Digital Operational Resilience Act (DORA)

Jurisdiction:
European Union
enforcing
Effective:
Jan 17, 2025
Authority:
European Supervisory Authorities (EBA, EIOPA, ESMA)
Official text Verified Mar 26, 2026

Obligations Covered

Risk Assessment Incident Reporting Record-Keeping & Documentation

ICT Risk Management #

Obligation:
Risk Assessment
enforcing
Effective:
Jan 17, 2025
Risk tier:
all
Scope:
providers, deployers

Requirements

RequirementDetails
ICT risk management frameworkComprehensive framework for identifying, assessing, and mitigating ICT risks
GovernanceManagement body must approve and oversee the ICT risk management framework
Business continuityEstablish ICT business continuity and disaster recovery plans
Cyber risk managementAddress cybersecurity risks as part of the ICT risk framework

Penalties

ViolationFine
Non-complianceDetermined by national competent authorities per member state law

ICT Incident Reporting #

Obligation:
Incident Reporting
enforcing
Effective:
Jan 17, 2025
Risk tier:
all
Scope:
providers, deployers

Requirements

RequirementDetails
Classify incidentsClassify ICT-related incidents using ESA criteria
Major incident reportingNotify competent authorities of major ICT incidents
Reporting thresholds>24 hours duration, >2 hours critical service disruption, ≥2 EU states affected, or >EUR 100,000 economic impact
Voluntary threat reportingEncouraged to report significant cyber threats

Penalties

ViolationFine
Non-complianceDetermined by national competent authorities per member state law

Digital Operational Resilience Testing #

Obligation:
Record Keeping
enforcing
Effective:
Jan 17, 2025
Risk tier:
all
Scope:
providers, deployers

Requirements

RequirementDetails
Resilience testing programConduct regular testing of ICT systems and tools
Threat-led penetration testingSignificant entities must perform TLPT aligned with TIBER-EU
Documentation and remediationDocument test results and remediate identified vulnerabilities
Register of ICT contractsMaintain and submit register of third-party ICT contracts to authorities

Penalties

ViolationFine
Non-complianceDetermined by national competent authorities per member state law

Third-Party ICT Risk Management #

Obligation:
Risk Assessment
enforcing
Effective:
Jan 17, 2025
Risk tier:
all
Scope:
providers, deployers

Requirements

RequirementDetails
Contractual requirementsKey contractual provisions for ICT third-party service agreements
Concentration riskAssess and manage concentration risk from third-party ICT dependencies
Critical provider oversightDesignated critical third-party providers (CTPPs) subject to ESA oversight
Exit strategiesMaintain exit strategies for critical ICT third-party services

Penalties

ViolationFine
CTPP non-complianceESAs may impose periodic penalty payments on critical third-party providers