DORA Academy All courses DORA Fundamentals Certification
0% Complete
Free Preview

What is DORA?

3 min
Lesson 1 of 31

The Digital Operational Resilience Act (DORA) (Regulation (EU) 2022/2554) is the European Union's single, binding rulebook for the way financial entities manage technology risk. It became fully applicable on 17 January 2025.

Why the EU created DORA

Modern finance runs on software. Core banking platforms, payment rails, trading systems, claims engines and customer apps are all ICT systems, and a failure in any of them can stop a bank, an insurer or a market infrastructure from functioning. Before DORA, technology risk was governed by a patchwork: EBA guidelines for banks, EIOPA guidelines for insurers, national supervisory practices, and sectoral rules such as PSD2. The patchwork produced three problems:

Inconsistency

The same control was expected at different depths depending on the country and the sector.

Gaps

ICT third-party providers, cloud, data centres, software vendors: sat largely outside direct supervision.

Fragmented reporting

A single incident could trigger several overlapping notifications under different regimes.

What DORA actually does

DORA replaces the patchwork with one directly-applicable Regulation that sets uniform requirements across all 27 Member States. It does four things:

1
Harmonises ICT risk management: one framework, one vocabulary, one standard of care for every financial entity.
2
Standardises incident reporting: common classification criteria and fixed deadlines for notifying supervisors.
3
Mandates resilience testing: from basic vulnerability scans to advanced threat-led penetration testing.
4
Brings ICT third parties into scope: including a direct EU oversight regime for the most critical providers.
Regulation, not Directive. DORA is a Regulation: it applies directly in every Member State with no national transposition. The text you read on EUR-Lex is the law. there is no national version to wait for.

Operational resilience: the core idea

DORA's guiding principle is operational resilience, the ability of a financial entity to keep delivering its critical functions through, and to recover from, any kind of ICT disruption: a cyber-attack, a software failure, a data-centre outage, or a third-party collapse. DORA does not promise that incidents will never happen. It requires entities to be able to absorb, adapt and recover when they do.

Key takeaway: DORA is one binding EU Regulation that unifies how financial entities manage, test, report and oversee technology risk. Its goal is operational resilience (staying functional through disruption) not the impossible promise of zero incidents.

That was your free preview

The rest of the course is free too. Add your work email below and the remaining 30 lessons, every knowledge check, the certification exam and your verifiable certificate open straight away.

Unlock the full course
Free with signup

Who Must Comply: DORA Scope

2 min
Lesson 2 of 31
Free with signup

Timeline, Legal Basis & Penalties

3 min
Lesson 3 of 31
Free with signup

Module 1 Quiz

8 min
Lesson 4 of 31
Free with signup

The Five Pillars at a Glance

2 min
Lesson 5 of 31
Free with signup

The ICT Risk Management Framework

2 min
Lesson 6 of 31
Free with signup

Governance & Board Accountability

2 min
Lesson 7 of 31
Free with signup

Module 2 Quiz

8 min
Lesson 8 of 31
Free with signup

Detecting & Classifying ICT Incidents

3 min
Lesson 9 of 31
Free with signup

The 4h / 72h / 1-Month Reporting Workflow

3 min
Lesson 10 of 31
Free with signup

Significant Cyber Threats & Voluntary Reporting

2 min
Lesson 11 of 31
Free with signup

Module 3 Quiz

8 min
Lesson 12 of 31
Free with signup

The Resilience Testing Programme

2 min
Lesson 13 of 31
Free with signup

Threat-Led Penetration Testing (TLPT)

2 min
Lesson 14 of 31
Free with signup

Module 4 Quiz

8 min
Lesson 15 of 31
Free with signup

ICT Third-Party Risk & the Register of Information

2 min
Lesson 16 of 31
Free with signup

Contracts & Critical ICT Third-Party Providers

2 min
Lesson 17 of 31
Free with signup

Special Focus: DORA for Contract & Procurement Managers

6 min
Lesson 18 of 31
Free with signup

Pillar 5: Information Sharing

2 min
Lesson 19 of 31
Free with signup

Module 5 Quiz

8 min
Lesson 20 of 31
Free with signup

Worked Example: DORA in a Real Institution

2 min
Lesson 21 of 31
Free with signup

Common Misunderstandings & How to Avoid Them

2 min
Lesson 22 of 31
Free with signup

Module 6 Quiz

6 min
Lesson 23 of 31
Free with signup

Two Regulations, Two Scope Tests

3 min
Lesson 24 of 31
Free with signup

The DORA Scope Test, and the Carve-Outs

4 min
Lesson 25 of 31
Free with signup

The NIS2 Scope Test, and Why It Is Not the Same Test

3 min
Lesson 26 of 31
Free with signup

The Insurer That Is In Neither

4 min
Lesson 27 of 31
Free with signup

Scope Quiz: DORA or NIS2

8 min
Lesson 28 of 31
Free with signup

Building a DORA Compliance Roadmap

2 min
Lesson 29 of 31
Free with signup

Common Pitfalls & Audit Readiness

2 min
Lesson 30 of 31
Free with signup

Course Summary & Certification Exam Prep

2 min
Lesson 31 of 31

Course Complete!

You have finished every lesson and knowledge check of the DORA Fundamentals Certification.
You are ready to sit the certification exam.

Start Certification Exam