1. Digital Policy
  2. Instruments
  3. DORA

Regulation · directly applicable · CELEX 32022R2554

DORA

Regulation (EU) 2022/2554 on digital operational resilience for the financial sector

Official text: Regulation (EU) 2022/2554 (Digital Operational Resilience Act)Tier 1 · primary law

Status
Applicable as of 19 August 2026
Competent authority
ESAs
Sanction ceiling
none recorded

What it does

ICT risk management for the financial sector, with no transposition patchwork.

How it allocates obligations

Operational resilience of financial entities and their ICT dependencies.

Regulated actor
Financial entity · ICT third-party service provider
Protected party
End user
Territorial reach
Established in the EU
Implementation model
Directly applicable
Enforcement mechanism
Financial supervisors; ESA oversight framework for critical ICT third-party providers.

Key dates

Entry into force, application and transposition are different events and are kept apart. A date at month precision is shown as a month rather than invented as a day.

  1. 14 December 2022AdoptionAdoption
  2. 27 December 2022Publication in the Official JournalPublication in the Official Journal
  3. 16 January 2023Entry into forceEntry into force
  4. 17 January 2025Application dateDORA becomes applicable, with no transposition patchwork.What it requires: ICT risk management, incident reporting, resilience testing and third-party risk arrangements in place.

The whole compliance calendar, filterable →

Who it applies to

2 rules in the dataset turn on this instrument. They are conditions, not a test: the engine ranks them against what you actually answer, and downgrades rather than excludes where a question is left blank.

Yes

actor Financial entity

DORA has applied since 17 January 2025 as a Regulation, with no transposition patchwork. It governs ICT risk management, incident reporting, digital operational resilience testing and third-party risk arrangements for financial entities.

Last verified 27 September 2026

Potentially applicable

actor Provider of data processing services or ICT third-party service provideractivity Cloud or data processing services or Operating ICT for financial services

An ICT provider serving financial entities is reached through the contractual requirements DORA imposes on its customers, and — if designated critical — directly through the ESA oversight framework.

Last verified 27 September 2026

Run these against your situation →

Key provisions

7 provisions recorded. This is what the dataset holds, not the whole instrument — an article that is not here has not been entered, which is a different statement from its not existing.

ArticleHeadingBindsApplies
Art. 5Governance and organisationFinancial entities must have an internal governance and control framework for the effective and prudent management of ICT risk; the management body defines, approves, oversees and is responsible for the ICT risk management framework.Financial entityApplies from 17 January 2025the instrument’s general date; nothing specific to this article is recorded
Art. 6ICT risk management frameworkFinancial entities must have a sound, comprehensive and well-documented ICT risk management framework as part of their overall risk management system.Financial entityApplies from 17 January 2025the instrument’s general date; nothing specific to this article is recorded
Art. 17ICT-related incident management processFinancial entities must define, establish and implement a process to detect, manage and notify ICT-related incidents.Financial entityApplies from 17 January 2025the instrument’s general date; nothing specific to this article is recorded
Art. 19Reporting of major ICT-related incidents and voluntary notification of significant cyber threatsFinancial entities must report major ICT-related incidents to their competent authority, and may notify significant cyber threats voluntarily.Financial entityApplies from 17 January 2025the instrument’s general date; nothing specific to this article is recorded
Art. 24General requirements for the performance of digital operational resilience testingFinancial entities other than microenterprises must establish, maintain and review a digital operational resilience testing programme as part of the ICT risk management framework.Financial entityApplies from 17 January 2025the instrument’s general date; nothing specific to this article is recorded
Art. 28General principles (ICT third-party risk)Financial entities must manage ICT third-party risk as an integral component of ICT risk within their ICT risk management framework.Financial entity · ICT third-party service providerApplies from 17 January 2025the instrument’s general date; nothing specific to this article is recorded
Art. 31Designation of critical ICT third-party service providersThe ESAs, through the Joint Committee and on the Oversight Forum's recommendation, designate critical ICT third-party service providers and appoint as Lead Overseer for each the ESA responsible for the financial entities holding the largest share of total assets among its users.ICT third-party service providerApplies from 17 January 2025the instrument’s general date; nothing specific to this article is recorded

Enforcement

No enforcement recorded

This dataset holds no enforcement action under this instrument. That is what the record says; it is not a finding that none has been taken.

The whole enforcement observatory →

Evidence and sources

Every statement this site makes about DORA, graded by what actually carries it. The grade is derived from the claim type and its sources, never stored, so it cannot drift from what it describes.

The instrument record itself was last verified on 27 August 2026; every claim below carries its own date.

1 Interpretation
Interpretationinterpretation

The EU's directive-based instruments underperform its regulation-based ones badly — the strongest single argument for the regulation-first drafting approach used elsewhere in the rulebook.

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part VII

Read it in the brief →Last verified 27 August 2026

The full bibliography and the evidence method →

How it interacts

1 recorded interaction with other instruments — each with a direction, the provisions that carry it and its own sources. Direction is preserved as recorded: an instrument that amends another is not the same as one amended by it.