EU regulation · financial ICT resilience

DORA

The Digital Operational Resilience Act (Regulation 2022/2554) applies across the EU financial sector and has been in force since January 2025. As a regulation it applies directly, without national transposition.

Who it applies to

Banks, insurers, investment firms, and payment and crypto-asset service providers
Critical ICT third-party providers serving the financial sector
In force across the EU since January 2025
What it requires

The obligations, clearly explained.

01
ICT risk management
A documented framework for identifying, protecting against, detecting, and recovering from ICT risk.
02
Incident reporting
Classification of major ICT incidents and reporting to the competent regulator.
03
Resilience testing
A digital resilience testing program, including threat-led penetration testing (TLPT) for significant entities.
04
Third-party risk
Oversight of ICT providers, including contractual requirements and concentration risk management.
How Raptoric helps

We do the engineering work, not just the documentation.

Threat-led testing
We run TLPT-style engagements that validate resilience against the regulation's requirements.
ICT risk assessment
We assess and document your ICT risk framework against the requirements of DORA.
Resilience testing
We test detection and response in the context of your incident reporting obligations.
Third-party review
We assess the ICT providers your operational risk depends on.
We deliver the testing and the evidence. Compliance is overseen by your national regulator and the European supervisory authorities.
FAQ

Questions, answered

Who does DORA apply to?
Banks, insurers, investment firms, payment and crypto-asset service providers, and their critical ICT providers across the EU. DORA is a regulation and applies directly, without national transposition.
Is DORA already in force?
Yes, it has applied since January 2025. Entities in scope that are not yet aligned are exposed to regulatory risk and should complete the alignment without delay.
What does DORA require around testing?
ICT risk management, incident reporting, and digital resilience testing, including threat-led penetration testing (TLPT) for significant entities. We run the testing and prepare the evidence.
Does DORA cover our third parties?
Yes. ICT third-party risk management is one of the regulation's core requirements. We assess the providers your operational risk depends on.

Need to be ready for DORA?

Our team will define the scope of work with you on a 30-minute call.
Book a scoping call or email contact@raptoric.com