IT, data & continuous

Digital Operational Resilience Act

DORA is the EU regulation that entered into force on 17 January 2025, requiring financial institutions to establish robust ICT risk management frameworks to withstand and recover from cyberattacks, IT failures and operational disruptions. The regulation applies to approximately 20 types of financial entities, including banks, insurers, investment firms and crypto-asset service providers, and mandates comprehensive monitoring, testing and reporting of ICT systems.

Source: EU DORA (Digital Operational Resilience Act, 2025)

← All terms