Overview

The Digital Operational Resilience Act (DORA) is Regulation (EU) 2022/2554. It establishes a single EU framework for the digital operational resilience of financial entities, harmonising rules that were previously scattered across sectoral guidance and national practice. DORA applies from 17 January 2025 and covers a broad range of firms, including credit institutions, investment firms, payment and e-money institutions, insurers and, for the first time under a dedicated regime, certain critical ICT third-party providers.

The five pillars

DORA is commonly described through five areas. First, ICT risk management: firms must maintain a governance and control framework to identify, protect against, detect, respond to and recover from ICT-related disruption. Second, ICT-related incident management, classification and reporting to competent authorities. Third, digital operational resilience testing, ranging from basic testing to threat-led penetration testing for more significant entities. Fourth, management of ICT third-party risk, including contractual requirements and an EU-level oversight framework for ICT providers designated as critical. Fifth, arrangements for information and intelligence sharing on cyber threats.

Relevance to resolution

DORA is a supervisory and operational-resilience regime rather than a resolution instrument, but the two frameworks reinforce each other. A bank that meets DORA's expectations for ICT risk management and third-party oversight is better placed to sustain operational continuity if it enters resolution, because the systems and provider relationships supporting its critical functions are documented, tested and contractually controlled. DORA's third-party pillar overlaps directly with third-party risk management and with the operational-continuity dimension of resolvability. Persistent ICT fragility can, in turn, surface as an impediment to resolvability.

The operative text is Regulation (EU) 2022/2554 itself, supplemented by regulatory and implementing technical standards developed by the European Supervisory Authorities. Because it is a regulation, DORA applies directly in all member states without transposition. It sits alongside the internal-governance requirements of Article 74 of the Capital Requirements Directive (2013/36/EU), which already required sound management of outsourced activities, and it interacts with the broader operational-resilience expectations articulated by international standard setters.

Practical relevance

For banks, DORA formalises and standardises ICT and third-party controls that resolution planning also depends on, reducing the gap between the going-concern and resolution views of the same systems. For investors and analysts, DORA compliance is a lens on a firm's operational and cyber resilience, an area of risk distinct from capital and liquidity. Because DORA is recent, supervisory practice and the oversight of critical ICT providers are still maturing, and detailed technical standards continue to shape how the requirements bite in practice.