DORA: Digital operational resilience for financial entities
The Digital Operational Resilience Act obliges banks, insurers, payment institutions, crypto-asset service providers, and their critical ICT third-party providers to a unified ICT risk-management framework — directly applicable EU law, no national transposition required.
A regulation, directly applicable in all 27 member states.
Regulation (EU) 2022/2554 ("DORA") consolidates ICT risk requirements for the financial sector — previously scattered across various sectoral rules — into one unified framework. As a regulation, it applies directly, with no national implementing law, to banks, insurers, investment firms, payment and e-money institutions, crypto-asset service providers (CASPs), and other financial entities.
DORA also covers critical ICT third-party providers (cloud providers, data centres, etc.) via a dedicated oversight regime run by the European Supervisory Authorities (EBA, ESMA, EIOPA).
DORA is operationalised through a series of Regulatory and Implementing Technical Standards (RTS/ITS) from the ESAs — in particular on incident reporting, the third-party register (Register of Information), and resilience testing (TLPT).
Key deadlines
DORA published in the EU Official Journal
Regulation (EU) 2022/2554, Official Journal L 333; the regulation enters into force twenty days later.
Full applicability EU-wide
Art. 64: "This Regulation shall apply from 17 January 2025." Directly applicable law in all member states, with no national implementing act.
ICT third-party register maintained continuously
Under Art. 28, the Register of Information must be kept continuously up to date and made available to supervisors on request and per ITS requirements.
Reporting major ICT incidents
Art. 19 combined with RTS/ITS (incl. Commission Delegated Regulation (EU) 2025/301): initial notification within 4 hours of classification, intermediate report within 72 hours, final report within one month.
What DORA actually requires.
ICT risk management
A holistic framework for identifying, protecting against, detecting, responding to, and recovering from ICT risk — including governance responsibility at management-body level.
Third-party register (RoI)
A complete, continuously up-to-date register of all ICT third-party providers, including concentration-risk assessment, reportable to the competent supervisory authority.
Major-incident reporting cascade
Staggered reporting within 4 hours (initial notification), 72 hours (intermediate report), and one month (final report) after classifying a major ICT-related incident.
Resilience testing (TLPT)
Regular testing of digital operational resilience; for significant institutions this includes threat-led penetration testing (TLPT).
Register, reporting cascade, and cross-mapping — in one pack.
Supply chain resilience you can prove. DORA treats third-party providers not as an appendix but as the core of operational resilience — ReportAct turns the register into the continuous evidence for it.
The ReportAct DORA Framework Pack maintains a complete ICT third-party register (RT.02.xx per the ESMA ITS structure) with XBRL export, so supervisory reporting can be produced directly from sealed data.
Concentration risk in the supervisor’s focus. The European Supervisory Authorities designate critical ICT third-party providers (CTPPs), and BaFin lists the concentration of ICT outsourcing as a focus risk. ReportAct calculates concentration risk deterministically from your register — clusters by service type and country, single-point-of-failure detection — and seals the result as evidence under Art. 29.
For the reporting cascade, ReportAct provides a deadline tracker with a 4-hour classification alert — every status change is cryptographically sealed, so it cannot be altered unnoticed after the fact.
Through cross-mapping to ISO/IEC 27001 and the EU AI Act, a control captured once automatically counts toward multiple regimes instead of maintaining third-party assessments repeatedly.
Product/positioning statement, not legal advice.
Read the originals
ReportAct is not a consultancy. This page does not constitute legal advice. Operational detail of the reporting cascade and the Register of Information is continually refined through delegated and implementing acts (RTS/ITS) from the ESAs — check the current status directly with EBA, ESMA, or EIOPA before relying on it for binding decisions. Our Terms of Service apply.
A DORA register that holds up to an audit.
Start right away with your ICT third-party register — including reporting-cascade tracker and XBRL export.