Skip to main content
Les Assises 2026 · Monaco

Meet us at the Startup area, and at our workshop on Wednesday 7 October, 4:30 pm.

Book the workshop

GLOSSARY · Regulations

DORA (Digital Operational Resilience Act)

DORA (Regulation (EU) 2022/2554, the Digital Operational Resilience Act) is the European regulation that sets uniform requirements for the digital operational resilience of financial entities: banks, insurers, investment firms, payment institutions, crypto-asset providers and their critical ICT third-party providers. It rests on five pillars: ICT risk management, ICT-related incident management and reporting, digital operational resilience testing, ICT third-party risk management, and information sharing. It has applied since 17 January 2025.

A regulation, not a directive

Unlike NIS2, DORA applies directly in every member state without transposition, and it is lex specialis for the financial sector: where both texts could apply, DORA governs. Its requirements are detailed by regulatory and implementing technical standards from the European supervisory authorities, which set the register of information templates, the incident classification criteria, the content of the ICT risk framework and the threat-led penetration testing regime.

The five pillars in practice

ICT risk management: a documented framework, approved by the management body, with identification and classification of ICT-supported functions, protection, detection, response and recovery. Incident management: classification of ICT incidents and reporting of the major ones to the competent authority on initial, intermediate and final reports. Testing: a program including threat-led penetration tests for the entities designated for them. Third-party risk: a strategy, the register of information, contract clauses, exit plans. Information sharing: voluntary exchange of threat intelligence.

What it demands from governance

DORA is explicit that the management body bears the ultimate responsibility for ICT risk, approves the framework and the strategy, sets the risk tolerance, is informed of major incidents and keeps its own knowledge current. For a board, that translates into a risk appetite for ICT, a reporting that measures against it, a register of critical ICT dependencies it has seen, and a testing program whose results it has read. The supervisor can ask for all four.

GO DEEPER

The reference guide.

ON MINDLAPSE

Where this term lives in the platform.

The pages that put the definition to work.

SEE IT VERIFIED

Definitions are the easy part. Proving them is the product.

Thirty minutes on your scope: risk, compliance, third parties, and how each term above becomes a verified control.

Refusing is exactly as easy as accepting, and nothing is pre-selected. Your choice is kept for 6 months and can be changed at any time from the footer.

Strictly necessary

Always on

Stores your cookie choice in this browser so we can honour it on your next visit. No tracking identifier, no third party. Cannot be disabled.