The Digital Operational Resilience Act (DORA) establishes a unified regulatory framework regarding digital operational resilience for the European financial sector, applying comprehensively starting January 17, 2025.
Scope of Application
DORA applies to over 22,000 financial entities, including banks, insurance companies, investment firms, and crypto-asset service providers. Crucially, it also brings critical third-party Information and Communication Technology (ICT) service providers (e.g., cloud platforms like AWS, Azure, Google Cloud) under direct EU financial supervision.
Five Core Pillars of DORA
1. ICT Risk Management
Financial entities must set up comprehensive ICT risk management frameworks. Management bodies are ultimately accountable and cannot delegate this responsibility. They must map their ICT systems, identify critical assets, and implement protection and prevention mechanisms.
2. ICT-Related Incident Reporting
DORA harmonizes reporting timelines. Entities must classify ICT incidents and report "major" incidents to competent authorities within stringent deadlines:
- Initial Notification: Within 4 hours of classification, but no later than 24 hours of awareness.
- Intermediate Report: Within 72 hours.
- Final Report: Within one month.
3. Digital Operational Resilience Testing
Entities must execute regular operational resilience testing. For significant entities, this requires advanced Threat-Led Penetration Testing (TLPT) at least every three years, covering live production systems and involving relevant ICT third-party service providers.
4. ICT Third-Party Risk Management
DORA establishes strict rules for managing supplier risk. Financial entities must:
- Maintain a register of information of all ICT third-party contracts.
- Ensure contracts contain specific mandatory clauses (e.g., data location, exit strategies, auditing rights).
- Assess concentration risk (e.g., relying too heavily on a single cloud provider).
5. Information Sharing
The regulation encourages voluntary sharing of cyber threat information and intelligence between financial entities to enhance the overall sector's defensive capabilities.
Oversight of Critical ICT Providers
Critical ICT third-party providers (CTPPs) will be directly overseen by a Lead Overseer (one of the European Supervisory Authorities: EBA, ESMA, or EIOPA). The Lead Overseer can request information, conduct off-site and on-site inspections, and issue fines up to 1% of the provider's average daily worldwide turnover for non-compliance.