EU Regulation 2022/2554

DORA is live. Operational resilience is now a supervisory matter

The Digital Operational Resilience Act has applied since January 2025, and EU financial regulators are no longer asking whether your ICT risk is managed — they are asking you to prove it.

Applies from
17 January 2025
Who's in scope
Banks, insurers, funds, payment firms + critical ICT providers
Reach
EU financial entities — including UK firms serving them
Enforcement
National competent authorities & the ESAs

The highlights

DORA consolidates ICT risk requirements for over 22,000 financial entities into a single, directly applicable regulation built on five pillars.

ICT risk managementPillar 1

A board-owned ICT risk framework covering identification, protection, detection, response and recovery. Management bodies carry personal accountability — resilience cannot be delegated to IT.

Incident reportingPillar 2

Major ICT incidents must be classified against harmonised criteria and reported to your competent authority — initial notification, intermediate report and final report on fixed timelines.

Resilience testingPillar 3

A proportionate testing programme for all in-scope entities, with threat-led penetration testing (TLPT) at least every three years for those designated significant.

Third-party riskPillar 4

A Register of Information covering every ICT contract, mandatory contractual provisions, concentration risk analysis and exit strategies. Critical providers fall under direct ESA oversight.

Information sharingPillar 5

A framework for exchanging cyber threat intelligence between financial entities — voluntary, but a clear signal of the collaborative posture supervisors expect.

Sentinel42 compliance dashboard showing overall compliance score, open incidents, risk levels and a twelve-month compliance trend
The Sentinel42 dashboard — compliance score, open incidents, risk levels and trend at a glance. Illustrative representation of the interface; figures shown are examples, not real customer data.

Where to start

  • Map your entity classification — confirm whether you are in scope, whether proportionality applies, and whether TLPT designation is likely.
  • Build the Register of Information — most firms underestimate this. Every ICT third-party arrangement, catalogued in the ESA template, is the foundation of Pillar 4.
  • Test your incident classification — run a tabletop against the DORA thresholds so the first time you classify a major incident isn't during one.
  • Gap-assess against the RTS — the technical standards carry the detail — assess against them, not just the level-one text.

Regulated, and not sure you'd pass an inspection?

Sentinel42 delivers DORA gap assessments, Register of Information build-outs and board-level resilience programmes for financial entities and their ICT suppliers.