Comprehensive guide to DORA's Regulatory Technical Standards (RTS) and Implementing Technical Standards (ITS). Download the complete PDF documentation and understand all compliance requirements.
Every one of the 13 RTS/ITS policy products, decoded pillar by pillar into plain implementation language: thresholds, timelines, templates and a ready-to-use checklist at the end of each chapter. 24 pages you can act on, instead of several hundred pages of ESA legal text you have to reconcile yourself.
The Digital Operational Resilience Act (DORA) is supplemented by detailed Regulatory Technical Standards (RTS) and Implementing Technical Standards (ITS) developed by the European Supervisory Authorities (ESAs) - EBA, EIOPA, and ESMA. New to the regulation? Start with our complete guide to what DORA is, then return here for the technical detail.
RTS (Regulatory Technical Standards): Define detailed technical requirements and regulatory standards that financial entities must comply with.
ITS (Implementing Technical Standards): Provide practical implementation details, templates, and formats for reporting and compliance.
If you already run an ISO 27001 ISMS, it is the fastest roadmap to these standards. Read our ISO 27001 → DORA mapping guide (what maps cleanly, the regulatory delta, and the quick wins) or learn the full control mapping in the DORA Programme Manager certification.
17 January 2025: DORA became fully applicable across all EU Member States. Financial entities must comply with the Regulation and with the RTS and ITS adopted under it.
DORA Entry into Force: Regulation (EU) 2022/2554 entered into force, giving entities 24 months to prepare.
RTS & ITS Development: ESAs developed and finalized technical standards through public consultations.
Final RTS Adoption: European Commission adopted final RTS packages covering all DORA pillars.
Full Application: DORA and the first-batch RTS/ITS become fully applicable across the EU.
Second Batch in the Official Journal: oversight harmonisation (2025/295, 13 Feb), incident reporting RTS/ITS (2025/301 and 2025/302, 20 Feb), TLPT (2025/1190, in force 8 July) and subcontracting (2025/532, in force 22 July). The DORA level-2 framework is complete.
DORA is supplemented by 13 texts developed jointly by the EBA, ESMA and EIOPA (the European Supervisory Authorities, or ESAs): eleven binding technical standards (RTS and ITS) and two sets of Joint Guidelines applied on a comply-or-explain basis. The standards were delivered in two batches: the "first batch" submitted to the European Commission in January 2024, and the "second batch" finalised mid-2024. Once adopted by the Commission as Delegated Regulations or Implementing Regulations, the standards are directly applicable across all 27 Member States, no national transposition required.
Every adopted act, with its DORA mandate and the directly citable Official Journal reference. Use the exact regulation number when you reference a requirement in a policy document or a supervisory response: "the RTS on subcontracting" is ambiguous, "Delegated Regulation (EU) 2025/532, Article 5" is not.
| Standard | DORA mandate | Legal act | Status | Text |
|---|---|---|---|---|
| ICT risk management framework + simplified framework | Art. 15, Art. 16(3) | Delegated Regulation (EU) 2024/1774 | In force, applies alongside DORA since 17 Jan 2025 | EUR-Lex |
| Classification of major incidents and significant cyber threats | Art. 18(3) | Delegated Regulation (EU) 2024/1772 | In force, applies alongside DORA since 17 Jan 2025 | EUR-Lex |
| Policy on ICT services supporting CIFs (third-party policy) | Art. 28(10) | Delegated Regulation (EU) 2024/1773 | In force, applies alongside DORA since 17 Jan 2025 | EUR-Lex |
| Register of Information (template & taxonomy) | Art. 28(9) | Implementing Regulation (EU) 2024/2956 | In force, annual submission via your NCA (first cycle 2025) | EUR-Lex |
| CTPP designation criteria | Art. 31(6) | Delegated Regulation (EU) 2024/1502 | In force, basis of the 2025 CTPP designations | EUR-Lex |
| Oversight fees charged to designated CTPPs | Art. 43(2) | Delegated Regulation (EU) 2024/1505 | In force: OJ 30 May 2024 | EUR-Lex |
| Harmonisation of oversight conduct (Lead Overseer regime) | Art. 41(1) | Delegated Regulation (EU) 2025/295 | In force: OJ 13 Feb 2025 | EUR-Lex |
| Incident reporting: content & time limits (4h / 72h / 1 month) | Art. 20(a) | Delegated Regulation (EU) 2025/301 | In force: OJ 20 Feb 2025 | EUR-Lex |
| Incident reporting: forms & templates | Art. 20(b) | Implementing Regulation (EU) 2025/302 | In force: OJ 20 Feb 2025 | EUR-Lex |
| Joint examination teams | Art. 41(1)(c) | Delegated Regulation (EU) 2025/420 | In force, adopted 16 Dec 2024 | EUR-Lex |
| Subcontracting of ICT services supporting CIFs | Art. 30(5) | Delegated Regulation (EU) 2025/532 | In force since 22 July 2025: OJ 2 July 2025 | EUR-Lex |
| Threat-led penetration testing (TLPT) | Art. 26(11) | Delegated Regulation (EU) 2025/1190 | In force since 8 July 2025: OJ 18 June 2025 | EUR-Lex |
| Aggregated costs & losses of major incidents | Art. 11(11) | Joint Guidelines JC/GL/2024/34 (not an RTS) | Applies: ESA guidelines, comply-or-explain at NCA level | EBA |
The same cross-reference, decoded standard by standard with implementation checklists, is available in our RTS & ITS Complete Overview.
The catalogue is abstract until you map it onto a concrete decision. Take a common one: a bank moves its payment processing platform to a public cloud provider. Payment processing is a critical or important function (CIF), so the move triggers obligations from six of the standards above, each demanding a specific artefact:
| Standard | What it requires here | Artefact to produce |
|---|---|---|
| 2024/1773 (third-party policy) | The outsourcing decision must follow your board-approved policy on ICT services supporting CIFs: due diligence, risk assessment before signature, exit strategy | Pre-contract risk assessment + documented board or committee approval |
| DORA Art. 30 (contract itself) | The cloud contract must contain the Article 30(3) mandatory clauses: audit and access rights, data location, termination rights, exit assistance, service levels | Contract clause mapping, each Art. 30(3) point matched to a clause reference |
| 2024/2956 (Register of Information) | One row per contracted ICT service, flagged as supporting a CIF, with provider LEI, jurisdiction and dependency data | Updated Register of Information before the next annual submission |
| 2025/532 (subcontracting) | You must assess the provider's subcontracting chain for the service (who actually runs the data centres, where support sits) and secure notification and objection rights for material changes | Subcontracting chain assessment + contract clauses on chain visibility |
| 2024/1772 + 2025/301 (incidents) | An outage of the platform is assessed against the major-incident criteria; if major, the 4h / 72h / 1-month reporting chain starts, cloud provider incidents included | Incident classification procedure covering provider-originated incidents, with provider notification duties in the contract |
| 2025/1190 (TLPT) | If your entity is in TLPT scope, the systems supporting payment processing, now partly on cloud infrastructure, belong in the test scope | TLPT scope definition including the cloud-hosted components |
The pattern generalises: CIF status is the switch that turns most of these standards on. Before mapping any outsourcing against the catalogue, settle whether the function it supports is critical or important, our CIF identification guide covers the methodology, and the third-party risk guide covers the Article 28-30 chain end to end.
The RTS on ICT risk management framework (Commission Delegated Regulation 2024/1774) is the densest and most operationally significant of the technical standards. It runs to 70+ recitals and articles, covering the full ICT control surface a financial entity must maintain. Key chapters include security policies and procedures (governance level), human resources policy and security awareness, identity management and access control with multi-factor authentication for privileged access, cryptographic controls including key management, network security (segmentation, monitoring, secure configuration), ICT operations (change, capacity, vulnerability), ICT project management and acquisition, ICT business continuity policy with documented RTOs/RPOs, and crisis communication.
| Requirement Area | Key Provisions |
|---|---|
| Governance | Management body responsibilities, ICT risk management function, three lines of defence |
| Risk Assessment | Comprehensive ICT risk assessment at least annually, documenting critical/important functions |
| Protection & Prevention | Security policies, access controls (incl. MFA for privileged), change management, network security |
| Cryptography | Encryption at rest, in transit, in use; key management aligned with recognised standards; cryptographic agility |
| Detection | Continuous monitoring, anomaly detection, logging and correlation, SOC capabilities |
| Response & Recovery | Business continuity plans, disaster recovery, backup strategies, validated RTO/RPO end-to-end |
| Learning & Evolving | Post-incident reviews, threat intelligence integration, control updates, lessons learned governance |
Financial entities must classify ICT-related incidents based on specific criteria:
Incidents are classified as "major" based on:
The €29.99 reference covers all 13 RTS/ITS policy products in a single PDF, including this incident-reporting chapter in full: classification criteria, the 4h / 72h / 1-month chain, and a Pillar 2 checklist you can lift into your programme plan. For an incident deep-dive, see the Incident Response & Reporting Playbook (Pillar 2).
Advanced testing framework for entities identified as significant:
Detailed requirements for managing ICT third-party service providers:
| Stage | Requirements |
|---|---|
| Pre-Contracting | Due diligence, risk assessment, alternative provider analysis, concentration risk evaluation |
| Contractual | Article 30 mandatory clauses, SLAs, audit rights, termination rights, data access & location |
| Monitoring | Continuous oversight, performance monitoring, incident reporting from providers, register updates |
| Exit | Exit strategies tested annually, transition plans, data retrieval procedures, alternative provider identified |
The RTS on subcontracting is the late-2024 standard that operationalises Article 30 paragraphs on sub-outsourcing of critical or important functions. Key obligations:
One of the most misunderstood aspects of the DORA framework is the legal pathway by which the technical standards become binding obligations. Unlike Directives, which require national transposition, DORA itself is a Regulation under Article 288 TFEU, directly applicable in all Member States with no need for national legislation. The RTS and ITS follow a similar route but with one extra step:
This means the question "is this RTS in force?" has a binary answer that you can verify on EUR-Lex. There is no national grace period, no transposition delay. The 17 January 2025 application date for DORA itself was the trigger, most RTS applied from that date or shortly after.
For most financial entities, DORA RTS arrive in a regulatory landscape already shaped by sector-specific guidance from the ESAs, national supervisors, ENISA, NIS2 and global standards (ISO 27001, NIST CSF). Understanding the interaction matters for implementation efficiency.
Largely superseded by the RTS on ICT risk management framework. The EBA opened a consultation in 2024 on repealing or amending these guidelines. In practice, banks should treat DORA + RTS 2024/1774 as authoritative; legacy EBA guidelines remain useful as implementation depth on specific topics (network segmentation, secure development) but no longer add binding obligations beyond what DORA mandates.
Partially superseded for ICT outsourcing by DORA Articles 28-30 plus the RTS on subcontracting. Non-ICT outsourcing (e.g., physical document management, certain operational outsourcing) continues to follow the EBA Outsourcing Guidelines. Banks need to maintain two parallel registers in many cases: DORA Register of Information for ICT and the EBA outsourcing register for non-ICT.
Under consultation in 2024 for repeal or alignment with DORA. Practically replaced by DORA Articles 28-30 + RTS on subcontracting for cloud outsourcing.
NIS2 covers a broader universe (energy, transport, health, digital infrastructure, financial services, public administration) but for financial entities DORA acts as lex specialis under NIS2 Article 4(1): DORA prevails over NIS2 obligations where they overlap. Financial entities subject to both DORA and NIS2 (e.g., a bank with a separately authorised data centre operator subsidiary) must navigate the dual framework carefully.
Not binding under EU law but widely adopted. ISO 27001 controls map well to many DORA requirements; supervisors generally accept ISO 27001 certification as evidence of control design but require independent validation that DORA-specific requirements (e.g., incident classification, register of information) are met. NIST CSF provides a useful taxonomy but does not satisfy DORA on its own.
Access authoritative sources for DORA technical standards:
Implementing DORA RTS requirements can be complex. Our experts can help you:
Identify gaps between your current state and DORA RTS requirements
Develop a structured implementation plan with timelines and priorities
Create compliant policies, procedures, and documentation
Train your teams on DORA RTS requirements and best practices
All 13 Regulatory and Implementing Technical Standards for DORA in one searchable reference
Complete TLPT pillar page, who must test, TIBER-EU alignment, phases, scope requirements
Plain-language explainer of the Digital Operational Resilience Act: 5 pillars, scope, penalties and compliance roadmap
Free interactive 45-point self-assessment across all 5 DORA pillars
Supervisory inspections, internal audit duties under Article 6, audit scope by pillar and how to prepare
Complete TLPT framework: scope, methodology, and reporting templates from the RTS text
4-hour, 72-hour, and final report timelines with decision trees and classification criteria
Deep-dive comparing Regulatory and Implementing Technical Standards under DORA
Recent amendments and updates to DORA Technical Standards from ESAs
Take our free 5-minute assessment to evaluate your DORA readiness
Sector-specific guidance for banking institutions
50+ expert answers on compliance, deadlines and penalties
Both frameworks apply to many financial entities: lex specialis rule, dual compliance obligations, and where DORA takes precedence
Complete guide to the Register of Information, Article 30 mandatory clauses, the 19 designated CTPPs, and the due diligence framework
The Article 3(22) concept most RTS obligations cascade from, definition, identification methodology and worked examples
Workbooks, playbooks and certifications built for EU financial entities. Add several to your cart: volume discounts apply automatically.
Take our free 5-minute assessment and get an instant DORA compliance score with personalised recommendations.