DORA is live. Operational resilience is now a supervisory matter
The Digital Operational Resilience Act has applied since January 2025, and EU financial regulators are no longer asking whether your ICT risk is managed — they are asking you to prove it.
- Applies from
- 17 January 2025
- Who's in scope
- Banks, insurers, funds, payment firms + critical ICT providers
- Reach
- EU financial entities — including UK firms serving them
- Enforcement
- National competent authorities & the ESAs
The highlights
DORA consolidates ICT risk requirements for over 22,000 financial entities into a single, directly applicable regulation built on five pillars.
ICT risk managementPillar 1
A board-owned ICT risk framework covering identification, protection, detection, response and recovery. Management bodies carry personal accountability — resilience cannot be delegated to IT.
Incident reportingPillar 2
Major ICT incidents must be classified against harmonised criteria and reported to your competent authority — initial notification, intermediate report and final report on fixed timelines.
Resilience testingPillar 3
A proportionate testing programme for all in-scope entities, with threat-led penetration testing (TLPT) at least every three years for those designated significant.
Third-party riskPillar 4
A Register of Information covering every ICT contract, mandatory contractual provisions, concentration risk analysis and exit strategies. Critical providers fall under direct ESA oversight.
Information sharingPillar 5
A framework for exchanging cyber threat intelligence between financial entities — voluntary, but a clear signal of the collaborative posture supervisors expect.

Where to start
- Map your entity classification — confirm whether you are in scope, whether proportionality applies, and whether TLPT designation is likely.
- Build the Register of Information — most firms underestimate this. Every ICT third-party arrangement, catalogued in the ESA template, is the foundation of Pillar 4.
- Test your incident classification — run a tabletop against the DORA thresholds so the first time you classify a major incident isn't during one.
- Gap-assess against the RTS — the technical standards carry the detail — assess against them, not just the level-one text.
Regulated, and not sure you'd pass an inspection?
Sentinel42 delivers DORA gap assessments, Register of Information build-outs and board-level resilience programmes for financial entities and their ICT suppliers.