The Digital Operational Resilience Act (DORA) applies from today.
Five pillars
- ICT risk management: a comprehensive, documented framework owned by the management body.
- ICT-related incident reporting: classification and reporting of major incidents to competent authorities.
- Digital operational resilience testing, including threat-led penetration testing (TLPT) for designated entities at least every three years.
- ICT third-party risk management, including mandatory contract terms (Articles 28 to 30) and a register of information.
- Information sharing on cyber threats.
Critical ICT third-party providers are subject to direct EU oversight. UK technology and service providers with EU financial clients should expect contract renegotiations, audit and access rights, and incident assistance obligations.
Source: Regulation (EU) 2022/2554, DORA (EUR-Lex)
This update is general information, not legal advice. If you would like help assessing the impact on your information security or privacy programme, contact us.