← Legislation library

European Union

DORA

The Digital Operational Resilience Act sets uniform requirements for the security of network and information systems across EU financial entities and their critical ICT third-party providers, covering ICT risk management, incident reporting, resilience testing, and supplier oversight.

13 articles

Article 5

Subject matter and scope

This Regulation lays down requirements for the digital operational resilience of financial entities and their critical ICT third-party service providers.

Article 6

Definitions

Key definitions including ICT risk, ICT service, digital operational resilience, and incident.

Article 9

ICT risk management framework

Financial entities shall have in place an effective and sound ICT risk management framework.

Article 10

ICT systems, protocols and tools

Financial entities shall use and maintain updated ICT systems, protocols and tools that are reliable, have sufficient capacity, and are technologically resilient.

Article 17

Detection

Financial entities shall have in place mechanisms to promptly detect anomalous activities, including ICT-related incidents.

Article 18

Response and recovery

Financial entities shall put in place a comprehensive ICT business continuity policy and ICT response and recovery plans.

Article 23

ICT-related incident management process

Financial entities shall put in place an ICT-related incident management process to detect, manage and notify ICT-related incidents.

Article 28

General principles for ICT third-party risk management

Financial entities shall manage ICT third-party risk as an integral element of their ICT risk management framework.

Article 29

Key ICT third-party service providers

Financial entities shall adopt a strategy on ICT third-party risk and exercise due diligence when assessing ICT third-party service providers.

Article 30

Preliminary assessment of ICT concentration risk

Financial entities shall assess the potential impact of ICT concentration risk on the continuous delivery of critical or important functions.

Article 34

Classification of major ICT-related incidents and significant cyber threats

Financial entities shall report major ICT-related incidents and significant cyber threats to the competent authorities.

Article 38

General requirements for digital operational resilience testing

Financial entities shall establish, maintain and review a digital operational resilience testing programme.

Article 44

Threat-led penetration testing

Financial entities identified by competent authorities shall carry out threat-led penetration testing on their critical or important functions at least every three years.

Turn DORA into tracked tasks

eurocompliant maps these obligations to checklists and evidence, so you can prove compliance instead of re-reading the text.

Start free trial