Regulation (EU) 2022/2554, known as DORA (Digital Operational Resilience Act), is the European law that harmonises how financial entities and their ICT service providers must manage technology risk. It applies from 17 January 2025 and, being a regulation, is directly applicable without national transposition. This guide summarises the essentials so you can tell whether it affects you and what you need to demonstrate.
Guidance prepared by Jaquers Ciberseguridad from the Regulation and its technical standards. It is not legal advice: specific deadlines and thresholds depend on the type of entity and the technical standards in force, which you should verify with your legal advisers and your supervisor.
1. Who DORA applies to
DORA covers around twenty types of financial entities: credit institutions, payment and electronic money institutions, investment firms, crypto-asset service providers, fund managers, insurance and reinsurance undertakings and intermediaries, occupational pension funds, credit rating agencies, data reporting service providers, crowdfunding platforms and central counterparties, among others.
It also reaches the third-party ICT service providers that work for them (cloud, software, data centres, managed security services, data analytics), indirectly through their customers’ contractual requirements and, for providers designated as critical by the European Supervisory Authorities, through direct oversight. The Regulation applies the principle of proportionality: smaller entities have a simplified framework.
2. The five pillars
A framework approved and overseen by the management body, which identifies assets and dependencies, protects and prevents, detects anomalies, responds and recovers, and learns from every incident and every test. Management is personally accountable for its implementation.
A process to detect, manage and log all incidents, classify them using the common European criteria and report major ones to the supervisor within the deadlines in the next section.
An annual testing programme (vulnerability assessments, penetration tests, configuration reviews, scenario tests) and, for the entities the supervisor designates, threat-led penetration testing (TLPT) every three years.
A register of information covering all contractual arrangements with ICT providers, minimum contractual clauses, assessment of concentration risk and exit strategies for critical or important functions.
Voluntary arrangements between entities to share threat intelligence, indicators of compromise and tactics within trusted communities.
3. Major incident reporting: 4 hours, 72 hours and one month
ICT-related incidents are classified using common criteria (clients affected, duration, geographical spread, data losses, criticality of services and economic impact). Those classified as major must be reported to the competent authority in three stages:
| Deadline | What must be sent |
|---|---|
| 4 hours from classifying the incident as major and, in any case, within 24 hours of becoming aware of it | Initial notification: what happened, services and clients affected, whether other Member States are affected and whether the continuity plan has been activated. |
| 72 hours from the initial notification | Intermediate report: situation update, changes in classification, measures taken and a provisional impact assessment. |
| One month from the intermediate report | Final report: root cause, actual impact, mitigation measures and lessons learned. |
Besides notifications to the supervisor, affected clients must be informed when the incident affects their financial interests and, if personal data is involved, the GDPR must be complied with in parallel. Significant cyber threats may be reported voluntarily.
4. Resilience testing and TLPT
All entities (except microenterprises) must maintain a proportionate testing programme, documented and performed by independent parties, with a procedure to prioritise and fix what is found. Entities the supervisor identifies as systemically important must carry out, at least every three years, threat-led penetration testing (TLPT) following the TIBER-EU framework: entity-specific threat intelligence, simulation of a real attacker against live production systems supporting critical functions, a red team with proven experience and the involvement of the ICT providers concerned.
In practice this turns one-off pentesting into a continuous obligation: every test must be documented, every finding tracked to its fix and every fix verified.
5. Third-party ICT service providers
DORA requires financial entities to keep a register of information covering all their ICT contractual arrangements, distinguishing those supporting critical or important functions, available to the supervisor on request. Contracts must include, as a minimum, a description of the services and their location, service levels, incident notification obligations, audit and access rights, cooperation with authorities and a realistic exit strategy. If you are a provider to a financial entity, be ready to answer detailed questionnaires, accept these clauses and demonstrate your own security testing.
6. Readiness checklist
And which regime (full or simplified) applies to us.
With periodic review, an allocated budget and training for its members.
And we have rehearsed the procedure with a drill.
With findings tracked to their fix and evidence retained.
And, if so, the three-year cycle is planned.
With critical or important functions identified and the minimum clauses in the contracts.
Tested, not just written down.
7. How Jaquers helps
Our services fit the resilience testing pillar and incident management: tests performed by an independent team, with reproducible evidence, every finding tracked to its fix and a documented retest, all exportable for the supervisor and for your customers’ questionnaires.
If you want to know where your organisation stands on DORA, request an initial assessment: a 30-minute conversation to understand your systems and what worries you.