European Union
DORA
The Digital Operational Resilience Act sets uniform requirements for the security of network and information systems across EU financial entities and their critical ICT third-party providers, covering ICT risk management, incident reporting, resilience testing, and supplier oversight.
13 articles
Governance and organisation
Financial entities shall have in place an internal governance and control framework ensuring effective and prudent management of ICT risk, with the management body bearing ultimate responsibility and keeping up to date with sufficient ICT risk knowledge and skills.
ICT risk management framework
Financial entities shall have a sound, comprehensive and well-documented ICT risk management framework, reviewed at least annually, subject to internal audit, and including a digital operational resilience strategy.
Protection and prevention
Financial entities shall continuously monitor and control the security of ICT systems, minimise ICT risk impact, and implement documented information security, access, authentication, change-management and patching policies.
Detection
Financial entities shall have in place mechanisms to promptly detect anomalous activities and ICT-related incidents, with multiple layers of control, alert thresholds, and sufficient resources devoted to monitoring.
ICT-related incident management process
Financial entities shall define, establish and implement an ICT-related incident management process to detect, manage and notify ICT-related incidents, with early warning indicators, classification, escalation and communication procedures.
Classification of ICT-related incidents and cyber threats
Financial entities shall classify ICT-related incidents and significant cyber threats using criteria including clients affected, duration, geographical spread, data losses, criticality and economic impact.
Operational or security payment-related incidents concerning credit institutions, payment institutions, account information service providers, and electronic money institutions
The ICT-related incident management, classification and reporting requirements of this Chapter also apply to operational or security payment-related incidents affecting credit institutions, payment institutions, account information service providers, and electronic money institutions.
General principles
Financial entities shall manage ICT third-party risk as an integral component of ICT risk, remain fully responsible for compliance regardless of outsourcing, adopt a strategy and register of ICT third-party arrangements, conduct due diligence, and put in place exit strategies for critical or important functions.
Preliminary assessment of ICT concentration risk at entity level
When assessing ICT third-party risk, financial entities must also consider whether a contractual arrangement would create dependence on a non-substitutable provider or overlapping arrangements with closely connected providers, weighing costs and risks of alternative solutions and subcontracting.
Key contractual provisions
Contractual arrangements on the use of ICT services must be documented in a single written document and include specified minimum elements (service description, data locations, security, termination rights); arrangements supporting critical or important functions require additional elements including monitoring, audit rights, and exit strategies.
Operational coordination between Lead Overseers
The three Lead Overseers of critical ICT third-party service providers shall set up a joint oversight network to coordinate oversight activities, drawing up a common oversight protocol and able to call on the ECB and ENISA for technical advice.
General investigations
The Lead Overseer may conduct investigations of critical ICT third-party service providers, with powers to examine records, obtain copies, summon representatives, interview persons, and request telephone and data traffic records, subject to written authorisation.
International cooperation
EBA, ESMA and EIOPA may conclude administrative arrangements with third-country regulatory and supervisory authorities to foster international cooperation on ICT third-party risk, reporting jointly to the European Parliament, Council and Commission every five years.
Turn DORA into tracked tasks
eurocompliant maps these obligations to checklists and evidence, so you can prove compliance instead of re-reading the text.
Start free trial