DORA: Digital Operational Resilience Act
DORA, Regulation (EU) 2022/2554, is the EU law on digital operational resilience that has applied since 17 January 2025 to almost every licensed financial firm, including payment and e-money institutions, investment firms and crypto-asset service providers. It requires an ICT risk framework, incident reporting, resilience testing and control of ICT third-party providers such as cloud services.
At a glance
| Official title | Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/10111 |
|---|---|
| English title | Digital Operational Resilience Act |
| Citation | Regulation (EU) 2022/2554 |
| Jurisdiction | European Union (applies in every EU/EEA state) |
| Type | regulation |
| Adopted | 2022-12-14 |
| In force from | 2023-01-16 |
| Status | In force; applies from 17 January 2025 |
Full text
Official full text: Digital Operational Resilience Act (PDF, en)1 · 1,458 KB · file checked 2026-09-24
Official page: eur-lex.europa.eu1
Summary
DORA sets one set of rules on information and communication technology (ICT) risk for almost every regulated financial entity in the EU, including banks, payment and e-money institutions, investment firms, fund managers and crypto-asset service providers. Firms must run an ICT risk-management framework, classify and report major ICT-related incidents, test their digital operational resilience: with threat-led penetration testing for the most significant firms: and manage the risk of ICT third-party providers through contract requirements and a register of arrangements. Critical ICT third-party providers such as large cloud providers come under direct EU oversight.
Summary written by the Atlas from the official text; the law itself prevails.
Main articles
- Art. 2: Scope: the financial entities covered, including CASPs under MiCA.
- Art. 5-16: ICT risk-management framework and governance.
- Art. 17-23: ICT-related incident management, classification and reporting.
- Art. 24-27: Digital operational resilience testing; threat-led penetration testing under Art. 26.
- Art. 28-30: Managing ICT third-party risk and key contractual provisions.
- Art. 31: Designation and oversight of critical ICT third-party providers.
Licences it governs
- EMI · Lithuania
Electronic money institution licence for non-limited activity
LB · capital EUR 350,000
- VASP · Germany
Qualified crypto custody licence (Erlaubnis für das qualifizierte Kryptoverwahrgeschäft nach § 1 Absatz 1a Satz 2 Nummer 6 KWG)
BaFin
- VASP · Ireland
Virtual Asset Service Provider AML/CFT Registration
CBI
Regulators that apply it
- Netherlands
Authority for the Financial Markets (AFM)
The Autoriteit Financiële Markten (AFM) is the Netherlands' autonomous conduct-of-business supervisory authority (zelfstandig bestuursorgaan
- France
Financial Markets Authority (AMF)
The Autorité des marchés financiers (AMF) is France's independent financial markets authority, tasked with safeguarding savings invested in
- Germany
Federal Financial Supervisory Authority (BaFin)
BaFin operates as Germany's unified federal financial supervisor under the Federal Ministry of Finance, supervising credit institutions, fin
- Spain
Bank of Spain (BdE)
Banco de España is Spain's national central bank and banking supervisor, operating as an integral part of the European System of Central Ban
- Lithuania
Bank of Lithuania (LB)
The Bank of Lithuania operates as the central bank of the Republic of Lithuania and member of the Eurosystem, conducting integrated prudenti
- Ireland
Central Bank of Ireland (CBI)
The Central Bank of Ireland serves the public interest by maintaining monetary and financial stability while ensuring that the financial sys
- Czech Republic
Czech National Bank (CNB)
The Czech National Bank acts as the central bank and unified supervisory authority of the Czech financial market under Act No. 6/1993 Coll.
- Spain
National Securities Market Commission (CNMV)
The National Securities Market Commission is the Spanish agency responsible for supervising and inspecting secondary securities markets, inv
- Italy
National Commission for Companies and the Stock Exchange (CONSOB)
CONSOB is Italy's independent administrative authority tasked with safeguarding investor protection, market transparency, fair conduct among
- Luxembourg
Commission de Surveillance du Secteur Financier (CSSF)
The CSSF operates as the unified public supervisory authority for the Luxembourg financial centre, conducting prudential supervision and mar
- Cyprus
Cyprus Securities and Exchange Commission (CySEC)
The Cyprus Securities and Exchange Commission is the independent public supervisory authority responsible for the regulation and supervision
- Netherlands
De Nederlandsche Bank (DNB)
De Nederlandsche Bank acts as the central bank of the Netherlands and integral member of the Eurosystem and ESCB, exercising prudential supe
- European Union
European Banking Authority (EBA)
The European Banking Authority is an independent EU agency that creates the European Single Rulebook for banking and payments, fosters super
- European Union
European Securities and Markets Authority (ESMA)
ESMA operates as an independent European Union supervisory authority that protects the public interest by contributing to the stability and
- Estonia
Finantsinspektsioon (FI)
Finantsinspektsioon is Estonia's independent financial supervision and crisis resolution authority operating with autonomous responsibilitie
- Poland
Polish Financial Supervision Authority (KNF)
KNF ensures the proper functioning, stability, security, and transparency of the Polish financial market, safeguards public confidence in fi
- Latvia
Latvijas Banka (LB)
Latvijas Banka is the central bank of the Republic of Latvia and member of the Eurosystem, operating as the single integrated financial supe
- Malta
Malta Financial Services Authority (MFSA)
The Malta Financial Services Authority is the single autonomous financial regulator in Malta, entrusted with prudential and conduct supervis
- Slovakia
National Bank of Slovakia (NBS)
Národná banka Slovenska acts as the central bank and integrated financial supervisory authority of the Slovak Republic. It safeguards price
Sources
- eur-lex.europa.eu: TXT (32022R2554) · retrieved 2026-09-24
Does DORA apply to your business?
Send us a short description of what you do. We tell you which obligations and licences follow from it, and what it takes to comply.
A free preliminary assessment: we check your business model against the licence before you spend on an application. We handle this licence and any other fintech licence, including jurisdictions the Atlas does not cover yet.