ICT risk management for the financial sector, with no transposition patchwork.
How it allocates obligations
Operational resilience of financial entities and their ICT dependencies.
Regulated actor
Financial entity · ICT third-party service provider
Protected party
End user
Territorial reach
Established in the EU
Implementation model
Directly applicable
Enforcement mechanism
Financial supervisors; ESA oversight framework for critical ICT third-party providers.
Key dates
Entry into force, application and transposition are different events and are kept apart. A date at month precision is shown as a month rather than invented as a day.
14 December 2022AdoptionAdoption
27 December 2022Publication in the Official JournalPublication in the Official Journal
16 January 2023Entry into forceEntry into force
17 January 2025Application dateDORA becomes applicable, with no transposition patchwork.What it requires: ICT risk management, incident reporting, resilience testing and third-party risk arrangements in place.
2 rules in the dataset turn on this instrument. They are conditions, not a test: the engine ranks them against what you actually answer, and downgrades rather than excludes where a question is left blank.
Yes
actor Financial entity
DORA has applied since 17 January 2025 as a Regulation, with no transposition patchwork. It governs ICT risk management, incident reporting, digital operational resilience testing and third-party risk arrangements for financial entities.
Last verified 27 September 2026
Potentially applicable
actor Provider of data processing services or ICT third-party service provideractivity Cloud or data processing services or Operating ICT for financial services
An ICT provider serving financial entities is reached through the contractual requirements DORA imposes on its customers, and — if designated critical — directly through the ESA oversight framework.
7 provisions recorded. This is what the dataset holds, not the whole instrument — an article that is not here has not been entered, which is a different statement from its not existing.
Article
Heading
Binds
Applies
Art. 5
Governance and organisationFinancial entities must have an internal governance and control framework for the effective and prudent management of ICT risk; the management body defines, approves, oversees and is responsible for the ICT risk management framework.
Financial entity
Applies from 17 January 2025the instrument’s general date; nothing specific to this article is recorded
Art. 6
ICT risk management frameworkFinancial entities must have a sound, comprehensive and well-documented ICT risk management framework as part of their overall risk management system.
Financial entity
Applies from 17 January 2025the instrument’s general date; nothing specific to this article is recorded
Art. 17
ICT-related incident management processFinancial entities must define, establish and implement a process to detect, manage and notify ICT-related incidents.
Financial entity
Applies from 17 January 2025the instrument’s general date; nothing specific to this article is recorded
Art. 19
Reporting of major ICT-related incidents and voluntary notification of significant cyber threatsFinancial entities must report major ICT-related incidents to their competent authority, and may notify significant cyber threats voluntarily.
Financial entity
Applies from 17 January 2025the instrument’s general date; nothing specific to this article is recorded
Art. 24
General requirements for the performance of digital operational resilience testingFinancial entities other than microenterprises must establish, maintain and review a digital operational resilience testing programme as part of the ICT risk management framework.
Financial entity
Applies from 17 January 2025the instrument’s general date; nothing specific to this article is recorded
Art. 28
General principles (ICT third-party risk)Financial entities must manage ICT third-party risk as an integral component of ICT risk within their ICT risk management framework.
Financial entity · ICT third-party service provider
Applies from 17 January 2025the instrument’s general date; nothing specific to this article is recorded
Art. 31
Designation of critical ICT third-party service providersThe ESAs, through the Joint Committee and on the Oversight Forum's recommendation, designate critical ICT third-party service providers and appoint as Lead Overseer for each the ESA responsible for the financial entities holding the largest share of total assets among its users.
ICT third-party service provider
Applies from 17 January 2025the instrument’s general date; nothing specific to this article is recorded
Enforcement
No enforcement recorded
This dataset holds no enforcement action under this instrument. That is what the record says; it is not a finding that none has been taken.
Every statement this site makes about DORA, graded by what actually carries it. The grade is derived from the claim type and its sources, never stored, so it cannot drift from what it describes.
The instrument record itself was last verified on 27 August 2026; every claim below carries its own date.
1 Interpretation
Interpretationinterpretation
The EU's directive-based instruments underperform its regulation-based ones badly — the strongest single argument for the regulation-first drafting approach used elsewhere in the rulebook.
1 recorded interaction with other instruments — each with a direction, the provisions that carry it and its own sources. Direction is preserved as recorded: an instrument that amends another is not the same as one amended by it.