Ask your compliance data anything. Sienna Insights, now available.
Join the webinar

DORA: the EU's Digital Operational Resilience Act explained

DORA, Regulation (EU) 2022/2554, is the EU's law on digital operational resilience for the financial sector. It sets requirements for ICT risk management, incident reporting, resilience testing, and oversight of the third-party providers that banks, insurers, and investment firms depend on.

August 24, 2026
15 min read
Share

Table of contents

DORA, the Digital Operational Resilience Act, is a European Union regulation that sets uniform rules for how banks, insurance companies, investment firms, and other financial entities manage the risk of their technology failing. It became directly applicable across all EU member states on 17 January 2025.

What DORA is

DORA's full name is Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector. The European Parliament and Council adopted it on 14 December 2022, and it was published in the Official Journal of the European Union on 27 December 2022.

DORA is a regulation, not a directive. That distinction matters for how it reaches your organization. A directive, like the EU Whistleblowing Directive, sets a goal that each member state then writes into its own national law, which is why whistleblowing rules look slightly different in Germany, France, and the Netherlands. A regulation skips that step. DORA applies in its entirety, the same way, in every member state, with no national transposition law in between.

Alongside the regulation, the EU adopted an amending directive, (EU) 2022/2556, on the same day. It updated eight existing pieces of EU financial-services legislation so their rules line up with DORA's requirements, rather than leaving two conflicting rulebooks in place.

Why DORA exists

Financial services now run on technology, and increasingly on technology supplied by outside vendors. When that technology fails, whether through a cyberattack or a system outage, the damage doesn't stay contained. It can disrupt financial services across borders and ripple into other sectors and the wider economy. Before DORA, financial entities managed this mostly by holding capital against potential losses. That approach covers financial risk, but it does little to prevent an ICT incident or speed up recovery from one. DORA closes that gap by regulating the operational side directly: how firms manage ICT risk day to day, not just how much capital they hold against the fallout.

Who DORA applies to

DORA covers financial entities across roughly 20 categories, spanning banks, insurance companies, and investment firms, according to EIOPA. It also covers the ICT third-party providers, cloud services and other technology vendors among them, that these financial entities rely on to operate.

What DORA requires

DORA groups its requirements into six areas.

ICT risk management comes first: financial entities need a documented framework for managing the risk that their information and communication technology poses to the business.

ICT third-party risk management covers how firms monitor the vendors they depend on, including the contractual terms that govern those relationships. DORA also requires financial entities to keep a register of their ICT third-party arrangements, submitted to their national competent authority.

Digital operational resilience testing ranges from basic checks to advanced threat-led penetration testing (TLPT), where a firm runs a controlled, intelligence-led simulated cyberattack against its own systems. The EU's TIBER-EU framework, the shared European standard for this kind of testing, was updated in February 2025 to align with DORA's technical standards.

ICT-related incident management sets out general requirements for handling incidents, plus a duty to report major ICT-related incidents to competent authorities and, on a voluntary basis, to notify significant cyber threats.

Information sharing lets financial entities exchange threat intelligence with each other on cyber threats and vulnerabilities.

Oversight of critical third-party providers rounds it out. DORA created an EU-wide oversight framework for the ICT vendors judged critical to the financial sector, known as critical ICT third-party providers, or CTPPs. On 18 November 2025, the European Supervisory Authorities (EBA, EIOPA, and ESMA) published the first official list of designated CTPPs, a concrete step in getting that oversight framework running.

How DORA relates to other rules you may already track

DORA isn't the only EU law covering cybersecurity and operational resilience. The NIS2 Directive sets baseline cybersecurity obligations across 18 sectors. Where the two overlap, financial services being one of them, DORA takes precedence: its rules on ICT risk management, incident reporting, resilience testing, and third-party risk apply in place of the equivalent NIS2 provisions for that entity. Outside financial services, NIS2 remains the baseline. For the fuller picture on how NIS2 works for organizations it does cover directly, see our NIS2 Directive guide.

If your organization also uses AI in trading, credit scoring, or fraud detection, you're likely tracking the EU AI Act too. Unlike NIS2, DORA doesn't fold into the AI Act's risk management provisions. The two apply independently, so meeting DORA's ICT risk requirements doesn't automatically satisfy your AI Act obligations, or the other way around.

And if you're DORA-covered because you're an EU financial entity, but also SOX-registered because of a US listing or a US-listed parent, you're managing two unrelated control frameworks at once: SOX Section 404 covers your internal controls over financial reporting, while DORA covers ICT operational resilience. See our SOX compliance guide if you're tracking both.

DORA and whistleblower protection: a connection worth flagging

DORA's incident reporting duty and whistleblower protection are two different things. DORA requires a financial entity, as an organization, to report major ICT-related incidents to its regulator. That's an institutional obligation, not a protection for an individual who raises a concern.

But a separate connection exists. DORA's amending directive updated existing EU financial-services legislation directly. Separately, "financial services, products, and markets" is one of the specific categories of EU law that the EU Whistleblowing Directive protects reports about. That suggests an employee at a financial entity who raises a concern about how their organization is handling its DORA obligations, for example a gap in ICT risk management or a third-party arrangement that was never assessed, could fall within the Whistleblowing Directive's protected scope. If so, that protection would sit alongside DORA's own regulator-facing reporting duty, not replace it.

This is a reasonable reading based on how the two frameworks are built, not a settled legal conclusion, so it shouldn't go live without your sign-off.

How SpeakUp supports your DORA-related reporting and governance

SpeakUp doesn't replace the ICT risk management tools, resilience testing, or incident classification systems DORA requires. Those stay with your IT and security teams.

What SpeakUp Report adds is the reporting and case management layer that sits alongside them. Employees, contractors, and third parties can flag a suspected ICT incident, a vendor risk concern, or a governance gap the same way they'd report any other type of misconduct, anonymously if they choose. Every report lands in one auditable system with clear ownership and an escalation path, which supports the internal reporting culture that both DORA's governance expectations and, where it applies, the EU Whistleblowing Directive call for.

If your organization already runs its whistleblowing program through SpeakUp, extending it to capture DORA-relevant reports is a configuration change, not a new system. Book a demo to see how it fits, or visit our whistleblowing software page for the full picture on secure reporting and case management.

Frequently asked questions

What is DORA?
DORA, the Digital Operational Resilience Act, is Regulation (EU) 2022/2554. It's an EU law that sets uniform requirements for how financial entities manage ICT risk, test their operational resilience, report major incidents, and oversee the technology vendors they depend on.

Who does DORA apply to?
DORA applies to roughly 20 categories of financial entities, including banks, insurance companies, and investment firms, along with the ICT third-party providers that support them.

When did DORA come into effect?
The European Parliament and Council adopted DORA on 14 December 2022, and it was published in the Official Journal on 27 December 2022. It became directly applicable across the EU on 17 January 2025.

Is DORA a regulation or a directive?
DORA is a regulation. It applies directly and identically in every EU member state, unlike a directive such as the EU Whistleblowing Directive, which each country transposes into its own national law.

How does DORA relate to NIS2?
For financial entities, DORA takes precedence. Where DORA's ICT risk management, incident reporting, testing, and third-party risk rules apply, they replace the equivalent NIS2 provisions for that entity.

Does DORA affect EU AI Act compliance?
Not directly. The two frameworks apply independently, so complying with one doesn't automatically satisfy the other, even for the same financial entity.

What is a critical ICT third-party provider (CTPP)?
A CTPP is an ICT vendor, for example a cloud or data services provider, that the European Supervisory Authorities have designated as critical to the financial sector. CTPPs fall under DORA's EU-wide oversight framework. The first list of designated CTPPs was published on 18 November 2025.

Does DORA require a whistleblowing channel?
Not directly. DORA's own reporting duty is an institutional one: financial entities report major ICT incidents to their regulator. Separately, employees who raise concerns about a financial entity's compliance with DORA may be protected under the EU Whistleblowing Directive, since financial services is one of its covered categories. Confirm this with legal counsel for your specific situation.

Sources

Digital Operational Resilience Act (DORA) – EIOPA
Digital Operational Resilience Act (DORA) | Updates, Compliance, Training – Cyber Risk GmbH

Subscribe to newsletter
By subscribing you agree to with our Privacy Policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Share