What it is
A binding EU regulation that standardizes how financial entities manage ICT risk, handle incidents, test resilience, and control third party ICT dependencies.
Key points
- Applies to many EU financial entities and introduces EU level oversight for critical ICT third party service providers.
- Requires an ICT risk management framework covering prevention, detection, response, recovery, and communication.
- Mandates reporting of major ICT related incidents to competent authorities and encourages structured post incident learning.
- Requires digital operational resilience testing, with advanced threat led penetration testing for certain entities.
- Strengthens ICT third party risk management through due diligence, contract requirements, monitoring, and exit planning.
Concrete example
A payment firm migrates key workloads to a cloud provider. Under DORA, it must assess concentration risk, harden identity and logging, ensure incident support is contractually defined, test recovery with realistic exercises, and maintain an exit path if the provider becomes a critical dependency.