Regulation · DORA

DORA: who it applies to and what it requires

DORA — the Digital Operational Resilience Act, Regulation (EU) 2022/2554 — has applied since 17 January 2025 to financial entities in the EU: banks, insurers, investment firms, payment and e-money institutions, crypto-asset service providers and others. It requires an ICT risk management framework, incident reporting, resilience testing and tight management of ICT vendors — and that last pillar is how it reaches software and IT companies.

01

Applies to

The 20 categories of financial entity in Art. 2(1) — from credit institutions to CASPs — supervised in Poland by the KNF.

02

Five pillars

ICT risk management (Ch. II), incident reporting (Ch. III), resilience testing (Ch. IV), third-party risk (Ch. V), information sharing (Ch. VI).

03

Reaches vendors through the contract

Articles 28–30: register of information, pre-contractual assessment, mandatory clauses. Vendors experience DORA as questionnaires and addenda.

04

Supervised, with sanctions

Competent authorities can order corrective action and impose penalties under national law, and the ESAs directly oversee critical vendors (Art. 31–44).

Who is in scope

Art. 2(1) lists the financial entities: credit institutions, payment institutions, e-money institutions, investment firms, crypto-asset service providers and issuers of asset-referenced tokens, CSDs, CCPs, trading venues, trade repositories, AIFMs and management companies, data reporting service providers, insurance and reinsurance undertakings, insurance intermediaries, IORPs, credit rating agencies, administrators of critical benchmarks, crowdfunding service providers, securitisation repositories — and, in Art. 2(1)(u), ICT third-party service providers. That last entry does not make vendors regulated the way banks are; it brings them into the oversight framework for critical providers and into the contractual regime of Chapter V.

Proportionality applies: microenterprises and certain smaller entities follow a simplified ICT risk management framework (Art. 16), and some categories are excluded from parts of the regulation (Art. 2(3)–(4)).

The five pillars in one table

PillarArticlesWhat it means in practice
ICT risk managementArt. 5–16Management body accountability, an ICT risk management framework, identification, protection, detection, response and recovery, learning and communication
ICT incident management and reportingArt. 17–23Incident classification; reporting major ICT incidents to the supervisor — initial notification, intermediate report, final report — within the deadlines set by the RTS/ITS
Digital operational resilience testingArt. 24–27A testing programme; threat-led penetration testing (TLPT) at least every three years for entities designated by the authorities
ICT third-party riskArt. 28–44Strategy, register of information, pre-contractual assessment, mandatory clauses, exit strategies; the oversight framework for critical providers
Information sharingArt. 45Voluntary sharing of cyber threat information

Key dates

  • 16 January 2023 — entry into force.
  • 17 January 2025 — date of application. All obligations bite.
  • 2025 — the first registers of information are filed with the supervisor; further RTS/ITS are adopted (including on subcontracting).
  • Ongoing — the ESAs designate critical ICT third-party providers and supervise them directly.

What the supervisor asks for first

In practice the first requests to a financial entity concern the register of information (Art. 28(3)), the ICT risk management framework and its latest review (Art. 6), the incident classification and reporting procedure (Art. 17–19), and evidence that ICT vendor contracts contain the Art. 30 clauses. Audomate's AI audit checks exactly those documents against exactly those articles.

Audit your DORA readiness in a 4-week pilotYour documents, a cited gap list, remediation drafts.

Questions we get most often

A regulation — directly applicable in every member state without transposition. Poland adopted accompanying legislation naming the KNF as the competent authority and setting penalties, but the obligations come from the EU text itself.
Not directly as a regulated entity — unless it is designated a critical ICT third-party provider. It reaches the company through contracts with financial entity customers, who must impose the Art. 30 clauses, register the services and assess the vendor. See [DORA for ICT vendors](/dora-for-ict-vendors).
DORA is lex specialis for financial entities: where DORA applies, its ICT risk and incident rules take precedence over NIS2 (Art. 4 NIS2). A software vendor can be covered by NIS2 directly (by sector and size) and by DORA indirectly (by contract) at the same time.

Updated 7 September 2026 · This page explains the rules in plain language and is not legal advice. What applies to you always depends on your own contracts and services.

Find out where you stand in four weeks

Pick this regulation for a 4-week pilot. Your documents, a cited gap list, remediation drafts — and a verified mark if you pass.