
What the document says
Regulation (EU) 2022/2554, the Digital Operational Resilience Act, was adopted on 14 December 2022 and applied across the EU from 17 January 2025, according to the regulation's own text in the Official Journal. DORA covers roughly twenty categories of financial entity, from banks and insurers to investment firms and crypto-asset service providers, and, distinctively, extends direct oversight to the ICT third parties those entities depend on. EIOPA's summary describes an EU-wide oversight framework built specifically to address concentration risk where many financial firms rely on a small number of cloud and technology providers.
The regulation requires financial entities to maintain a governance framework for ICT risk with the management body bearing ultimate responsibility, to report major ICT-related incidents to competent authorities through a single reporting channel, to test digital operational resilience regularly, and, for larger systemically important entities, to undergo threat-led penetration testing. ESMA's account of the regulation notes that much of the operational detail, including incident classification thresholds, reporting templates and the criteria for designating a provider as critical, was left to regulatory and implementing technical standards that the European Supervisory Authorities developed after the regulation's adoption.
Confidence and limits
The application date, entity scope and outline requirements come directly from the regulation's own text and the supervisory authorities' summaries of it. This entry does not evaluate whether any particular financial entity or ICT provider has met its obligations, and does not attempt to enumerate the full set of technical standards, which continued to be refined after January 2025.
Why it mattered
Before DORA, oversight of a bank's technology risk mostly stopped at the bank's own boundary; its cloud or software providers answered to their customers by contract, not to a regulator directly. DORA's third-party oversight framework changes that by letting supervisors designate certain ICT providers as critical and examine them directly, a structural shift for firms whose risk model assumed vendor relationships were purely commercial matters. It also standardises how a major ICT incident gets classified and reported, replacing what had been a patchwork of national and sectoral notification rules.
Defensive takeaway
Map which of your ICT providers might be designated critical under the Union oversight framework, and verify that your incident classification process follows the European Supervisory Authorities' technical standards rather than an older, informal severity scale.
- Does your organisation fall within one of the roughly twenty financial entity categories DORA covers, or are you an ICT provider serving one?
- Can your incident reporting process meet the classification thresholds and timelines set in the regulatory technical standards, not just DORA's general text?
- Have you identified which contractual arrangements with ICT providers would need updating to meet DORA's third-party risk provisions?
DORA's application date marked a regulatory starting point rather than a finished state; the technical standards underneath it kept developing afterward, and supervisors were still building out the critical-provider oversight regime well after January 2025.
If your organisation is a financial entity operating in the EU, or a critical ICT provider serving one, confirm whether your incident classification and reporting templates match the technical standards the European Supervisory Authorities issued under DORA, not just the regulation's general text.
EUR-Lex, EIOPA and ESMA together establish the regulation's application date, scope and the technical standards developed under it. This entry does not evaluate any individual firm's or supervisor's implementation.
Sources & reading trail
Adoption date, entity scope and the ICT risk management, incident reporting and third-party oversight framework.
government-primary · Source published: 27 December 2022 · Retrieved: 16 September 2026
Application date of 17 January 2025 and the concentration-risk rationale for the ICT third-party oversight framework.
government-primary · Source published: Not established · Retrieved: 16 September 2026
The regulatory and implementing technical standards developed by the European Supervisory Authorities under DORA.
government-primary · Source published: Not established · Retrieved: 16 September 2026
Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.