Back to library
Financial · Issued by European Union

DORA

Digital Operational Resilience Act (EU 2022/2554)

EUFinanceICTResilience
Compare DORA with

EU regulation harmonising ICT risk management for financial entities. Live from 17 January 2025.

DORA covers ICT risk management, incident reporting, digital operational resilience testing (including TLPT), third-party ICT risk, and information sharing. Applies to banks, insurers, investment firms, crypto-asset service providers and their critical ICT third parties.

At a glance

Complexity
High
Certification
Regulatory (mandatory)
Time to implement
9–18 months
Issued by
European Union

Fits

Industries
bankinginsuranceit
Risk types
cyberoperationalcompliancefinancial
Frequently asked

Questions risk leaders ask

EU regulation harmonising ICT risk management, incident reporting, testing, and third-party risk oversight for financial entities. Effective 17 January 2025.
India regulatory hub

Compare: DORA (EU) vs India's CERT-In and RBI cyber requirements

Cross-regulator comparison of incident-reporting clocks, third-party oversight and operational-resilience expectations.

India overlap matrix
See if it fits you

Run the Finder to get a personalised match score for DORA.

Made with Emergent