DORA
In force European Union · In force Jan 16, 2023 · no upcoming deadlines
Deadlines
Summaries for reference, not legal advice. Check the official text.
What it does
Harmonised ICT risk-management, major ICT-incident reporting, digital operational resilience testing (including threat-led penetration testing) and ICT third-party risk rules for EU financial entities. Financial entities must keep a register of all ICT third-party contracts. Critical ICT third-party providers (cloud, data centres and similar) come under direct EU oversight.
- Who it applies to
- About 20 types of EU financial entities (credit institutions, payment and e-money institutions, investment firms, crypto-asset service providers, insurers, trading venues, CCPs and others) and ICT third-party service providers designated as critical. Microenterprises and some small entities get a simplified framework.
- Penalties
- Administrative penalties for financial entities are set by Member States. Critical ICT third-party providers face periodic penalty payments of up to 1% of average daily worldwide turnover of the preceding business year, imposed daily for up to six months (Art 35(8)).
- Enforced by
- National competent authorities for financial supervision; the European Supervisory Authorities (EBA, EIOPA, ESMA) as Lead Overseers of critical ICT third-party providers
- Official name
- Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (Digital Operational Resilience Act)
- Citation
- OJ L 333, 27.12.2022, p. 1
- Topics
- cybersecurity, financial, breach-notification
Research notes
TLPT must be performed at least every three years by entities identified by their competent authority (Art 26). There is no single EU-wide first-test date; each authority notifies its entities. Registers of information are now collected annually; confirm each year's deadline with the national authority. The Digital Omnibus proposal COM(2025) 837 does not amend DORA in its title, but its single-entry point for incident reporting could interact with DORA reporting.
Related
Questions about DORA
- What are the DORA compliance deadlines?
- Jan 16, 2023: DORA enters into force. Jan 17, 2025: DORA applies. Apr 30, 2025: First registers of information submitted to the ESAs. Jul 8, 2025: TLPT regulatory technical standards enter into force. Nov 18, 2025: First critical ICT third-party providers designated.
- When does DORA take effect?
- DORA took effect on Jan 16, 2023.
- Who does DORA apply to?
- About 20 types of EU financial entities (credit institutions, payment and e-money institutions, investment firms, crypto-asset service providers, insurers, trading venues, CCPs and others) and ICT third-party service providers designated as critical. Microenterprises and some small entities get a simplified framework.
- What are the penalties under DORA?
- Administrative penalties for financial entities are set by Member States. Critical ICT third-party providers face periodic penalty payments of up to 1% of average daily worldwide turnover of the preceding business year, imposed daily for up to six months (Art 35(8)).