Regulatory primer

DORA

Regulation (EU) 2022/2554 — Digital Operational Resilience Act · European Union · In force; applicable from 17 January 2025

DORA is the EU's horizontal regulation of digital operational resilience for the financial sector. It requires financial entities to manage ICT risk, classify + report ICT-related incidents, test their resilience, and govern third-party ICT providers. It applies from 17 January 2025.

Updated 15 May 2026·Reading time ~ 7 min·Regulator-first explainer

What it is

DORA harmonises and tightens what was previously a patchwork of sectoral guidance (EBA + EIOPA + ESMA + national-supervisor expectations on outsourcing, cybersecurity, business continuity). It applies across banking, investment, insurance, payments, e-money, crypto-asset service providers, central securities depositories, trading venues, and selected other financial entities.

Five pillars: ICT risk management (Chapter II), ICT-related incident reporting (Chapter III), digital operational resilience testing (Chapter IV), management of third-party ICT risk (Chapter V), and information sharing (Chapter VI). Critical ICT third-party providers (CTPPs) — designated by the European Supervisory Authorities — face direct EU-level oversight.

Supervised at national level by the existing financial-sector supervisor (e.g. BaFin in Germany, ACPR in France, DNB in the Netherlands). The Joint Committee of the ESAs coordinates cross-border + CTPP supervision.

Who's in scope

  • Banks (credit institutions), payment institutions, electronic money institutions, account information service providers, central securities depositories.
  • Investment firms, fund managers, market makers, trading venues, central counterparties.
  • Insurance + reinsurance undertakings, IORPs, insurance intermediaries (above thresholds).
  • Crypto-asset service providers (under MiCA), credit-rating agencies, administrators of critical benchmarks.
  • ICT third-party service providers serving the above financial entities (governed through their financial-entity customers; CTPPs face direct oversight).
  • Some smaller entities benefit from proportionality (microenterprises, certain IORPs).

Key obligations

Art. 5 — ICT risk-management framework

Financial entity must adopt + maintain a documented ICT risk-management framework. The management body sets the framework, approves it, oversees ICT risk.

Art. 6-9 — ICT risk-management components

Identification + classification of ICT-supported business functions + information assets. Protection + prevention measures. Detection mechanisms. Response + recovery procedures.

Art. 17 — ICT-related incident management process

Documented process for ICT-related incident management. Early-warning indicators, monitoring + handling roles, post-incident reviews.

Art. 18 — incident classification

Classify ICT-related incidents by impact criteria — affected clients, data losses, duration, geographical spread, economic impact. The Joint Committee RTS (Reg. (EU) 2024/1772) standardises thresholds.

Art. 19 — major-incident notification

Major ICT incidents notified to competent authority: early warning within 24h, intermediate report within 72h, final report within 1 month of intermediate.

Art. 24-26 — digital operational resilience testing

Annual testing programme proportionate to size + risk profile. Includes vulnerability assessments, scenario-based testing, threat-led penetration testing (TLPT — Art. 26) every 3 years for designated entities.

Art. 28 — third-party ICT risk management

Strategy on ICT third-party risk including a register of contractual arrangements. Pre-contractual due diligence + ongoing monitoring of providers. Exit strategy + concentration-risk assessment.

Art. 30 — contractual provisions for ICT services

Mandatory contractual clauses for ICT services: clear service description, locations of processing, data-protection terms, business-continuity, access/inspection rights, exit clauses, sub-contracting controls.

Art. 31-44 — CTPP oversight

Critical ICT Third-Party Providers designated by the Joint Committee of ESAs face direct EU-level oversight (Lead Overseer). First CTPP designations expected through 2025-2026.

Timeline + applicability

  • 16 Jan 2023DORA entered into force.
  • 17 Jan 2025DORA became applicable. Financial entities must have full risk-management framework + register of ICT contractual arrangements.
  • 2025-2026First CTPP designations + first major-incident reports under the new templated process.

What's still being worked out

Areas where the regulation's interpretation is genuinely unsettled. Vendor pages skip this; we don't. Your counsel is the right venue for definitive guidance on your deployment.

  • Where 'ICT services' starts and 'pure SaaS / managed cloud' stops — the proportional regulatory treatment of standard cloud infrastructure vs critical financial-sector ICT.
  • Threshold for CTPP designation — substantive criteria are in Art. 31 but the Joint Committee's application discretion is being established.
  • How DORA's third-party-ICT register interacts with vendor concentration risk reporting under existing prudential regulation (CRR / Solvency II).
  • Interaction with NIS2 — financial entities under DORA are excluded from most NIS2 obligations (NIS2 lex specialis / DORA lex specialis rules) but the boundary is operationally complex.
  • How AI components within ICT services are governed — DORA doesn't distinguish AI, but AI Act + DORA concurrent obligations are emerging via practice + supervisor guidance.

Sectors most affected

Primary sources

Where Promethean fits

Promethean's L12 chain feeds DORA Art. 17-19 incident classification + notification when an AI component fails. Per-decision evidence (when did the AI misbehave, what was the impact volume, what was active spec + model) collapses the postmortem from a multi-week reconstruction to a chain-export query. For third-party ICT providers (Art. 28), the chain is the per-customer audit-trail evidence the financial-entity customer references in their register of contractual arrangements.

What Promethean does NOT solve

  • ICT risk-management framework design (Art. 5) — that's a board-level governance document.
  • TLPT testing (Art. 26) — that's specialist offensive-security work.
  • Business continuity + disaster recovery planning (Art. 11) — that's operations.
  • Contractual due diligence with ICT vendors (Art. 30) — that's procurement + legal.
  • ICT concentration-risk modelling — that's risk-function work.

FAQ

Does DORA apply to my fintech SMB?

If you hold a financial-sector authorisation (payment institution, e-money institution, investment firm, etc.) AND don't qualify for proportionality exemption, yes. Pre-licensed startups operating under a sponsor bank's umbrella inherit the bank's DORA obligations indirectly. Pure SaaS vendors serving financial entities are NOT directly regulated by DORA, but their financial-entity customers carry Art. 28 third-party-risk obligations that cascade.

What counts as a 'major incident' under Art. 19?

Defined by RTS (Reg. (EU) 2024/1772). Two-track classification: (1) significant impact criteria — affected clients, data loss, economic impact, duration, geographical spread, reputation — and (2) the entity's own thresholds. An incident is major when it meets either the significance criteria OR the entity's internal threshold AND has actually occurred. AI-component failures producing material customer-impact would generally cross.

How does DORA interact with NIS2?

Financial entities subject to DORA are largely excluded from NIS2 — DORA acts as lex specialis. But non-financial entities supplying ICT services to financial-sector customers may be NIS2-regulated separately (e.g. cloud providers, MSSPs). The DORA Art. 28 register-of-contractual-arrangements then sits alongside the NIS2 supplier-risk assessment for those vendors.

What's a CTPP and does my vendor need to worry?

Critical ICT Third-Party Provider — designated by the Joint Committee of ESAs under Art. 31. Criteria: systemic importance, substitutability, criticality of services, EU-wide scale. Designated CTPPs face direct EU-level oversight by a Lead Overseer (one of the ESAs). First designations are being made through 2025-2026. Most SaaS vendors won't be CTPPs; the large hyperscalers + major financial-infrastructure providers likely will be.

Can a chain-based audit trail satisfy DORA evidence requirements?

It can satisfy specific obligations within DORA — the per-decision evidence layer for AI components, the time-bounded incident reconstruction for Art. 19 notifications, the per-customer audit trail for Art. 28 third-party-risk register. It does NOT satisfy DORA in totality — DORA covers organisational governance, testing programmes, BCP/DR, and procurement processes that are operator-side. The chain is the AI-decisioning slice of the broader DORA compliance posture.