Skip to Primary Navigation

EU DORA

The Digital Operational Resilience Act (DORA for short) is intended to strengthen the IT security frameworks of financial entities and ensure that they remain resilient in the face of cybersecurity threats and in the event of severe operational disruption.

Rule Overview

Jurisdiction: European Union

Regulator: ESMA

Topic: Resilience

EUR-Lex (EU) 2022/2054
Overview
Latest News
Further Reading

DORA rules cover:

  • ICT risk management
  • ICT third-party risk management
  • Digital operational resilience testing
  • ICT-related incidents
  • Information sharing on cyber threats
  • Oversight of critical third-party providers

DORA has applied to all relevant financial entities and third parties since 17 January 2025.

Latest News

View More News

Further Reading