
On 17 January 2025 the Digital Operational Resilience Act (Regulation (EU) 2022/2554), known as DORA, became applicable across the European Union. It sets a uniform framework for how banks, insurers, investment firms, payment institutions, crypto-asset service providers and many other financial entities manage information and communication technology (ICT) risk.
More than a year later, the regulation has moved from implementation project to day-to-day operation. Supervisors have received the first registers of ICT third-party arrangements, and incident reporting has become routine.
Five pillars of resilience
DORA is built around five areas: ICT risk management, ICT-related incident management and reporting, digital operational resilience testing, management of ICT third-party risk, and information sharing on cyber threats.
Crucially, the regulation places ultimate responsibility for ICT risk with the management body. Board members must understand ICT risk sufficiently to approve and oversee the framework — a notable step beyond treating technology as a purely operational matter.
The register of information
Every in-scope entity must maintain a register of information covering all contractual arrangements with ICT third-party service providers. The European Supervisory Authorities collected the first registers in 2025, using them among other things to identify providers that may be designated as critical.
Many firms found that compiling the register was harder than expected: contract data was scattered across procurement, legal and IT functions, and sub-outsourcing chains were poorly documented.
Oversight of critical ICT providers
DORA introduced a direct EU oversight framework for critical ICT third-party providers, such as major cloud service providers. In November 2025 the European Supervisory Authorities published the first list of designated critical providers, bringing these firms under lead overseer supervision.
Incident reporting and testing
Major ICT-related incidents must be classified using harmonised criteria and reported to the competent authority through initial, intermediate and final reports within tight deadlines. Significant firms must also carry out threat-led penetration testing at least every three years.
Relevance for auditors and non-financial companies
For external auditors, DORA provides a richer body of documented controls and incident information relevant to IT general controls and going concern assessments. Technology companies serving the financial sector, meanwhile, increasingly face DORA-driven contractual clauses on audit rights, exit strategies and incident notification.
Conclusion
DORA has made operational resilience a legal obligation rather than a best practice. The first year showed that the hardest part is not technology but governance and data — knowing exactly which services depend on which providers, and who is accountable when something goes wrong.



