What is DORA?
The Digital Operational Resilience Act (DORA) (Regulation (EU) 2022/2554) is the European Union's single, binding rulebook for the way financial entities manage technology risk. It became fully applicable on 17 January 2025.
Why the EU created DORA
Modern finance runs on software. Core banking platforms, payment rails, trading systems, claims engines and customer apps are all ICT systems, and a failure in any of them can stop a bank, an insurer or a market infrastructure from functioning. Before DORA, technology risk was governed by a patchwork: EBA guidelines for banks, EIOPA guidelines for insurers, national supervisory practices, and sectoral rules such as PSD2. The patchwork produced three problems:
Inconsistency
The same control was expected at different depths depending on the country and the sector.
Gaps
ICT third-party providers, cloud, data centres, software vendors: sat largely outside direct supervision.
Fragmented reporting
A single incident could trigger several overlapping notifications under different regimes.
What DORA actually does
DORA replaces the patchwork with one directly-applicable Regulation that sets uniform requirements across all 27 Member States. It does four things:
Operational resilience: the core idea
DORA's guiding principle is operational resilience, the ability of a financial entity to keep delivering its critical functions through, and to recover from, any kind of ICT disruption: a cyber-attack, a software failure, a data-centre outage, or a third-party collapse. DORA does not promise that incidents will never happen. It requires entities to be able to absorb, adapt and recover when they do.
That was your free preview
The rest of the course is free too. Add your work email below and the remaining 30 lessons, every knowledge check, the certification exam and your verifiable certificate open straight away.
Unlock the full course