Resources · DORA

DIGITAL OPERATIONAL RESILIENCE

The Digital Operational Resilience Act (DORA), Regulation (EU) 2022/2554, has applied since 17 Jan 2025. It covers financial entities and their ICT providers.

Step 1

Work out which side of DORA you are on

The regulation works with two roles: the financial entity and the ICT third-party service provider. The obligations, and the way they are enforced, differ so much between the two that nothing else is worth reading until this is settled.

Guide · 15 min read

Guide to the DORA Regulation

Who falls within the scope of Article 2 and who is carved out of it, how the obligations of a financial entity differ from those of a provider, what the incident reporting deadlines are and what goes into the register of information. In our own words, with links to the binding text.

Open the guide →
Calculator

Does DORA apply to you?

A walk through the list of financial entities in Article 2(1) and the exclusions in Article 2(3), ending in whether you are a financial entity, an ICT provider, or outside the scope altogether. It also tests for the simplified framework under Article 16.

Run the calculator →
For providers

A bank has sent you a contract addendum

A breakdown of the provisions a bank has to have in the contract under Article 30: audit rights, exit strategy, data locations, incident reporting, subcontractors. For every point, what it actually means for a software house and what can be negotiated.

Open the checklist →

Step 2

Start with the obligations that get checked first

In practice, a missed reporting deadline and a missing register of information are what shows up first — both are dated, traceable and visible to the supervisor without any on-site inspection.

FAQ · common questions

FAQ on the DORA Regulation

Answers to the questions that keep coming back: from when DORA actually applies, when an incident is major, how the deadlines run over a weekend, whether a provider is supervised by the Czech National Bank and how DORA meets the Czech Cybersecurity Act.

Open the FAQ →
Deadlines

Incident classification and reporting deadlines

The materiality thresholds under Regulation 2024/1772 and the time limits tied to them under Regulation 2025/301, including the different regime for credit institutions and central counterparties, for which the weekend deferral does not apply.

Open the decision tree →
Register of information

The register of information step by step

The fifteen templates of Implementing Regulation 2024/2956 in the order in which they are filled in, with notes on the rank in the supply chain, on LEI codes and on which subcontractors go into the register and which do not.

Open the how-to →

Step 3

The legal text and the accompanying standards

The regulation itself runs to 64 articles and there are more than ten accompanying technical standards. The point of this group is to make all of it searchable by question rather than by article number.

Regulation

Regulation (EU) 2022/2554 interactive

A structured walk through the articles of the regulation with notes for practice, search and an anchored table of contents. It marks what applies to all financial entities, what only to the large ones and what to entities under the simplified framework.

Open the regulation →
Overview

The RTS and ITS accompanying DORA

An overview of the regulatory and implementing technical standards that supplement DORA, showing which article of the regulation each of them fleshes out and who it applies to in practice. Including the standards on subcontracting and on threat-led penetration testing.

Open the overview →
Cheatsheet · financial entity

DORA summary to print

A condensed two-page overview for a financial entity: the five areas, the ICT risk management framework under Article 6, reporting deadlines, the register of information, testing and the simplified framework under Article 16. Ready to print to PDF straight from the browser.

Open the summary →
Cheatsheet · ICT provider

DORA summary for providers

What a financial entity has to require from you contractually under Article 30, what it means to be a critical provider and how that is decided, and what will be asked of you in an audit and for the register of information. Ready to print to PDF.

Open the summary →
Content valid as of 8 August 2026

Where we can help

ICT risk and resilience,
not just documentation.

An ICT risk assessment against the framework in Article 6, an incident classification and reporting process built to hold both the four-hour and the twenty-four-hour deadline, and, on the provider side, support with security questionnaires and with the contract addenda banks send out.