DORA implementation plan
Key contacts
The Digital Operational Resilience Act ("DORA") is a European regulation aiming to enhance the digital resilience of financial entities. It focuses on minimising digital risks within the financial sector, ensuring that financial entities can withstand and recover from operational disruptions caused by cyberattacks, technical failures, or other digital threats.
Rules to improve the operational resilience of financial entities
DORA establishes rules to improve the operational resilience of financial entities. This includes managing ICT (information and communication technology) risks, ensuring service continuity, and increasing the transparency of third-party ICT service providers. The regulation requires financial entities to implement comprehensive strategies and measures for risk management and to regularly test their systems and processes.
By strengthening accountability across the supply chain, DORA aims to safeguard the overall stability of the financial system.
Adoption by the European Council and the European Parliament
DORA was officially adopted by the European Council and the European Parliament in 2022. The regulation will come into effect on 17 January 2025, following a two-year implementation period. From this date, its rules will be binding on all covered entities.
DORA applies to a broad range of financial institutions within the European Union, including:
- Managers of alternative investment funds (AIFMs);
- Investment firms;
- Banks;
- Insurance companies and reinsurers;
- Payment service providers;
- Central securities depositories;
- Crypto-asset service providers; and
- Critical ICT service providers that support the financial sector (including cloud providers).
In addition, critical ICT service providers such as cloud providers, software vendors, and data centers that deliver services to the financial sector also fall under DORA’s supervisory scope. This makes DORA unique, as it extends its reach to both financial institutions and their service providers.
DORA implementation plan for compliance
In order to comply with the comprehensive obligations arising from DORA, we have created an implementation plan for you to monitor the implementation of DORA. The implementation plan can be used as a starting point for complying with DORA, or as a final check for financial entities. Click on this link if you want to download the implementation plan.
DORA Implementation Plan
Newsletter
Sign up to receive the most relevant updates about the latest developments in the sector and participate in our upcoming (online) events.