Apply a common digital operational resilience framework across 20 categories of EU financial entities.
Strengthen the ability to prevent, withstand, respond to, and recover from ICT disruptions.
Establish processes to identify, classify, escalate, and report major ICT-related incidents in accordance with DORA’s regulatory notification and reporting requirements.
Improve ICT provider due diligence, contracting, monitoring, register-of-information maintenance, concentration-risk management, and exit planning.
Who Should Consider a DORA Assessment?
EU financial entities should assess their compliance with DORA and the applicable regulatory and implementing technical standards. Cloud providers, data centers, software providers, MSPs, MSSPs, BPOs, and other ICT providers supporting EU financial entities should assess their contractual and operational readiness to meet customer obligations under DORA. A service provider is not automatically a directly regulated CTPP; direct oversight applies only following formal designation by the European Supervisory Authorities. The ESAs published the first list of designated CTPPs on November 18, 2025, and designated providers are subject to oversight by their assigned Lead Overseers.
Governance and requirements for managing ICT risks and operational resilience.
Detection, classification, management, and reporting of major ICT-related incidents.
Proportionate risk-based testing, including vulnerability assessments and penetration testing, with advanced TLPT at least every three years for financial entities identified by the competent authority under DORA.
Due diligence, contracts, monitoring, concentration risk, and exit planning.
Voluntary exchange of cyber-threat information and intelligence.
EU oversight of designated CTPPs to address systemic and concentration risk.