Regulation (EU) 2024/1023 on digital operational resilience for the financial sector (DORA)

Overview

The Digital Operational Resilience Act (DORA) establishes a comprehensive framework for ICT risk management in the EU financial sector. It requires financial entities to manage ICT risk through incident management, digital operational resilience testing, and third-party risk management. DORA introduces an oversight framework for critical ICT third-party service providers (notably cloud providers), establishes information-sharing arrangements, and mandates incident reporting to competent authorities. The regulation covers all financial entities including banks, insurers, and investment firms. Regulation (EU) 2024/1023 applies from 17 January 2025.

This eu regulation (32024R1023) is part of the EU’s legal framework governing financial technology. EU financial technology regulation addresses digital operational resilience in the financial sector, establishing requirements for ICT risk management and incident reporting.

Type: EU Regulation

CELEX Number: 32024R1023

Date of Effect: See the official publication in the Official Journal of the European Union.

Key Provisions

Regulation (EU) 2024/1023 on digital operational resilience for the financial sector (DORA) establishes the core legal framework in this field. For specific provisions, articles, and implementing measures, consult the full text on EUR-Lex.

Significance

This legislation represents a key component of EU law in the area of financial technology. It reflects the EU’s approach to harmonization and regulatory policy within the internal market framework.