The Digital Operational Resilience Act is an EU regulation, applicable from January 2025, that sets ICT risk-management requirements for banks, insurers, and other financial entities — and their critical technology vendors.
It covers ICT risk management, mandatory incident reporting, resilience testing (including threat-led penetration testing for larger entities), and direct oversight of critical third-party ICT providers, closing a gap where financial regulators previously had limited visibility into vendor risk.
In force since January
European Commission
Regulation (EU) 2022/2554