Back to Frameworks
Industry

DORA

The Digital Operational Resilience Act is an EU regulation, applicable from January 2025, that sets ICT risk-management requirements for banks, insurers, and other financial entities — and their critical technology vendors.

It covers ICT risk management, mandatory incident reporting, resilience testing (including threat-led penetration testing for larger entities), and direct oversight of critical third-party ICT providers, closing a gap where financial regulators previously had limited visibility into vendor risk.

See how LumiGRC handles DORA

Get a Demo
2025

In force since January

0%
Typical certification profile
Audit Rigor65%
Time to Certify60%
Surveillance Burden57%
Issued & Enforced By

European Commission

Regulation (EU) 2022/2554

Key Points

  • EU regulation for financial-sector ICT risk, in force since Jan 2025
  • Mandatory incident reporting and resilience testing
  • Direct oversight extends to critical third-party ICT vendors
  • Threat-led penetration testing required for larger entities