DORA
DORA: Digital Operational Resilience Act (Regulation (EU) 2022/2554)
DORA is an EU regulation requiring financial entities to withstand and recover from ICT disruptions. It applies from January 2025.
Last verified Jul 17, 2026
Q&A
What is DORA?
DORA is an EU regulation requiring financial entities to withstand and recover from ICT disruptions. It applies from January 2025.
Who needs DORA?
EU financial entities: banks, insurers, investment firms, payment and e-money institutions, crypto-asset service providers, and more, plus the critical ICT third-party providers, including cloud and software vendors, that support them.
How long does DORA take?
DORA compliance is continuous. Resilience testing is performed on a regular basis, with advanced threat-led penetration testing required periodically for entities in scope for it.
How much does a DORA audit cost?
Costs depend on entity size and testing obligations. Threat-led penetration testing and third-party risk programs are significant line items for larger entities; smaller entities face proportionate requirements.
What does a DORA audit cover?
Assessment covers ICT risk management, incident reporting, resilience testing, and ICT third-party risk against DORA and its regulatory technical standards. Advanced testing may include threat-led penetration testing by qualified providers.
What it is
The Digital Operational Resilience Act sets uniform requirements for the security and resilience of the information and communication technology (ICT) that supports the EU financial sector. It has applied since 17 January 2025 and covers a broad range of financial entities as well as the critical ICT third-party providers that serve them.
DORA is built on several pillars: ICT risk management, incident reporting, digital operational resilience testing, and management of ICT third-party risk. For the most significant entities, testing includes threat-led penetration testing (TLPT) carried out by qualified testers.
Because it is a regulation with direct effect, DORA's requirements are consistent across member states, though supervision is shared between the European Supervisory Authorities and national competent authorities. The goal is demonstrable operational resilience, not a one-off certificate.
EU financial entities: banks, insurers, investment firms, payment and e-money institutions, crypto-asset service providers, and more, plus the critical ICT third-party providers, including cloud and software vendors, that support them.
Assessment covers ICT risk management, incident reporting, resilience testing, and ICT third-party risk against DORA and its regulatory technical standards. Advanced testing may include threat-led penetration testing by qualified providers.
DORA compliance is continuous. Resilience testing is performed on a regular basis, with advanced threat-led penetration testing required periodically for entities in scope for it.
Costs depend on entity size and testing obligations. Threat-led penetration testing and third-party risk programs are significant line items for larger entities; smaller entities face proportionate requirements.
Choose assessors with financial-sector ICT risk expertise and familiarity with DORA's regulatory technical standards. For threat-led penetration testing, testers must meet the qualification requirements set out under the TLPT framework.
Service pathways
Not every service under this framework is fully available today. Hover a pathway for context.
- Not yet operationalFormal DORA certificationDORA has no certification scheme. Article 6(6) requires internal audit of the ICT risk management framework instead.
- AvailableInternal audit of ICT risk framework (Art. 6(6))
- AvailableRegister of Information (RoI) preparation and submission
- AvailableThreat-Led Penetration Testing (TIBER-EU)TLPT must be performed by testers qualified under the TIBER-EU framework specifically, a narrow and specialized pool distinct from general penetration testers.