DORA

The EU's operational-resilience regime: five pillars from ICT risk to threat-led testing.

Conditional standard · Regulation (EU) 2022/2554 on digital operational resilience for the financial sector

Issued by

European Union

Region

European Union

Effective

In force January 2023; applies since January 2025

Oversight

European Supervisory Authorities and national competent authorities

Applies when

EU financial entities, and ICT providers serving them

In the catalog

Curated, versioned & cross-mapped

The obligation, plainly.

DORA makes digital operational resilience a directly binding EU regulation for the financial sector, built on five pillars: ICT risk management, incident classification and reporting, resilience testing up to threat-led penetration testing, ICT third-party risk with a register of information and exit strategies, and information sharing.

It reaches beyond Europe the way GDPR does: African institutions serving EU financial entities, or supplying ICT services to them, meet DORA in due diligence and contracts. Its third-party pillar effectively deputises every critical supplier into the regime.

Where programmes are tested.

01

ICT risk management

A governed framework: identification, protection, detection, response and recovery, board-owned.

02

Incident reporting

Classification, and major-incident reports to authorities on harmonised timelines.

03

Resilience testing

A testing programme scaling to threat-led penetration testing for significant entities.

04

Third-party risk

The register of information, contractual provisions, concentration analysis and exit strategies.

Curated once, evidenced continuously.

  • DORA's pillars are curated and cross-mapped to the resilience, incident and vendor control families, the same controls that carry ISO 22301 and the supervisory cyber regimes.
  • Requirements resolve to shared controls: implement a control once and it counts toward every framework it maps to.
  • Status is evidence-gated: a requirement can't be marked implemented without valid, in-date evidence behind it.
  • Every attestation carries maker/checker, and every action lands in an append-only audit trail.

DORA, asked plainly.

The questions compliance teams actually ask before an adoption decision or an audit.

Does DORA apply to companies outside the EU?

Directly it binds EU financial entities, but its third-party pillar flows the obligations down: an African ICT or fintech provider serving an EU bank will find DORA clauses in the contract, the register of information, audit rights, exit provisions. Meeting the substance is the price of the deal.

What is threat-led penetration testing?

TLPT: intelligence-driven red-team testing of live production systems, required periodically for entities designated as significant, on the TIBER-EU model. For everyone else the requirement scales down to a proportionate testing programme, but it must exist and produce evidence.

What is the register of information?

A structured register of every ICT third-party arrangement, services, criticality, locations, sub-contracting chains, that entities maintain and report to supervisors. It is DORA's most operational demand, and it is essentially the vendor module's inventory discipline made mandatory.

How does DORA relate to ISO 22301 and the cyber frameworks?

The substance overlaps heavily: continuity, incident response, testing, third-party control. What DORA adds is legal force, harmonised reporting clocks and the register. Cross-mapped, the controls you run for 22301 and the supervisory regimes carry most of DORA's weight.

Where it connects.

The full catalog
Cross-mapped with

Compliance you can prove.
Walk into your next audit ready.

Book a working demo. We'll map your obligations to the standards you're audited against and the regulators you actually answer to.

The platform, modules, catalog, audit trail and security architecture are live today; the continuous live-evidence engine is in active development, shown in a working demo. Reach us at hello@cardinalgrc.com.