Does Digital Operational Resilience Act (DORA) require Risk Assessment?

European Union • enforcing

Yes — 2 provisions

Requirements at a glance

This regulation imposes 8 specific requirements for Risk Assessment across 2 provisions:

ICT Risk Management #

Obligation:
Risk Assessment
enforcing
Effective:
Jan 17, 2025
Risk tier:
all
Scope:
providers, deployers

Requirements

RequirementDetails
ICT risk management frameworkComprehensive framework for identifying, assessing, and mitigating ICT risks
GovernanceManagement body must approve and oversee the ICT risk management framework
Business continuityEstablish ICT business continuity and disaster recovery plans
Cyber risk managementAddress cybersecurity risks as part of the ICT risk framework

Penalties

ViolationFine
Non-complianceDetermined by national competent authorities per member state law

Third-Party ICT Risk Management #

Obligation:
Risk Assessment
enforcing
Effective:
Jan 17, 2025
Risk tier:
all
Scope:
providers, deployers

Requirements

RequirementDetails
Contractual requirementsKey contractual provisions for ICT third-party service agreements
Concentration riskAssess and manage concentration risk from third-party ICT dependencies
Critical provider oversightDesignated critical third-party providers (CTPPs) subject to ESA oversight
Exit strategiesMaintain exit strategies for critical ICT third-party services

Penalties

ViolationFine
CTPP non-complianceESAs may impose periodic penalty payments on critical third-party providers
View full regulation View obligation Obligation matrix