DORA
Regulation (EU) 2022/2554, applicable since January 2025. It requires the financial sector to prove it can withstand an incident, not just say so.
What DORA is
The Digital Operational Resilience Act governs the ability of European financial entities to withstand, respond to and recover from incidents related to information and communication technology.
It is a regulation, so it applies directly with no national transposition. And it has been applicable since 17 January 2025.
Its contribution over what came before is that it unifies. Each European financial supervisor used to have its own technology risk guidance; DORA replaces them with a single regime and adds something that did not exist: direct oversight of the sector's critical technology providers.
Who DORA applies to
A wide catalogue of financial entities: credit institutions, payment institutions, electronic money institutions, investment firms, insurers and reinsurers, fund managers, crypto-asset service providers, market infrastructures and others.
And third party ICT service providers, who come in two ways. By contract, because financial entities are required to pass requirements to them. And directly, if they are designated as critical by the European Supervisory Authorities, in which case they fall under an oversight framework of their own.
If you sell software to a European bank or insurer, DORA reaches you by the first route even though you are not a financial entity.
What DORA requires
Five blocks.
ICT risk management. A governance framework with management body involvement, identification of functions and assets, protection and prevention, detection, response and recovery, continuity policies and response and recovery plans.
ICT-related incident management. A process for detection, handling and classification, and reporting of major incidents to the competent authority through an initial, intermediate and final report.
Digital operational resilience testing. A programme of periodic testing of the systems supporting critical functions. And for entities identified by their authority, threat led penetration testing, more demanding and with its own requirements on who may carry it out.
Third party ICT risk. A register of information on contractual arrangements, submitted to the competent authority. Minimum contractual clauses. Pre-contract analysis and an exit strategy.
Information sharing. Voluntary arrangements to share threat information between entities.
How DORA is demonstrated
There is no DORA certificate. It is a legal obligation supervised by each member state's competent authorities and, for critical providers, by the European Supervisory Authorities.
What gets demonstrated is the management framework, the third party information register, incident records and the results of the testing programme.
With Zerod
DORA does not ask you to say you can withstand an incident. It asks you to prove it. Zerod was born doing exactly that.
Activate DORA and Zerod gives you its control register, generates the ICT risk management framework documentation, and connects the resilience testing programme to the continuous security validation the platform already runs.
Frequently asked questions
Does DORA apply to me as a software vendor?
It can reach you by contract: financial entities are required to pass requirements to their ICT service providers. And if you are designated a critical provider by the European authorities, you come under direct oversight.
Does DORA replace NIS2?
No. For financial entities covered by DORA it acts as the specific regime against the general one, but they are separate laws with different scopes. Check which applies to you based on your sector and activity.