EU regulation · directly applicable Regulations / DORA

DORA: Digital operational resilience for financial entities

The Digital Operational Resilience Act obliges banks, insurers, payment institutions, crypto-asset service providers, and their critical ICT third-party providers to a unified ICT risk-management framework — directly applicable EU law, no national transposition required.

What is DORA

A regulation, directly applicable in all 27 member states.

Regulation (EU) 2022/2554 ("DORA") consolidates ICT risk requirements for the financial sector — previously scattered across various sectoral rules — into one unified framework. As a regulation, it applies directly, with no national implementing law, to banks, insurers, investment firms, payment and e-money institutions, crypto-asset service providers (CASPs), and other financial entities.

DORA also covers critical ICT third-party providers (cloud providers, data centres, etc.) via a dedicated oversight regime run by the European Supervisory Authorities (EBA, ESMA, EIOPA).

DORA is operationalised through a series of Regulatory and Implementing Technical Standards (RTS/ITS) from the ESAs — in particular on incident reporting, the third-party register (Register of Information), and resilience testing (TLPT).

Timeline

Key deadlines

27.12.2022Published

DORA published in the EU Official Journal

Regulation (EU) 2022/2554, Official Journal L 333; the regulation enters into force twenty days later.

17.01.2025Directly applicable

Full applicability EU-wide

Art. 64: "This Regulation shall apply from 17 January 2025." Directly applicable law in all member states, with no national implementing act.

ongoingRegister of Information

ICT third-party register maintained continuously

Under Art. 28, the Register of Information must be kept continuously up to date and made available to supervisors on request and per ITS requirements.

4h / 72h / 1 mo.Reporting cascade

Reporting major ICT incidents

Art. 19 combined with RTS/ITS (incl. Commission Delegated Regulation (EU) 2025/301): initial notification within 4 hours of classification, intermediate report within 72 hours, final report within one month.

Core obligations

What DORA actually requires.

ICT risk management

A holistic framework for identifying, protecting against, detecting, responding to, and recovering from ICT risk — including governance responsibility at management-body level.

Third-party register (RoI)

A complete, continuously up-to-date register of all ICT third-party providers, including concentration-risk assessment, reportable to the competent supervisory authority.

Major-incident reporting cascade

Staggered reporting within 4 hours (initial notification), 72 hours (intermediate report), and one month (final report) after classifying a major ICT-related incident.

Resilience testing (TLPT)

Regular testing of digital operational resilience; for significant institutions this includes threat-led penetration testing (TLPT).

How ReportAct solves it

Register, reporting cascade, and cross-mapping — in one pack.

Supply chain resilience you can prove. DORA treats third-party providers not as an appendix but as the core of operational resilience — ReportAct turns the register into the continuous evidence for it.

The ReportAct DORA Framework Pack maintains a complete ICT third-party register (RT.02.xx per the ESMA ITS structure) with XBRL export, so supervisory reporting can be produced directly from sealed data.

Concentration risk in the supervisor’s focus. The European Supervisory Authorities designate critical ICT third-party providers (CTPPs), and BaFin lists the concentration of ICT outsourcing as a focus risk. ReportAct calculates concentration risk deterministically from your register — clusters by service type and country, single-point-of-failure detection — and seals the result as evidence under Art. 29.

For the reporting cascade, ReportAct provides a deadline tracker with a 4-hour classification alert — every status change is cryptographically sealed, so it cannot be altered unnoticed after the fact.

Through cross-mapping to ISO/IEC 27001 and the EU AI Act, a control captured once automatically counts toward multiple regimes instead of maintaining third-party assessments repeatedly.

Product/positioning statement, not legal advice.

Primary sources

Read the originals

Regulation (EU) 2022/2554 (DORA), EUR-Lex https://eur-lex.europa.eu/eli/reg/2022/2554/oj/eng
Commission Delegated Regulation (EU) 2025/301 — RTS on the major-ICT-incident reporting cascade https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32025R0301
EBA — European Banking Authority, DORA topic page https://www.eba.europa.eu/
ESMA — European Securities and Markets Authority, DORA topic page https://www.esma.europa.eu/

ReportAct is not a consultancy. This page does not constitute legal advice. Operational detail of the reporting cascade and the Register of Information is continually refined through delegated and implementing acts (RTS/ITS) from the ESAs — check the current status directly with EBA, ESMA, or EIOPA before relying on it for binding decisions. Our Terms of Service apply.

Next step

A DORA register that holds up to an audit.

Start right away with your ICT third-party register — including reporting-cascade tracker and XBRL export.