Loading…
Loading…
DORA is a directly-applicable EU Regulation (no Member-State transposition required) that consolidates and replaces the patchwork of sector-specific ICT-risk guidance previously issued by the EBA, ESMA, EIOPA and national competent authorities. The five pillars:
1. ICT risk-management framework (Articles 5–16). All in-scope entities must operate a documented ICT risk-management framework proportionate to size and risk profile, with board-level accountability and an annual internal audit. Microenterprises benefit from a simplified regime.
2. ICT-related incident management, classification and reporting (Articles 17–23). Mandatory classification of ICT incidents using harmonised criteria (Commission Delegated Regulation 2024/1772 / RTS). Major incidents must be reported to the competent authority within regulatory deadlines (initial / intermediate / final reports), and significant cyber threats may also be voluntarily notified.
3. Digital operational resilience testing (Articles 24–27). All entities must perform a basic test programme (vulnerability assessments, network security assessments, source-code reviews, scenario-based tests, compatibility testing, performance testing, penetration testing). Significant entities additionally undergo Threat-Led Penetration Testing (TLPT) at least every three years, conducted by accredited testers under the TIBER-EU framework methodology.
4. ICT third-party risk management (Articles 28–44). Mandatory contract clauses for ICT outsourcing (Article 30 minimum content), pre-contractual due diligence, concentration-risk monitoring, and a Register of Information cataloguing all ICT third-party arrangements (Commission Implementing Regulation 2024/2956). Critically, this pillar establishes the CTPP regime: the ESAs designate Critical ICT Third-Party Providers based on systemic-impact criteria (Commission Delegated Regulation 2024/1502), and a Joint Examination Team conducts on-site inspections and may issue binding recommendations and pecuniary penalties up to 1% of average daily global turnover.
5. Information-sharing arrangements (Article 45). Voluntary mechanism for financial entities to exchange cyber-threat intelligence within trusted communities, with safe-harbour treatment under EU competition and data- protection law.
DORA is supported by 13 Level 2 Regulatory Technical Standards / Implementing Technical Standards and Commission Delegated/Implementing Regulations, several of which were adopted in mid-2024 to enable application by 17 January 2025.
binding EU mechanism putting hyperscalers (AWS, Azure, GCP, Oracle) under direct supervision by EU financial-sector authorities. ESAs may inspect data centres located inside or outside the EU, request information, recommend contractual modifications, and ultimately compel financial entities to terminate or suspend services with a non-compliant CTPP. First CTPP designations are expected in H2 2026 once the ESAs complete their criticality assessment based on the Register of Information data collected in 2025.
of the UK PRA Critical Third Parties (CTP) regime under the Financial Services and Markets Act 2023 (PRA SS2/21 successor); Singapore MAS Technology Risk Management Guidelines and the proposed CTP regime; Australia APRA CPS 230 (Operational Risk Management, effective 1 July 2025); and the Hong Kong HKMA Operational Resilience module. Sets a global precedent for direct financial-supervisor oversight of cloud providers.
estimates put one-time DORA implementation cost at €1–5m for mid-sized firms and €10m+ for systemic banks; ongoing annual cost ~€0.5–2m. Hyperscalers are internalising significant compliance and disclosure cost to retain EU financial-sector revenue.
scope.** DORA's coverage of CASPs creates a unified EU operational-resilience perimeter for crypto firms simultaneously with their MiCA prudential authorisation, increasing the EU-establishment compliance bar for non-EU CASPs.
accredited red-team providers and is influencing the broader CBEST / CORIE / iCAST family of regulator-led penetration-testing frameworks.
hyperscalers are widely expected; treatment of co-location providers, managed-security-service providers, and SaaS firms (Salesforce, ServiceNow, Workday) is less clear.
enforcement? The Joint Oversight Forum coordinates but final supervisory authority remains divided.
Treasury / UK HMT, given that ESA inspections may extend to non-EU data centres of US-headquartered cloud providers?
ICT products embedded in financial-services technology stacks remains to be clarified by joint ESA / ENISA guidance.