Skip to content

DORA

In force European Union · In force Jan 16, 2023 · no upcoming deadlines

Deadlines

DateWhat happens
Jan 16, 2023DORA enters into force3.7 years ago
Jan 17, 2025DORA applies20 months ago
Apr 30, 2025First registers of information submitted to the ESAs17 months ago
Jul 8, 2025TLPT regulatory technical standards enter into force15 months ago
Nov 18, 2025First critical ICT third-party providers designated10 months ago

Summaries for reference, not legal advice. Check the official text.

What it does

Harmonised ICT risk-management, major ICT-incident reporting, digital operational resilience testing (including threat-led penetration testing) and ICT third-party risk rules for EU financial entities. Financial entities must keep a register of all ICT third-party contracts. Critical ICT third-party providers (cloud, data centres and similar) come under direct EU oversight.

Who it applies to
About 20 types of EU financial entities (credit institutions, payment and e-money institutions, investment firms, crypto-asset service providers, insurers, trading venues, CCPs and others) and ICT third-party service providers designated as critical. Microenterprises and some small entities get a simplified framework.
Penalties
Administrative penalties for financial entities are set by Member States. Critical ICT third-party providers face periodic penalty payments of up to 1% of average daily worldwide turnover of the preceding business year, imposed daily for up to six months (Art 35(8)).
Enforced by
National competent authorities for financial supervision; the European Supervisory Authorities (EBA, EIOPA, ESMA) as Lead Overseers of critical ICT third-party providers
Official name
Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (Digital Operational Resilience Act)
Citation
OJ L 333, 27.12.2022, p. 1
Topics
cybersecurity, financial, breach-notification
Verified 2026-09-22 eba.europa.eu eba.europa.eu eur-lex.europa.eu
Research notes

TLPT must be performed at least every three years by entities identified by their competent authority (Art 26). There is no single EU-wide first-test date; each authority notifies its entities. Registers of information are now collected annually; confirm each year's deadline with the national authority. The Digital Omnibus proposal COM(2025) 837 does not amend DORA in its title, but its single-entry point for incident reporting could interact with DORA reporting.

Related

Questions about DORA
What are the DORA compliance deadlines?
Jan 16, 2023: DORA enters into force. Jan 17, 2025: DORA applies. Apr 30, 2025: First registers of information submitted to the ESAs. Jul 8, 2025: TLPT regulatory technical standards enter into force. Nov 18, 2025: First critical ICT third-party providers designated.
When does DORA take effect?
DORA took effect on Jan 16, 2023.
Who does DORA apply to?
About 20 types of EU financial entities (credit institutions, payment and e-money institutions, investment firms, crypto-asset service providers, insurers, trading venues, CCPs and others) and ICT third-party service providers designated as critical. Microenterprises and some small entities get a simplified framework.
What are the penalties under DORA?
Administrative penalties for financial entities are set by Member States. Critical ICT third-party providers face periodic penalty payments of up to 1% of average daily worldwide turnover of the preceding business year, imposed daily for up to six months (Art 35(8)).

When the rules change: new data, privacy and AI laws and deadlines, the next morning.