What DORA - EU Digital Operational Resilience Act requires
Regulation (EU) 2022/2554 (DORA - Digital Operational Resilience Act), published December 27, 2022 and directly applicable (no national transposition required) across all EU member states from January 17, 2025, establishes binding ICT risk management, incident reporting, resilience testing, and third-party risk oversight requirements for 20+ categories of EU financial entities. DORA applies to credit institutions, investment firms, payment institutions, e-money institutions, insurance/reinsurance undertakings, crypto-asset service providers (CASPs), central counterparties (CCPs), trade repositories, AIFMs, UCITS management companies, data reporting services providers, and more. Key obligations: (1) ICT risk management framework with governance, protection, detection, response, and recovery capabilities; (2) ICT-related incident classification and mandatory reporting - initial notification within 4 hours of classification as major incident, intermediate report within 72 hours, final report within 1 month; (3) Digital operational resilience testing including Threat-Led Penetration Testing (TLPT) every 3 years for significant entities; (4) ICT third-party risk management with contractual requirements for Critical ICT Third-Party Providers (CTPPs) who are directly supervised by an EU Lead Overseer (EBA, ESMA, or EIOPA depending on sector). DORA displaces NIS2 obligations for in-scope financial entities (lex specialis principle).
Pillar: Banking & Global Finance · Authority: European Parliament and the Council of the European Union · Version: 1.1.0 · Last updated:
Primary source: https://eur-lex.europa.eu/eli/reg/2022/2554/oj
SHA-256 integrity: 8266cbd21bbbf3e980605c05f1461f5c69e889d071ff51947bb91b974e30f7c6
Primary Citations — 6 traced to source
- Regulation (EU) 2022/2554, Article 2 (Scope of application and exemptions, establishing applicability to 20+ entity types)
- Regulation (EU) 2022/2554, Article 6 (ICT risk management framework requirements)
+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/dora-ict-risk.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/dora-ict-risk.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/dora-ict-risk
- Back to registry: Browse all 10,090 compliance nodes