Have you heard about DORA recently?
The Digital Operational Resilience Act (Regulation 2022/2554 on the digital operational resilience of the financial sector) or, also known by its acronym: “DORA” is a European Union regulation that has the overall purpose of improving operational resilience and cybersecurity in the financial sector, and in particular, to mitigate information and communication technology (ICT)-related risks.
Who does DORA apply to?
Broadly speaking, DORA applies to entities in the financial sector of the European Union, among which we find:
· Banks (both commercial and investment banks),
· Insurance companies,
· Fund managers,
· Securities companies (brokerage and trading of securities),
· Trading platforms (those that facilitate the purchase and sale of financial instruments),
· Providers of securities clearing and settlement services,
· Credit rating agencies.
And attention:
DORA also applies to critical ICT service providers (such as cloud service providers) that are deemed essential by the regulator following a formal process, although this designation will depend on factors such as (i) the systemic impact that a disruption to the ICT provider’s services would have and (ii) the systemic importance of the financial institutions that rely on those services.
What are the main requirements and obligations imposed by DORA?
DORA establishes requirements and obligations that concern:
• ICT risk management,
• The notification of incidents,
• Operational resilience testing,
• The establishment of cyber threat sharing agreements, and
• Monitoring the supply chain risk of financial institutions.
In addition, DORA has been strengthened through two regulatory packages:
– The first package became effective on July 15 and consists of the following Delegated Regulations:
o Delegated Regulation (EU) 2024/1772, which establishes regulatory technical standards specifying the criteria for the classification of ICT-related incidents and cyber threats, sets materiality thresholds and specifies the detailed reporting of serious incident notifications
o Delegated Regulation (EU) 2024/1773, introducing regulatory technical standards specifying the detailed content of the policy regarding contractual arrangements on the use of ICT services supporting essential or important functions provided by third-party ICT service providers
o Delegated Regulation (EU) 2024/1774, which introduces regulatory technical standards specifying ICT-related risk management tools, methods, processes and policies and the simplified ICT-related risk management framework.
– The second package, also composed of Delegated Regulations whose drafts were published last July 17 by the European Supervisory Authorities (ESAs), establishes technical standards addressing issues such as major incident reporting, threat-based penetration testing, as well as outsourcing of ICT services with essential or important functions and monitoring of ICT service providers, among others.
What deadlines should you be aware of if DORA applies to you?
Key milestones and dates are as follows:
• Entry into force: DORA entered into force on January 16, 2023.
• Implementation period: financial sector entities subject to the regulations have a two (2) year implementation period to comply with the requirements imposed by DORA: from January 17, 2023 to January 16, 2025.
• Commencement of the compliance period: financial sector entities must comply with the requirements set forth in the DORA regulation as of January 17, 2025, and the supervisory authorities will begin their activities.
If you want to know more about DORA, do not hesitate to contact us, our ITIP team can provide you with detailed guidance on how DORA could affect you as an entity operating in the financial sector and accompany you in the strategies that will allow you to comply with the requirements of this new regulation.




