Resources · DORA
The Digital Operational Resilience Act (DORA), Regulation (EU) 2022/2554, has applied since 17 Jan 2025. It covers financial entities and their ICT providers.
Step 1
The regulation works with two roles: the financial entity and the ICT third-party service provider. The obligations, and the way they are enforced, differ so much between the two that nothing else is worth reading until this is settled.
Who falls within the scope of Article 2 and who is carved out of it, how the obligations of a financial entity differ from those of a provider, what the incident reporting deadlines are and what goes into the register of information. In our own words, with links to the binding text.
Open the guide → CalculatorA walk through the list of financial entities in Article 2(1) and the exclusions in Article 2(3), ending in whether you are a financial entity, an ICT provider, or outside the scope altogether. It also tests for the simplified framework under Article 16.
Run the calculator → For providersA breakdown of the provisions a bank has to have in the contract under Article 30: audit rights, exit strategy, data locations, incident reporting, subcontractors. For every point, what it actually means for a software house and what can be negotiated.
Open the checklist →Step 2
In practice, a missed reporting deadline and a missing register of information are what shows up first — both are dated, traceable and visible to the supervisor without any on-site inspection.
Answers to the questions that keep coming back: from when DORA actually applies, when an incident is major, how the deadlines run over a weekend, whether a provider is supervised by the Czech National Bank and how DORA meets the Czech Cybersecurity Act.
Open the FAQ → DeadlinesThe materiality thresholds under Regulation 2024/1772 and the time limits tied to them under Regulation 2025/301, including the different regime for credit institutions and central counterparties, for which the weekend deferral does not apply.
Open the decision tree → Register of informationThe fifteen templates of Implementing Regulation 2024/2956 in the order in which they are filled in, with notes on the rank in the supply chain, on LEI codes and on which subcontractors go into the register and which do not.
Open the how-to →Step 3
The regulation itself runs to 64 articles and there are more than ten accompanying technical standards. The point of this group is to make all of it searchable by question rather than by article number.
A structured walk through the articles of the regulation with notes for practice, search and an anchored table of contents. It marks what applies to all financial entities, what only to the large ones and what to entities under the simplified framework.
Open the regulation → OverviewAn overview of the regulatory and implementing technical standards that supplement DORA, showing which article of the regulation each of them fleshes out and who it applies to in practice. Including the standards on subcontracting and on threat-led penetration testing.
Open the overview → Cheatsheet · financial entityA condensed two-page overview for a financial entity: the five areas, the ICT risk management framework under Article 6, reporting deadlines, the register of information, testing and the simplified framework under Article 16. Ready to print to PDF straight from the browser.
Open the summary → Cheatsheet · ICT providerWhat a financial entity has to require from you contractually under Article 30, what it means to be a critical provider and how that is decided, and what will be asked of you in an audit and for the register of information. Ready to print to PDF.
Open the summary →Where we can help
An ICT risk assessment against the framework in Article 6, an incident classification and reporting process built to hold both the four-hour and the twenty-four-hour deadline, and, on the provider side, support with security questionnaires and with the contract addenda banks send out.