New signups are temporarily closed.Existing customers can still sign in. Contact us to be notified when we reopen.
Skip to main content
← Legislation library

European Union

DORA

The Digital Operational Resilience Act sets uniform requirements for the security of network and information systems across EU financial entities and their critical ICT third-party providers, covering ICT risk management, incident reporting, resilience testing, and supplier oversight.

13 articles

Article 5

Governance and organisation

Financial entities shall have in place an internal governance and control framework ensuring effective and prudent management of ICT risk, with the management body bearing ultimate responsibility and keeping up to date with sufficient ICT risk knowledge and skills.

Article 6

ICT risk management framework

Financial entities shall have a sound, comprehensive and well-documented ICT risk management framework, reviewed at least annually, subject to internal audit, and including a digital operational resilience strategy.

Article 9

Protection and prevention

Financial entities shall continuously monitor and control the security of ICT systems, minimise ICT risk impact, and implement documented information security, access, authentication, change-management and patching policies.

Article 10

Detection

Financial entities shall have in place mechanisms to promptly detect anomalous activities and ICT-related incidents, with multiple layers of control, alert thresholds, and sufficient resources devoted to monitoring.

Article 17

ICT-related incident management process

Financial entities shall define, establish and implement an ICT-related incident management process to detect, manage and notify ICT-related incidents, with early warning indicators, classification, escalation and communication procedures.

Article 18

Classification of ICT-related incidents and cyber threats

Financial entities shall classify ICT-related incidents and significant cyber threats using criteria including clients affected, duration, geographical spread, data losses, criticality and economic impact.

Article 23

Operational or security payment-related incidents concerning credit institutions, payment institutions, account information service providers, and electronic money institutions

The ICT-related incident management, classification and reporting requirements of this Chapter also apply to operational or security payment-related incidents affecting credit institutions, payment institutions, account information service providers, and electronic money institutions.

Article 28

General principles

Financial entities shall manage ICT third-party risk as an integral component of ICT risk, remain fully responsible for compliance regardless of outsourcing, adopt a strategy and register of ICT third-party arrangements, conduct due diligence, and put in place exit strategies for critical or important functions.

Article 29

Preliminary assessment of ICT concentration risk at entity level

When assessing ICT third-party risk, financial entities must also consider whether a contractual arrangement would create dependence on a non-substitutable provider or overlapping arrangements with closely connected providers, weighing costs and risks of alternative solutions and subcontracting.

Article 30

Key contractual provisions

Contractual arrangements on the use of ICT services must be documented in a single written document and include specified minimum elements (service description, data locations, security, termination rights); arrangements supporting critical or important functions require additional elements including monitoring, audit rights, and exit strategies.

Article 34

Operational coordination between Lead Overseers

The three Lead Overseers of critical ICT third-party service providers shall set up a joint oversight network to coordinate oversight activities, drawing up a common oversight protocol and able to call on the ECB and ENISA for technical advice.

Article 38

General investigations

The Lead Overseer may conduct investigations of critical ICT third-party service providers, with powers to examine records, obtain copies, summon representatives, interview persons, and request telephone and data traffic records, subject to written authorisation.

Article 44

International cooperation

EBA, ESMA and EIOPA may conclude administrative arrangements with third-country regulatory and supervisory authorities to foster international cooperation on ICT third-party risk, reporting jointly to the European Parliament, Council and Commission every five years.

Turn DORA into tracked tasks

eurocompliant maps these obligations to checklists and evidence, so you can prove compliance instead of re-reading the text.

Start free trial