Regulation (EU) 2022/2554, the Digital Operational Resilience Act, has applied since 17 January 2025. Article 1(1)(a) lists what it requires of financial entities: ICT risk management, reporting of major ICT-related incidents and voluntary notification of significant cyber threats, digital operational resilience testing, information and intelligence sharing on cyber threats, and measures for the sound management of ICT third-party risk. Those five sets of requirements are Chapters II to VI of the Regulation, Articles 5 to 45, and they are the whole of what a supervisor assesses you against.
Two things shape every programme built on them. The requirements are not equal in weight: Chapter II on ICT risk management runs to twelve articles and Chapter V on third-party risk to seventeen, while information sharing is a single permissive article. And the duties are graded by entity: Article 16 replaces Articles 5 to 15 with a simplified framework for a defined list of smaller entities, and microenterprises are exempted from several specific obligations article by article.
| Fact | Detail |
|---|---|
| Legal basis | Regulation (EU) 2022/2554 of 14 December 2022, directly applicable in every Member State. Article 64 sets application from 17 January 2025. |
| Who it binds | The twenty types of financial entity listed in Article 2(1), points (a) to (t), from credit institutions to securitisation repositories, plus ICT third-party service providers under point (u). |
| The five requirement sets | ICT risk management (Articles 5 to 16), incident management, classification and reporting (17 to 23), resilience testing (24 to 27), ICT third-party risk (28 to 44) and information sharing (45). |
| Lighter regimes | Article 16 for small and non-interconnected investment firms, exempted payment and electronic money institutions and small IORPs. Microenterprises, fewer than 10 persons and up to EUR 2 million turnover or balance sheet under Article 3(60), are carved out of specific duties. |
| The reporting clocks | Delegated Regulation (EU) 2025/301, Article 5: initial notification within 4 hours of classifying an incident as major and no later than 24 hours from awareness, intermediate report within 72 hours, final report within one month. |
| Enforcement | Article 50 gives competent authorities supervisory, investigatory and sanctioning powers; Member States lay down the penalties. DORA fixes no EU-wide fine ceiling. |
Who has to comply with DORA?
Article 2(1) lists twenty types of financial entity: credit institutions, payment institutions including those exempted under the second Payment Services Directive, account information service providers, electronic money institutions including exempted ones, investment firms, crypto-asset service providers and issuers of asset-referenced tokens, central securities depositories, central counterparties, trading venues, trade repositories, managers of alternative investment funds, management companies, data reporting service providers, insurance and reinsurance undertakings, insurance and reinsurance intermediaries, institutions for occupational retirement provision, credit rating agencies, administrators of critical benchmarks, crowdfunding service providers and securitisation repositories. Article 2(2) calls that group financial entities. Point (u) adds ICT third-party service providers, who carry the oversight provisions of Chapter V rather than the entity duties.
Article 2(3) then removes six groups: alternative investment fund managers below the thresholds in Article 3(2) of the AIFM Directive, insurers and reinsurers below the size thresholds in Article 4 of Solvency II, occupational pension schemes with no more than 15 members in total, persons exempted under Articles 2 and 3 of MiFID II, insurance intermediaries that are microenterprises or small or medium-sized enterprises, and post office giro institutions. Article 2(4) lets a Member State exclude certain institutions listed in the Capital Requirements Directive from its own territory. Whether you are in scope is settled by those two paragraphs, and our guide to how DORA and NIS2 differ explains why a financial entity under DORA is treated as covered by a sector-specific act for NIS2 purposes under Article 1(2).
What does the ICT risk management framework have to contain?
Chapter II starts with the management body, not the framework. Article 5(2) makes the management body define, approve, oversee and be responsible for every arrangement in the framework, and lists what that means: bearing ultimate responsibility for ICT risk, setting roles for all ICT-related functions, approving the digital operational resilience strategy and the ICT risk tolerance level, approving and reviewing the ICT business continuity policy and the response and recovery plans, approving the ICT internal audit plans, allocating and reviewing the budget for digital operational resilience including training, and approving the policy on the use of ICT third-party services. Each of those is a dated decision a supervisor can ask to see.
Article 6(1) then requires a sound, comprehensive and well-documented ICT risk management framework as part of the overall risk management system. Article 6(4) requires financial entities other than microenterprises to assign ICT risk oversight to a control function with appropriate independence, and to segregate ICT risk management, control and internal audit according to the three lines of defence or an equivalent model. Article 6(5) requires the framework to be documented and reviewed at least once a year, and additionally after major ICT-related incidents and following supervisory instructions or the conclusions of testing or audit. Article 6(6) subjects it to internal audit on a regular basis, and Article 6(7) requires a formal follow-up process for critical audit findings. Article 6(8) requires the framework to include a digital operational resilience strategy that sets the risk tolerance level, information security objectives with key performance indicators and key risk metrics, and the ICT reference architecture.
Articles 7 to 14 supply the working parts: ICT systems and tools kept reliable and up to date, identification of all business functions and the ICT assets supporting them, protection and prevention under Article 9, detection mechanisms under Article 10 that are regularly tested, an ICT business continuity policy under Article 11, backup and restoration under Article 12, learning and evolving under Article 13 including post-incident reviews after a major incident, and crisis communication plans under Article 14. Our guides to writing a DORA ICT risk management framework and to DORA key risk indicators work through those articles one at a time.
Which entities get the simplified framework?
Article 16(1) disapplies Articles 5 to 15 for small and non-interconnected investment firms, payment institutions exempted under the Payment Services Directive, institutions exempted under the Capital Requirements Directive where the Member State has not used the Article 2(4) option, electronic money institutions exempted under the E-Money Directive, and small institutions for occupational retirement provision. Those entities still have to put in place and maintain a sound and documented ICT risk management framework, continuously monitor the security and functioning of all ICT systems, minimise the impact of ICT risk through resilient and updated systems, and identify and manage ICT risk to their business functions. The framework is lighter; the duty to have one is not removed.

How must ICT-related incidents be managed and reported?
Article 17 requires an ICT-related incident management process that detects, manages and notifies incidents, and requires every ICT-related incident and significant cyber threat to be recorded, with root causes identified, documented and addressed. Article 18 requires incidents to be classified on set criteria: the number and relevance of clients or financial counterparts affected, the duration including service downtime, the geographical spread, the data losses, the criticality of the services affected and the economic impact. The thresholds that turn those criteria into a major incident are in a separate delegated regulation, and our guide to DORA major incident classification walks through them.
Article 19(1) requires major ICT-related incidents to be reported to the relevant competent authority, and Article 19(4) fixes the three documents: an initial notification, an intermediate report once the status has changed significantly or on request, and a final report when the root cause analysis is complete. The time limits are set by Article 5 of Delegated Regulation (EU) 2025/301. The initial notification is due as early as possible and in any case within four hours of classifying the incident as major, and no later than 24 hours from the moment the entity became aware of it. The intermediate report is due within 72 hours of the initial notification, even where nothing has changed. The final report is due no later than one month after the intermediate report or its latest update. Where a deadline falls on a weekend or a bank holiday, Article 5(4) allows submission by noon of the next working day, but Article 5(5) withholds that relief from credit institutions, central counterparties, trading venues and entities identified as essential or important under NIS2.
Article 19(2) makes notification of significant cyber threats voluntary. Article 19(5) lets the reporting be outsourced, with the entity remaining fully responsible. Our comparison of incident reporting deadlines by regulation places the DORA clocks next to the GDPR, NIS2, AI Act and CRA ones.
What testing does DORA require?
Article 24(1) requires financial entities other than microenterprises to establish, maintain and review a sound and comprehensive digital operational resilience testing programme as an integral part of the ICT risk management framework. Article 24(4) requires tests to be undertaken by independent parties, internal or external, with sufficient resources and no conflicts of interest where the tester is internal. Article 24(5) requires procedures to prioritise, classify and remedy every issue the tests reveal. Article 24(6) sets the floor: at least yearly, appropriate tests on all ICT systems and applications supporting critical or important functions.
Article 25 lists what the programme draws on: vulnerability assessments and scans, open source analyses, network security assessments, gap analyses, physical security reviews, questionnaires and scanning software, source code reviews where feasible, scenario-based tests, compatibility testing, performance testing, end-to-end testing and penetration testing. Article 26 adds threat-led penetration testing at least every three years for the entities their competent authority identifies, performed on live production systems supporting several or all critical or important functions. Our guides to the annual testing programme the board must approve and to DORA threat-led penetration testing cover the two halves.
What does DORA require for ICT third-party providers?
Article 28(1) makes ICT third-party risk an integral component of ICT risk within the Article 6 framework, and makes the financial entity remain fully responsible at all times for its obligations whatever it has outsourced. Article 28(2) requires entities other than Article 16 entities and microenterprises to adopt and regularly review a strategy on ICT third-party risk, including a policy on ICT services supporting critical or important functions. Article 28(3) is the requirement most programmes underestimate: a register of information covering all contractual arrangements on the use of ICT services, maintained at entity, sub-consolidated and consolidated levels, distinguishing arrangements that support critical or important functions from those that do not, reported at least yearly to the competent authority, and produced in full on request. The same paragraph requires the authority to be told in a timely manner about any planned arrangement supporting a critical or important function.
Article 28(8) requires exit strategies for ICT services supporting critical or important functions. Article 30 fixes the contractual provisions: the rights and obligations of both parties set out in writing, in one document that includes the service level agreements. Articles 31 onward set up the oversight framework under which the European Supervisory Authorities designate critical ICT third-party service providers and appoint a Lead Overseer for each. Our guides to the register of information templates and to building a compliant vendor register cover the contract clauses and the filing.

Is information sharing mandatory?
No. Article 45(1) says financial entities may exchange cyber threat information and intelligence among themselves, including indicators of compromise, tactics, techniques and procedures, alerts and configuration tools, where the sharing aims to enhance digital operational resilience and is conducted within trusted communities under arrangements that protect the information. It is the one chapter written in the permissive mood. Article 45(3) adds the one hard duty: an entity that joins such an arrangement must notify its competent authority once its membership is validated, and again when it leaves. Beyond that, what a supervisor can expect is a documented decision about whether and how you participate.
How is DORA enforced?
Article 50(1) requires competent authorities to have all the supervisory, investigatory and sanctioning powers necessary for their duties under the Regulation, and Article 50(2) lists the minimum: access to any document or data the authority considers relevant, and on-site inspections and investigations including summoning representatives for oral or written explanations. Article 50(3) requires Member States to lay down rules establishing appropriate administrative penalties and remedial measures, effective, proportionate and dissuasive, and Article 50(4) requires them to confer at least the power to order a breach to cease and to require the temporary or permanent cessation of a practice. Article 51 has those powers exercised in accordance with national legal frameworks. The Regulation sets no EU-wide fine ceiling of its own; the penalties are national. What it does fix is the evidence a supervisor can demand, which is why our guide to what to expect from a DORA audit reads Article 50 alongside the internal audit Article 6(6) makes you run.
What the other results get wrong
The first error is presenting the five pillars as five projects of equal size. Chapter V alone runs from Article 28 to Article 44, and the register of information under Article 28(3) is a structured annual filing with its own implementing regulation. Article 45 is a single article whose first paragraph begins with the word may. A plan that budgets them equally has misread the Regulation.
The second is quoting 72 hours as the first reporting deadline. That figure is the intermediate report. The initial notification is due within four hours of classifying an incident as major and no later than 24 hours from awareness, which is a different operational problem: the clock starts with a classification decision that has to be made out of hours.
The third is treating every duty as applying to every entity in the same form. Article 16 replaces Articles 5 to 15 for a defined list of smaller entities, and microenterprises are excluded from the control function requirement in Article 6(4), the internal audit in Article 6(6), the testing programme in Article 24 and the third-party strategy in Article 28(2), among others. Reading the Regulation without the carve-outs overstates the work for a small payment institution and understates the judgement a larger one has to document.
Where do you stand?
Fill this in from your own records. A blank row is a finding waiting for a supervisor to make it.
| Question | Your answer | Article |
|---|---|---|
| Which of the twenty Article 2(1) entity types are you, and does Article 16 apply? | Art. 2(1), Art. 16(1) | |
| When did the management body last approve the digital operational resilience strategy and the ICT risk tolerance level? | Art. 5(2)(d), Art. 6(8) | |
| When was the ICT risk management framework last reviewed, and where is the report? | Art. 6(5) | |
| Who decides, out of hours, whether an incident is major, and can the initial notification go out within four hours? | Art. 18, Art. 19(4) | |
| Which ICT systems supporting critical or important functions were tested in the last twelve months? | Art. 24(6) | |
| Is every ICT contract in the register of information, split by critical or important function? | Art. 28(3) | |
| Does every contract supporting a critical or important function have an exit strategy? | Art. 28(8) |
If several rows are blank, start with scope and then with the framework. Our guide to scoring your DORA readiness turns these articles into a weighted assessment, our guide to what DORA compliance costs puts a budget line against each of them, and a free compliance check tells you which rows you can evidence today. Our DORA compliance software carries the requirements as tracked controls with an owner and evidence, keeps the register of information as xBRL-CSV, and runs the four-hour incident clock from the classification decision.
Frequently asked questions
What are the five pillars of DORA?
ICT risk management (Chapter II, Articles 5 to 16), ICT-related incident management, classification and reporting (Chapter III, Articles 17 to 23), digital operational resilience testing (Chapter IV, Articles 24 to 27), managing ICT third-party risk (Chapter V, Articles 28 to 44) and information-sharing arrangements (Chapter VI, Article 45). They are the items Article 1(1)(a) lists as the subject matter of the Regulation.
When did DORA start to apply?
Article 64 sets application from 17 January 2025. There is no later phase-in for the entity duties; the register of information, the incident clocks and the testing programme have all been live since that date.
Does DORA apply to microenterprises?
Yes, with carve-outs. A microenterprise under Article 3(60) employs fewer than 10 persons with turnover or balance sheet up to EUR 2 million, and is excluded from specific duties such as the independent control function in Article 6(4), the internal audit in Article 6(6) and the testing programme in Article 24. The framework itself, incident reporting and the register of information still apply.
What is the DORA reporting deadline for a major incident?
Under Article 5 of Delegated Regulation (EU) 2025/301, the initial notification is due within four hours of classifying the incident as major and no later than 24 hours from awareness, the intermediate report within 72 hours of the initial notification, and the final report within one month of the intermediate report.
Does DORA replace NIS2 for banks?
Article 1(2) treats DORA as a sector-specific Union act for financial entities identified as essential or important under NIS2, so the DORA requirements apply in place of the corresponding NIS2 ones. Our guide to DORA versus NIS2 sets out where the two still differ.
Primary sources
Article references, the entity list, the carve-outs and the application date are taken from Regulation (EU) 2022/2554, in particular Articles 1 to 3, 5, 6, 16 to 19, 24 to 26, 28, 30, 45, 50, 51 and 64. The reporting time limits are from Article 5 of Commission Delegated Regulation (EU) 2025/301. Confirm the current text before relying on a specific provision.




