes into its own national law — a regulation applies directly and identically across the EU. There is no national transposition to wait for and no twenty-seven-way variation to track: if you are in scope, the same text binds you in Dublin, Frankfurt, and Milan alike. That is the sharpest structural contrast with NIS2, which we return to below.
DORA covers a wide sweep of financial entities — around twenty categories — plus the technology providers they depend on. In scope, among others:
Crucially, DORA reaches past the financial entities themselves to their ICT third-party service providers — cloud platforms, data and analytics services, software vendors. Providers judged systemically important can be designated critical ICT third-party providers and placed under a new EU-level oversight framework run by the European Supervisory Authorities. For the first time, a hyperscale cloud provider can be overseen directly for the resilience of the financial services it underpins. The reach is deliberate: a bank can be impeccably run and still be taken down by a provider three steps removed from its balance sheet, so DORA regulates the dependency, not only the entity.
DORA is usually described as five pillars. Together they turn resilience from an aspiration into a set of testable obligations:
For anyone in third-party risk, the fourth pillar is the centre of gravity. DORA requires every financial entity to keep a register of information: a structured record of all contractual arrangements for ICT services, maintained at entity, sub-consolidated, and consolidated levels, and shareable with regulators on request. It is, in effect, a mandated inventory of your entire technology supply chain.
DORA also dictates what those contracts must contain — service levels, access and audit rights, exit strategies, and the locations of data and processing — and expects you to scale scrutiny to how critical the function is. That maps cleanly onto exposure-based thinking: the provider running a critical-or-important function warrants full-depth diligence; a low-exposure tool does not. Building the register is where most firms discover they never had a complete list of who touches what — which is precisely why coverage has to be complete by construction, not sampled. DORA is equally alert to concentration risk — too many critical functions resting on a single provider — which only becomes visible once the register is complete and classified by criticality.
The core dates are simple. DORA entered into force on 16 January 2023 and has applied since 17 January 2025; the technical standards that flesh it out (the RTS and ITS) have been arriving alongside. Firms in scope should already be maintaining the register, classifying incidents against DORA's criteria, and running their testing programmes.
One question comes up constantly: how does DORA relate to NIS2? Many financial entities technically fall within both, but DORA is lex specialis — the more specific law governs the ICT-resilience obligations it covers, so financial entities generally follow DORA rather than NIS2 on those points. The two are designed to interlock, not stack, and a firm that has mapped its ICT arrangements once should be able to satisfy both from the same underlying register.
This is an informational overview, not legal advice. Because DORA is a regulation it applies directly across the EU with no national transposition, but competent authorities and the detailed technical standards fill in specifics — verify the current text and any guidance for your entity type with qualified counsel. Last reviewed July 2026.
Its inside-out model ingests your whole vendor master and classifies every ICT arrangement by your own exposure — so the register of information is complete, not sampled. When a major incident is classified, CIIC keeps DORA's ~4-hour clock and drafts the reports.
How Polestead handles DORA →DORA — the Digital Operational Resilience Act, Regulation (EU) 2022/2554 — is an EU law, applying since 17 January 2025, that sets uniform requirements for the digital operational resilience of financial entities and their ICT third-party providers.
It entered into force on 16 January 2023 and has applied since 17 January 2025. Firms in scope should already meet its requirements, including maintaining the register of information and classifying incidents against DORA's criteria.
Directly, if they are EU financial entities. Indirectly and significantly, if they are ICT providers serving EU financial entities — DORA's third-party obligations flow through contracts, and critical providers can be placed under EU oversight regardless of where they are based.
ICT risk management; ICT incident management, classification and reporting; digital operational resilience testing; ICT third-party risk management; and information sharing.