Law · European Union

DORA: Digital Operational Resilience Act

DORA, Regulation (EU) 2022/2554, is the EU law on digital operational resilience that has applied since 17 January 2025 to almost every licensed financial firm, including payment and e-money institutions, investment firms and crypto-asset service providers. It requires an ICT risk framework, incident reporting, resilience testing and control of ICT third-party providers such as cloud services.

Last verified 2026-09-24Markdown · Data (CC BY 4.0)
Digital Operational Resilience Act: lawDORA§

At a glance

Official titleRegulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/10111
English titleDigital Operational Resilience Act
CitationRegulation (EU) 2022/2554
JurisdictionEuropean Union (applies in every EU/EEA state)
Typeregulation
Adopted2022-12-14
In force from2023-01-16
StatusIn force; applies from 17 January 2025

Full text

Official full text: Digital Operational Resilience Act (PDF, en)1 · 1,458 KB · file checked 2026-09-24

Official page: eur-lex.europa.eu1

Summary

DORA sets one set of rules on information and communication technology (ICT) risk for almost every regulated financial entity in the EU, including banks, payment and e-money institutions, investment firms, fund managers and crypto-asset service providers. Firms must run an ICT risk-management framework, classify and report major ICT-related incidents, test their digital operational resilience: with threat-led penetration testing for the most significant firms: and manage the risk of ICT third-party providers through contract requirements and a register of arrangements. Critical ICT third-party providers such as large cloud providers come under direct EU oversight.

Summary written by the Atlas from the official text; the law itself prevails.

Main articles

  • Art. 2: Scope: the financial entities covered, including CASPs under MiCA.
  • Art. 5-16: ICT risk-management framework and governance.
  • Art. 17-23: ICT-related incident management, classification and reporting.
  • Art. 24-27: Digital operational resilience testing; threat-led penetration testing under Art. 26.
  • Art. 28-30: Managing ICT third-party risk and key contractual provisions.
  • Art. 31: Designation and oversight of critical ICT third-party providers.

Licences it governs

Regulators that apply it

Last verified 2026-09-24Author Danil Marmysh, Founder & CEO, ProtegraReviewed by Anastasia Sidorenkova, Head of Licensing, ProtegraReport an errorReference information, not legal advice.

Sources

  1. eur-lex.europa.eu: TXT (32022R2554) · retrieved 2026-09-24

Does DORA apply to your business?

Send us a short description of what you do. We tell you which obligations and licences follow from it, and what it takes to comply.

A free preliminary assessment: we check your business model against the licence before you spend on an application. We handle this licence and any other fintech licence, including jurisdictions the Atlas does not cover yet.