What is DORA? ICT risk and resilience explained

The EU Digital Operational Resilience Act (DORA) is a directly applicable regulation for digital operational resilience in the financial sector. It creates a harmonised framework for ICT risk management, incident reporting, resilience testing, information sharing and oversight of ICT third-party risk.

Who this is for: For fintech teams and suppliers organising ICT risk and vendor evidence before DORA mapping is confirmed.

What DORA covers

DORA applies a common set of digital-operational-resilience requirements across in-scope EU financial entities. Its main areas include ICT risk management, ICT-related incident handling and reporting, resilience testing, third-party risk and supervisory oversight.

  • ICT risk management
  • Incident reporting and testing
  • ICT third-party risk

Track ICT risks

Use a risk register to record ICT assets, resilience scenarios, business impact, treatment owners, control evidence and open remediation.

Review important suppliers

Supplier records can capture service criticality, contracts, concentration risk, review evidence, incidents, exit planning and reassessment dates.

Confirm the specific mapping

DORA applicability, reporting duties, technical standards and contractual requirements should be mapped with qualified specialists before being represented as complete support.

Common questions

What is DORA in simple terms?

DORA is an EU regulation intended to ensure that in-scope financial entities can withstand, respond to and recover from ICT-related disruption.

When did DORA start applying?

Regulation (EU) 2022/2554 has applied since 17 January 2025, together with related technical standards and implementing measures.

Who does DORA apply to?

DORA applies to a broad range of EU financial entities and creates an oversight framework for certain critical ICT third-party providers. Exact entity and service scope should be confirmed by a qualified specialist.

What are DORA's main areas?

The main areas are ICT risk management, ICT-related incident management and reporting, digital operational resilience testing, ICT third-party risk management and information-sharing arrangements.

Does Trustega provide DORA legal advice?

No. Trustega can help organise ICT-risk, supplier and remediation records. Legal applicability, reporting duties and detailed regulatory mapping remain with qualified specialists.

Primary sources

Related practical guides