DORA - Improving digital operational resilience against cyberattacks
Official name
REGULATION (EU) 2022/2554 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011 (COM(2020)0595 – C9-0304/2020 – 2020/0266(COD))
Level 1
Doc. code
Get a subscription to have access to the whole content.
Current version
Final version
Next step
Entry into force and application
Entry into force
Get a subscription to have access to the whole content.
Application date
Get a subscription to have access to the whole content.
Relevant for
Get a subscription to have access to the whole content.
Associated initiatives
Level 1
DORA Directive
(binding, Amendment, EU)
Regulation on a framework for Financial Data Access (Open Finance - FIDA)
(binding, Main version, Amendment, EU)
Lag med kompletterande bestämmelser till DORA (Act with supplementary provisions to DORA)
(binding, Main version, Amendment, SE)
Financial Market Digitization Act - FinmadiG
(binding, Amendment, DE)
DORA Enforcement Act
(binding, Main version, Amendment, AT)
Level 2
Finansinspektionens föreslår föreskrifter och allmänna råd om insättningssystem (general guidelines on deposit schemes)
(binding, Main version, SE)
Regulation amending the Credit Institutions Risk Management Regulation
(binding, Amendment, AT)
Regulation amending the Investment Firms Audit Report Regulation and the Crowdfunding Service Provider Audit Regulation
(binding, Amendment, DE)
Förordning med kompletterande bestämmelser till DORA (Regulation laying down supplementary provisions to DORA)
(binding, Supplement, SE)
RTS on ICT risk management tools methods processes and policies (DORA package 1)
(binding, Supplement, EU)
RTS on criteria for the classification of ICT related incidents (DORA package 1)
(binding, Supplement, EU)
ITS on the register of information on the use of ICT third-party services (DORA package 1)
(binding, Supplement, EU)
RTS on the policy on the use of ICT third-party services supporting critical or important functions (DORA package 1)
(binding, Supplement, EU)
Specification of the criteria for desgnation of ICT third-party service providers as critical for financial entities
(binding, Supplement, EU)
Amount of the oversight fees to be charged by the Lead Overseer to critical ICT third-party service providers
(binding, Supplement, EU)
Guidelines on aggregated costs and losses from major ICT-related incidents (DORA package 2)
(binding, Supplement, EU)
RTS on subcontracting of critical or important functions including outsourcing management (DORA package 2)
(binding, Supplement, EU)
RTS on oversight harmonisation under DORA (DORA package 2)
(binding, Supplement, EU)
RTS on threat-led penetration testing (TLPT) (DORA package 2)
(binding, Supplement, EU)
RTS for the content of notifications and reports on major ICT incidents under DORA (DORA package 2)
(binding, Supplement, EU)
Implementation decision digital operational resilience financial sector (Uitvoeringsbesluit verordening digitale operationele weerbaarheid)
(binding, Amendment, NL)
Level 3 / Other
Digital Finance Package
(non-binding, EU)
Criteria for critical ICT third-party service providers and oversight fees under DORA
(non-binding, Amendment, EU)
ESAs Report on the landscape of ICT third-party providers
(non-binding, EU)
FMA information letter regarding supervision of crypto asset service providers pursuant to MiCAR
(binding, AT)
EIOPA opinion on the scope of DORA in light of the review of the Solvency II framework
(non-binding, EU)
Feasibility for further centralisation of reporting of major ICT-related incidents
(non-binding, EU)
BaFin plausibility checks for DORA ICT incident reporting
(binding, Supplement, DE)
Guidance on operational continuity in resolution
(binding, EU)
Information register concerning critical third-party ICT service providers according to DORA
(binding, NL)
Tiber EU-Framework
(non-binding, EU)
Guidelines on the oversight cooperation and information exchange between the ESAs and the competent authorities (DORA package 2)
(binding, Supplement, EU)
Report on operational policy tools for cyber resilience
(non-binding, EU)
EBA - FINAL Q&A: DORA - Other DORA topics
(binding, Supplement, EU)
Notes on the implementation of DORA in ICT risk management and ICT third-party risk management
(non-binding, DE)
ESAs opinion on the rejection of the ITS on the register of information under DORA
(non-binding, EU)
ESMA - Q&A: Digital Operational Resilience Act (DORA)
(binding, EU)
Source: EU, 2022/2554, 2022