Regulations library · European Union

DORA

Digital Operational Resilience Act, Regulation (EU) 2022/2554

In force European Union security financial third party

ICT risk management, incident reporting, resilience testing and a register of ICT third-party arrangements for the financial sector.

At a glance

Who it applies to
EU financial entities and their critical ICT third-party providers.
Who enforces it
European and national financial supervisors
When
In effect since 17 January 2025.

This is a reference entry. The priority laws get a full practical guide first.

Recent developments

Nothing reported yet. Regulatory Watch lists new rules, enforcement and court decisions as they arrive.

Sources

Dates and status are from the association's inventory and are being checked against primary sources. This page explains the law for practitioners; it is not legal advice.