DORA brings ICT operational resilience under one EU rulebook for finance. Here's what it covers.
What is DORA?
The Digital Operational Resilience Act (DORA) sets uniform requirements for the security and resilience of the ICT systems that financial entities depend on — so the sector can withstand and recover from disruptions.
Who does it apply to?
Financial entities operating in the EU — banks, insurers, investment firms, payment providers and more — and, importantly, their critical ICT third-party providers.
The five pillars
- ICT risk management — a documented framework for identifying and managing ICT risk.
- Incident reporting — classify and report major ICT-related incidents.
- Resilience testing — regular testing, up to threat-led penetration testing.
- Third-party risk — manage and monitor critical ICT providers.
- Information sharing — share cyber-threat intelligence.
Shared work with NIS2 and ISO 27001DORA's ICT risk and incident requirements overlap heavily with NIS2 and ISO 27001. One control set covers all three — and a self-hosted, in-region deployment keeps resilience evidence where regulators expect it. See DORA with Vallorix.
General guidance, not legal advice. Confirm your DORA obligations with your compliance and legal teams.