Don’t do SECURITY. Do business SECURELY.

DORA now applies across the EU financial sector

The Digital Operational Resilience Act applies from today to EU financial entities and their ICT third-party providers.

The Digital Operational Resilience Act (DORA) applies from today.

Five pillars

  • ICT risk management: a comprehensive, documented framework owned by the management body.
  • ICT-related incident reporting: classification and reporting of major incidents to competent authorities.
  • Digital operational resilience testing, including threat-led penetration testing (TLPT) for designated entities at least every three years.
  • ICT third-party risk management, including mandatory contract terms (Articles 28 to 30) and a register of information.
  • Information sharing on cyber threats.

Critical ICT third-party providers are subject to direct EU oversight. UK technology and service providers with EU financial clients should expect contract renegotiations, audit and access rights, and incident assistance obligations.

Source: Regulation (EU) 2022/2554, DORA (EUR-Lex)

This update is general information, not legal advice. If you would like help assessing the impact on your information security or privacy programme, contact us.

More insights