The Digital Operational Resilience Act, or DORA, is a European Union (EU) regulation that creates a binding, comprehensive information and communication technology (ICT) risk management framework for the EU financial sector.
DORA establishes technical standards that financial entities and their critical third-party technology service providers. It first entered into effect on 17 January 2025.
Stay up to date on the most important—and intriguing—industry trends on AI, automation, data and beyond with the Think newsletter. See the IBM Privacy Statement.
DORA has two main objectives: to comprehensively address ICT risk management in the financial services sector and to harmonize the ICT risk management regulations that already exist in individual EU member states.
Before DORA, risk management regulations for financial institutions in the EU primarily focused on ensuring that firms had enough capital to cover operational risks. While some EU regulators released guidelines on ICT and security risk management, these guidelines didn't apply to all financial entities equally, and they often relied on general principles rather than specific technical standards. In the absence of EU-level ICT risk management rules, EU member states issued their own requirements. This patchwork of regulations has proven difficult for financial entities to navigate.
With DORA, the EU aims to establish a universal framework for managing and mitigating ICT risk in the financial sector. By harmonizing risk management rules across the EU, DORA seeks to remove the gaps, overlaps and conflicts that could arise between disparate regulations in different EU states. A shared set of rules can make it easier for financial entities to comply while improving the entire EU financial system's resilience by ensuring that every institution is held to the same standard.
DORA applies to all financial institutions in the EU. That includes traditional financial entities, such as banks, investment firms and credit institutions, and non-traditional entities, including crypto-asset service providers and crowdfunding platforms.
Notably, DORA also applies to some entities typically excluded from financial regulations. For example, third-party service providers that supply financial firms with ICT systems and services—like cloud service providers and data centers—must follow DORA requirements. DORA also covers firms that provide critical third-party information services, such as credit rating services and data analytics providers.
This focus on third-party service providers means that even firms located outside of Europe can be responsible for regulatory compliance. For instance, many firms in India provide IT and business process outsourcing services to European clients; these Indian firms must pay attention to DORA’s regulatory requirements to remain compliant. Among other requirements, these firms must demonstrate strong cyber resilience and business continuity measures.
DORA is currently in effect and enforceable as of 17 January 2025, after years of development.
DORA was first proposed by the European Commission—the executive branch of the EU responsible for introducing legislation—in September 2020. It was part of a larger digital financial package that also includes initiatives for regulating crypto-assets and enhancing the EU’s overall digital finance strategy. The Council of the European Union and the European Parliament (the legislative bodies responsible for approving EU laws) formally adopted the DORA in November 2022.
Following adoption of the act, key details were ironed out by the European Supervisory Authorities (ESAs). The ESAs are the regulators that oversee the EU financial system, including The European Banking Authority (EBA), the European Securities and Markets Authority and the European Insurance and Occupational Pensions Authority.
The ESAs were in charge of drafting the regulatory technical standards (RTS) and implementing technical standards (ITS) that covered entities must implement. Many of these standards were finalized in 2024. For example, in March of 2024, regulators delivered regulatory technical standards specifying ICT risk management tools, methods, processes and policies. They also specified the criteria for the classification of major ICT-related incidents and cyber threats. Also in 2024, the European Commission began developing an oversight framework for critical ICT providers.
The DORA framework is considered complete as of July 2025.
Enforcement now falls to designated regulators in each EU member state, known as “competent authorities.” The competent authorities can request that financial entities take specific security measures and remediate vulnerabilities. They can also impose administrative—and, in some cases, criminal—penalties on entities that fail to comply. Each member state decides on its own penalties.
ICT providers deemed “critical” by the European Commission will be directly supervised by lead overseers from the ESAs. In November of 2025, regulars named 19 firms as “critical,” a list that included Amazon, Google and IBM.
Like competent authorities, lead overseers can request security measures and remediation and penalize noncompliant ICT providers. DORA allows lead overseers to levy fines on ICT providers amounting to 1% of the provider’s average daily worldwide turnover in the previous business year. Providers can be fined every day for up to six months until they achieve compliance.
DORA establishes technical requirements for financial entities and ICT providers across four domains:
Information sharing is encouraged but not required.
Requirements are expected to be enforced proportionately, which means smaller entities will not be held to the same standards as major financial institutions. Though major enforcement operations did not yet grab headlines in 2025, some legal experts cite 2026 as the year DORA enters a maturity phase. “Boards should be prepared for a new cadence of supervisory engagement focused on operational resilience rather than traditional prudential metrics,” writes Michael Huertas, the global and European Financial Services Legal Leader at PwC Legal.
The DORA makes an entity’s management body responsible for ICT management. Board members, executive leaders and other senior managers are expected to define appropriate risk management strategies, actively assist in executing them, and stay current on their knowledge of the ICT risk landscape. Leaders can also be held personally accountable for an entity’s failure to comply.
Covered entities are expected to develop comprehensive ICT risk management frameworks. Entities must map their ICT systems, identify and classify critical assets and functions, and document dependencies between assets, systems, processes and providers. Entities must conduct continuous risk assessments on their ICT systems, document and classify cyberthreats, and document their steps to mitigate identified risks.
As part of the risk assessment process, entities must conduct business impact analyses to assess how specific scenarios and severe disruptions might affect the business. Entities use the results of these analyses to set levels of risk tolerance and inform the design of their ICT infrastructure. Entities are also be required to implement suitable cybersecurity protection measures, such as policies for identity and access management (IAM) and patch management, along with technical controls such as extended detection and response systems, security information and event management (SIEM) software and security orchestration, automation and response (SOAR) tools.
Entities also need to establish business continuity and disaster recovery plans for various cyber risk scenarios, such as ICT service failures, natural disasters and cyberattacks. These plans must include data backup and recovery measures, system restoration processes and plans for communicating with affected clients, partners and the authorities.
Covered entities must establish systems for monitoring, managing, logging, classifying and reporting ICT-related incidents. Depending on the severity of the incident, entities may need to make reports to both regulators and affected clients and partners.
Entities are required to file three different kinds of reports for critical incidents: an initial report notifying authorities, an intermediate report on progress toward resolving the incident and a final report analyzing the root causes of the incident.
The rules on incident management, how incidents should be classified, which incidents must be reported and timelines for reporting were published in March 2024.
ESAs have also explored ways to streamline reporting by establishing a central, EU-wide reporting hub and common report templates. In January 2025, the ESAs issued the “Report on the feasibility for further centralisation of reporting of major ICT-related incidents.” The report concludes that a “single EU Hub scenario is feasible and brings certain benefits,” but such a hub would require at least five years to roll out. For now, reporting solutions exist at the national level.
Entities must test their ICT systems regularly to evaluate the strength of their protections and identify vulnerabilities. The results of these tests, and plans for addressing any weaknesses they find, will be reported to and validated by the relevant competent authorities.
Entities must carry out basic tests, like vulnerability assessments and scenario-based testing, once a year. Financial entities judged to play a critical role in the financial system will also need to undergo threat-led penetration testing (TLPT) every three years. The entity’s critical ICT providers will be required to participate in these penetration tests as well. Technical standards on how TLPTs should be carried out appeared in the EU’s official journal on 18 June 2025 and entered into effect 20 days later.
One unique aspect of DORA is that it applies not only to financial entities but also to the ICT providers that service the financial sector.
Financial firms are expected to take an active role in managing ICT third-party risk risk assessment and management. When outsourcing critical and important functions, financial entities must negotiate specific contractual arrangements regarding exit strategies, audits and performance targets for accessibility, integrity and security, among other things. Entities are not allowed to contract with ICT providers who cannot meet these requirements. The competent authorities are empowered to suspend or terminate contracts that don’t comply.
Financial institutions also need to map their third-party ICT dependencies and are required to ensure their critical and important functions are not too heavily concentrated with a single provider or small group of providers.
Critical ICT third-party service providers will be subject to direct oversight from relevant ESAs. As mentioned, 19 firms currently meet those standards and will have one of the ESAs assigned as a lead overseer. In addition to enforcing DORA requirements on critical providers, lead overseers are empowered to forbid providers from entering into contracts with financial firms or other ICT providers that don’t comply with DORA.
Financial entities must establish processes for learning from both internal and external ICT-related incidents. Toward that end, the DORA encourages entities to participate in voluntary threat intelligence sharing arrangements. Any information shared this way must still be protected under the relevant guidelines—for instance, personally identifiable information is still subject to General Data Protection Regulation considerations.
Flash storage with built‑in, AI‑driven protection and immutable snapshots to defend against cyberattacks and enable fast recovery.
Protect and safeguard your data against failures, cyberattacks, and disasters with AI‑powered threat detection, immutable snapshots, and enterprise‑grade storage resilience.
AI-powered detection, monitoring, and rapid response to protect IT, OT, and hybrid-cloud environments.