Comprehensive guide to DORA's Regulatory Technical Standards (RTS) and Implementing Technical Standards (ITS). Download the complete PDF documentation and understand all compliance requirements.
Get the complete official documentation of DORA Regulatory Technical Standards in PDF format
The Digital Operational Resilience Act (DORA) is supplemented by detailed Regulatory Technical Standards (RTS) and Implementing Technical Standards (ITS) developed by the European Supervisory Authorities (ESAs) - EBA, EIOPA, and ESMA.
RTS (Regulatory Technical Standards): Define detailed technical requirements and regulatory standards that financial entities must comply with.
ITS (Implementing Technical Standards): Provide practical implementation details, templates, and formats for reporting and compliance.
January 17, 2025: DORA regulation becomes fully applicable across all EU member states. Financial entities must comply with all RTS and ITS requirements.
DORA Entry into Force: Regulation (EU) 2022/2554 entered into force, giving entities 24 months to prepare.
RTS & ITS Development: ESAs developed and finalized technical standards through public consultations.
Final RTS Adoption: European Commission adopted final RTS packages covering all DORA pillars.
Full Application: All DORA requirements, including RTS and ITS, become fully applicable.
Requirement Area | Key Provisions |
---|---|
Governance | Management body responsibilities, ICT risk management function, three lines of defense |
Risk Assessment | Comprehensive ICT risk assessment at least annually, documenting critical/important functions |
Protection & Prevention | Security policies, access controls, change management, network security |
Detection | Continuous monitoring, anomaly detection, logging and correlation mechanisms |
Response & Recovery | Business continuity plans, disaster recovery, backup strategies, crisis communication |
Financial entities must classify ICT-related incidents based on specific criteria:
Incidents are classified as "major" based on:
Advanced testing framework for entities identified as significant:
Detailed requirements for managing ICT third-party service providers:
Stage | Requirements |
---|---|
Pre-Contracting | Due diligence, risk assessment, alternative provider analysis |
Contractual | Mandatory contract clauses, SLAs, audit rights, termination rights, data access |
Monitoring | Continuous oversight, performance monitoring, incident reporting from providers |
Exit | Exit strategies, transition plans, data retrieval procedures |
Access authoritative sources for DORA technical standards:
Implementing DORA RTS requirements can be complex. Our experts can help you:
Identify gaps between your current state and DORA RTS requirements
Develop a structured implementation plan with timelines and priorities
Create compliant policies, procedures, and documentation
Train your teams on DORA RTS requirements and best practices
Take our free 5-minute assessment to evaluate your DORA readiness
Sector-specific guidance for banking institutions
Implementation guidance for insurance companies
Frequently asked questions about DORA compliance