Skip to main content
Regulation

Digital Operational Resilience Act (DORA)

DORA is Regulation (EU) 2022/2554. It has applied since 17 January 2025 to 20 categories of licensed financial entity, from banks to crypto-asset service providers. It requires an ICT risk management framework, major incident reporting within 4 hours of classification, an annual register of ICT contracts, and threat-led penetration testing every three years.

Checked by Remmert
5 min read

What is DORA?

DORA is Regulation (EU) 2022/2554, the Digital Operational Resilience Act. It has applied since 17 January 2025 to twenty categories of licensed financial entity, from banks to crypto-asset service providers. It requires an ICT risk management framework, reporting of major ICT incidents within four hours of classification, an annual register of ICT contracts, and threat-led penetration testing every three years.

Last updated: 17 August 2026. Checked against the Official Journal text, the Level 2 measures in force, and DNB and AFM publications.

At a glance

Who does DORA apply to?

DORA applies by licence, not by sector. Article 2(1) lists the entity types; Article 2(3) removes some of them again; Article 16 puts a defined group on a lighter framework.

Licence typeIn scopeArticleRegime

What does DORA require?

Five obligation families. Article 45 adds voluntary cyber threat information sharing.

  • Articles 17–23

    Incident classification and reporting

    Incident management process, classification against Delegated Reg. (EU) 2024/1772, the 4-hour/72-hour/1-month reporting chain, voluntary notification of significant cyber threats.

  • Articles 5–16

    ICT risk management framework

    Governance and management-body accountability, identification, protection, detection, response and recovery, backup, learning, communication, plus the Art. 16 simplified framework.

  • Articles 24–27

    Resilience testing

    General testing requirements, and threat-led penetration testing at least every three years for designated entities.

  • Articles 28–30

    Third-party ICT risk

    The register of information, concentration risk assessment, mandatory contractual provisions, subcontracting conditions under Delegated Reg. (EU) 2025/532.

  • Articles 31–44

    Oversight of critical providers

    Designation, Lead Overseer powers, joint examination teams, oversight fees.

The dates

Every row here feeds the regulatory calendar.

2025

  1. 17 January 2025Passed

    DORA applies

  2. 12 March 2025Passed

    Delegated Reg. (EU) [2025/301](https://eur-lex.europa.eu/eli/reg_del/2025/301/oj/eng) in force: incident reporting content and time limits

  3. 24 March 2025Passed

    Delegated Reg. (EU) [2025/532](https://eur-lex.europa.eu/eli/reg_del/2025/532/oj/eng) adopted: subcontracting of ICT services supporting critical functions

  4. 8 July 2025Passed

    Delegated Reg. (EU) [2025/1190](https://eur-lex.europa.eu/eli/reg_del/2025/1190/oj/eng) in force: TLPT

  5. 18 November 2025Passed

    First 19 critical ICT third-party providers designated

2026

  1. 2–20 March 2026Passed

    DNB register of information window, reference date 31 December 2025

  2. 31 March 2026Passed

    AFM register of information deadline, same reference date

  3. April 2026Passed

    EBA additional data-quality checks on forms B_01.02 and B_05.01

2027

  1. February–March 2027Expected

    Next register of information cycle, reference date expected 31 December 2026

No fixed date

  1. RollingRecurring

    TLPT at least every three years for entities notified by DNB or AFM

The incident reporting clock

ReportDeadline

Differences by country

TopicNetherlandsGermanyBelgiumIreland

Two Dutch specifics worth calendaring separately

The DNB and AFM register deadlines are eleven days apart. Same reference date, different portals, different formats: DNB accepts xBRL-CSV or an Excel template it converts; the AFM accepts zipped xBRL-CSV only. A group supervised by both files twice and should calendar the earlier date.

The DNB Good Practice Informatiebeveiliging 2023 no longer applies to entities in DORA scope. DNB confirmed it is replaced from 17 January 2025 and that it will not publish an updated version, on the basis that a regulation takes precedence over guidelines and opinions. DNB also said its supervisory methods would not change drastically. The withdrawn Good Practice therefore remains a fair indicator of what DNB expects, even though it is no longer the applicable norm.

What recently changed

18 November 2025: the first critical ICT third-party providers are designated. The ESAs named 19 providers under Article 31 after a process that ran from April to November 2025, including a six-week window in which each provider could make a reasoned statement. The EBA is Lead Overseer for all nineteen.

2026: oversight moves from designation to examination. Joint examination teams were established through end-2025, annual oversight plans were drawn up per provider, initial examination activities are running during 2026, and oversight fee collection has begun.

March 2026: the register of information becomes a real annual report. The reference date moved from 31 March 2025, which was a one-off designation-driven collection, to 31 December 2025 with fixed national windows. In April 2026 the EBA layered additional data-quality checks on the consolidation-structure and ICT-provider forms, on top of the standard validation rules, a direct response to first-cycle data quality.

13 April 2026: DNB changes how incident reports are processed. Reports are now technically validated on submission and return either warnings, correctable in a later report, or errors, which require correction and resubmission through MijnDNB.

11 June 2026: the first published Dutch supervisory findings. The AFM examined ICT risk management at trading venues and found gap analyses were "often too global", leaving requirements unaddressed; that security monitoring, access control, logging, emergency changes and continuity management needed work; that policies and procedures were not clearly distinguished; and that DORA policies were applied inconsistently to intragroup ICT services. The AFM's position: the foundation is generally present, but assessments must be more detailed and periodic, and controls must be demonstrated in operation, not only in documents.

DORA was not touched by the Digital Omnibus. The November 2025 package and the Commission's proposal of 20 January 2026, COM(2026) 13 final, amend the NIS2 Directive, not DORA. As at 17 August 2026 no legislative proposal amending Regulation (EU) 2022/2554 had been tabled. The only live review is the narrow Article 58(3) question of whether statutory auditors should be brought into a strengthened resilience regime, consulted from 7 November 2025 to 17 January 2026.

What can GenCompl.ai do for you?

Our pipeline monitors the DORA Level 2 measures, the ESAs' annual critical-provider designations and the DNB and AFM reporting windows, and re-derives which obligations attach to a given entity when its own facts change: a new licence, a new German branch, a new ICT contract supporting a critical function.

Each conclusion carries the article it came from, the source and the date it was last recalculated. Deterministic where it has to be, AI where it may be, and you can see which part is which.

If you want to check applicability before talking to anyone, the scope check answers it in a few questions, with the article behind each conclusion.

Questions and answers

Does DORA apply to my Dutch pension fund if it has 80 members?
What is the actual deadline for the first incident report: 4 hours or 24 hours?
Our deadline falls on a Sunday. Can we file on Monday?
Do we report a major ICT incident only to DNB?
We are supervised by both DNB and AFM. Do we file one register of information or two?
Our cloud provider is not on the ESAs' critical provider list. Does that make it low risk?
The subcontracting RTS was rejected in January 2025. Do we still have to comply with it?
Is DORA going to be watered down by the EU's simplification agenda?
What are Dutch supervisors actually finding when they inspect DORA compliance?

Glossary

  • Competent authority (DORA)

    The national or European regulatory body designated under sectoral legislation or DORA to supervise compliance by financial entities. MiCA defines the same term differently.

  • Cyber threat (DORA)

    A potential circumstance, event, or action capable of damaging, disrupting, or otherwise adversely affecting network and information systems, users, or other individuals. The Cyber Resilience Act defines the same term differently.

  • Vulnerability (DORA)

    A flaw, weakness, or design error in an ICT asset or system that can be leveraged or exploited by a cyber threat. The Cyber Resilience Act defines the same term differently.

  • Information-sharing arrangement

    A voluntary agreement between financial entities and trusted partners to exchange cyber threat intelligence, indicators of compromise (IoCs), and defense techniques.

  • Concentration risk

    Operational and systemic exposure arising from dependence on a single ICT third-party service provider or a small group of non-substitutable providers.

  • Joint Examination Team

    A multidisciplinary team of examiners established by the Lead Overseer to coordinate and execute oversight activities and on-site inspections for critical ICT third-party providers.

  • Lead Overseer

    The European Supervisory Authority (EBA, ESMA, or EIOPA) designated to conduct direct regulatory oversight of a designated critical ICT third-party service provider.

  • ICT services

    Digital and data services provided via ICT systems to one or more internal or external users on an ongoing basis (including hardware-as-a-service, cloud computing, and data storage).

  • ICT intra-group service provider

    An entity within a financial group that provides ICT services primarily or exclusively to financial entities in the same group.

  • Critical ICT third-party service provider

    An ICT third-party provider designated as systemically critical by European Supervisory Authorities (ESAs) based on cross-border reliance, substitutability, and systemic relevance.