IT, data & continuous
Digital Operational Resilience Act (DORA)
DORA (Regulation (EU) 2022/2554) entered into force on 16 January 2023 and has applied since 17 January 2025 to more than twenty types of financial entities, including banks, insurers, investment firms and crypto-asset service providers. The regulation requires strong ICT risk management so that entities can withstand and recover from cyberattacks, IT failures and operational disruptions. Its elements include an ICT risk management framework, digital operational resilience testing, management of ICT third-party risk and the reporting of major ICT-related incidents, for which DORA sets strict deadlines.
Source: Verordening (EU) 2022/2554 (DORA)
Last updated: