The Digital Operational Resilience Act — Regulation (EU) 2022/2554, DORA — applies from 17 January 2025 to almost every regulated financial entity in the EU: credit institutions, payment and e-money institutions, crypto-asset service providers, investment firms, fund managers, creditors under several regimes and more. It sets one standard for ICT risk management and one register of ICT third-party arrangements. This guide explains what DORA requires, how proportionality works for smaller firms, and what our DORA services deliver.
The guide is general information, not legal advice.
The five pillars of DORA
- ICT risk management framework (Articles 5–16) — governance by the management body, a documented framework, identification and protection of ICT assets, detection, response and recovery, backup policies, learning and communication. A simplified framework applies to certain small entities (Article 16).
- ICT-related incident management and reporting (Articles 17–23) — classification of incidents and major incident reporting to the competent authority on fixed deadlines.
- Digital operational resilience testing (Articles 24–27) — a testing programme proportionate to the entity; threat-led penetration testing only for entities designated by the authority.
- ICT third-party risk (Articles 28–30) — a strategy, due diligence before contracting, mandatory contract clauses, exit plans, and the register of information on all ICT third-party arrangements (Article 28(3)), submitted to the authority annually.
- Information sharing (Article 45) — voluntary arrangements on cyber threat intelligence.
Proportionality
DORA applies to large and small firms, but the depth of the framework follows the entity's size, risk profile and the nature of its services (Article 4). A small payment institution does not need the tooling of a bank — but it needs every required document, an owner for each process and evidence that it works.
Our DORA services
- DORA ICT risk management framework and tooling — : gap analysis, the framework and policies, incident classification and reporting procedure, testing programme, third-party risk policy with contract clause checklist, and the first register of information;
- DORA register of information — annual update — : updating the register in the ITS template and supporting its submission each year.
DORA-aligned ICT documents are also part of a MiCA application and of payment and e-money institution applications; ordering DORA together with the licence avoids writing the same documents twice. See also compliance audits.
What you receive
- a DORA framework proportionate to your firm, with owners and evidence;
- the register of information in the required format;
- where ordered, the annual update of the register.
Prices are starting prices confirmed in a written quote and exclude VAT. All communication takes place by email.
Ready to start? Choose the DORA framework or the annual register update. Open the quote form.
Frequently asked questions
Does DORA apply to small payment institutions and crypto firms?
Yes. DORA applies from 17 January 2025 to payment and e-money institutions, crypto-asset service providers, fund managers and most other regulated financial entities. The depth of the framework follows the entity's size and risk profile (proportionality), but the required elements apply to all.
Related guides
- Banking and payment partners for fintechs
- Compliance audit for regulated firms
- Supervisory reporting after authorisation
More on this topic: Compliance services.