The Digital Operational Resilience Act (DORA) is now in force as of 16 January 2023 and will apply from 17 January 2025. DORA requires financial entities to strengthen their information and communication technology (ICT) security and manage ICT risks effectively.
DORA is established under Regulation (EU) 2022/2554, which sets forth requirements for ICT risk management and oversight of critical third-party ICT service providers.
DORA applies to 21 different types of financial entities, including banks, investment firms, and payment institutions, as identified by the European Supervisory Authorities (ESAs).
Entities must prepare their internal ICT risk management frameworks and ensure oversight of third-party ICT service providers before the regulation takes effect on 17 January 2025.