The Digital Operational Resilience Act (DORA) is a comprehensive EU regulation that establishes uniform requirements for ICT risk management in the financial sector. Enacted in 2022, DORA aims to strengthen the digital resilience of financial institutions across the European Union.
Scope
Applies to financial institutions including banks, insurance companies, investment firms, and payment service providers operating in the EU.
Requirements
Mandates ICT risk management, incident reporting, digital resilience testing, and third-party risk management for financial entities.
Timeline
Compliance requirements are being phased in, with full enforcement expected by 2025 for most financial institutions.