DORA: who it applies to and what it requires
DORA — the Digital Operational Resilience Act, Regulation (EU) 2022/2554 — has applied since 17 January 2025 to financial entities in the EU: banks, insurers, investment firms, payment and e-money institutions, crypto-asset service providers and others. It requires an ICT risk management framework, incident reporting, resilience testing and tight management of ICT vendors — and that last pillar is how it reaches software and IT companies.
Applies to
The 20 categories of financial entity in Art. 2(1) — from credit institutions to CASPs — supervised in Poland by the KNF.
Five pillars
ICT risk management (Ch. II), incident reporting (Ch. III), resilience testing (Ch. IV), third-party risk (Ch. V), information sharing (Ch. VI).
Reaches vendors through the contract
Articles 28–30: register of information, pre-contractual assessment, mandatory clauses. Vendors experience DORA as questionnaires and addenda.
Supervised, with sanctions
Competent authorities can order corrective action and impose penalties under national law, and the ESAs directly oversee critical vendors (Art. 31–44).
Who is in scope
Art. 2(1) lists the financial entities: credit institutions, payment institutions, e-money institutions, investment firms, crypto-asset service providers and issuers of asset-referenced tokens, CSDs, CCPs, trading venues, trade repositories, AIFMs and management companies, data reporting service providers, insurance and reinsurance undertakings, insurance intermediaries, IORPs, credit rating agencies, administrators of critical benchmarks, crowdfunding service providers, securitisation repositories — and, in Art. 2(1)(u), ICT third-party service providers. That last entry does not make vendors regulated the way banks are; it brings them into the oversight framework for critical providers and into the contractual regime of Chapter V.
Proportionality applies: microenterprises and certain smaller entities follow a simplified ICT risk management framework (Art. 16), and some categories are excluded from parts of the regulation (Art. 2(3)–(4)).
The five pillars in one table
| Pillar | Articles | What it means in practice |
|---|---|---|
| ICT risk management | Art. 5–16 | Management body accountability, an ICT risk management framework, identification, protection, detection, response and recovery, learning and communication |
| ICT incident management and reporting | Art. 17–23 | Incident classification; reporting major ICT incidents to the supervisor — initial notification, intermediate report, final report — within the deadlines set by the RTS/ITS |
| Digital operational resilience testing | Art. 24–27 | A testing programme; threat-led penetration testing (TLPT) at least every three years for entities designated by the authorities |
| ICT third-party risk | Art. 28–44 | Strategy, register of information, pre-contractual assessment, mandatory clauses, exit strategies; the oversight framework for critical providers |
| Information sharing | Art. 45 | Voluntary sharing of cyber threat information |
Key dates
- 16 January 2023 — entry into force.
- 17 January 2025 — date of application. All obligations bite.
- 2025 — the first registers of information are filed with the supervisor; further RTS/ITS are adopted (including on subcontracting).
- Ongoing — the ESAs designate critical ICT third-party providers and supervise them directly.
What the supervisor asks for first
In practice the first requests to a financial entity concern the register of information (Art. 28(3)), the ICT risk management framework and its latest review (Art. 6), the incident classification and reporting procedure (Art. 17–19), and evidence that ICT vendor contracts contain the Art. 30 clauses. Audomate's AI audit checks exactly those documents against exactly those articles.
Audit your DORA readiness in a 4-week pilotYour documents, a cited gap list, remediation drafts.
Questions we get most often
Updated 7 September 2026 · This page explains the rules in plain language and is not legal advice. What applies to you always depends on your own contracts and services.
Find out where you stand in four weeks
Pick this regulation for a 4-week pilot. Your documents, a cited gap list, remediation drafts — and a verified mark if you pass.