DORA — Digital Operational Resilience Act
Category: regulation Maturity: mature (binding since January 2025) First seen: 2026-03-17 Last updated: 2026-06-09
What it is
The EU’s Digital Operational Resilience Act — Regulation (EU) 2022/2554. Binding regulation for EU financial entities setting ICT risk management, ICT-related incident reporting, digital operational resilience testing, ICT third-party risk management, and information-sharing obligations. Establishes the Critical ICT Third-Party Provider (CTPP) designation regime.
How it’s used
- Named demand driver for Paul’s practice positioning [S-2026-03-17-paul-positioning].
- Cited by EBA as a reason for revising Internal Governance Guidelines under CRD — tightens board oversight, ICT / third-party risk and internal governance [S-2025-11-eba-ai-act-mapping].
- Aligned with BCBS d605 third-party risk principles, finalised 10 December 2025 [S-2025-12-10-bcbs-d605].
- Paul’s AI Assurance Pathway names the AI Contract Clause Library (DORA Art 30 + AI Act Arts 25, 53) as a core practitioner artefact for AI vendor contracts [S-2026-05-06-paul-ai-data-pathway].
- A Phase 2 evidence pack — DORA evidence pack (ICT risk management and third-party governance sections) — sits under Service Line — Regulatory Readiness and Evidence [S-2026-03-17-paul-practice-build-plan].
- UK joint Policy Statement 2 on operational incident and third-party reporting interacts with DORA’s parallel obligations for cross-border firms; comes into force 18 March 2027 [S-2026-03-fca-ps26-2].
- DORA’s incident-reporting mechanism produced its first sector-wide dataset in the ESAs’ first annual major-ICT-incident report (3 June 2026, Article 22(2) mandate): 3,383 major incidents (0.18 per entity), ~one third cross-border, system failures/external events the main drivers, ~10% cyber — the first hard evidence of DORA’s harmonised reporting regime in operation [S-2026-06-03-esas-dora-incident-report].
- The ESAs published “DORA Incident Reporting – Operational Instructions” (16 September 2026) — best-efforts, regularly-updated staff guidance (not legal interpretation or official ESA stance, agreed with competent authorities) to improve data quality and cross-jurisdiction consistency in major-ICT-incident reporting under ITS 2025/302 and RTS 2025/301 / 2024/1772. It gives 14 field-level conventions (English CA→ESA templates; monetary fields in thousands; monthly intermediate reports and a one-month final-report deadline; immutable unique incident IDs; always flagging “critical services affected”; excluding the home country from geographical spread; standardised LEI/EUID TPP-origin formatting) — sharpening the machine-readable evidence base of the reporting regime [S-2026-09-16-eba-dora-incident-reporting-operational-instructions].
Theoretical basis
- maps-to → EU AI Act — deployer third-party obligations overlap with DORA.
- relates-to → Operational Resilience and Third Party Risk — DORA is a core regime in this Topic page.
- relates-to → BCBS AI Governance Framework — d605 alignment.
- relates-to → Critical Third Parties regime — UK parallel.
Strengths / weaknesses
Not synthesised — corpus references DORA as an obligation backbone but does not surface strengths / weaknesses analysis. To be added when a critical source arrives.
Tensions
None surfaced.