DORA: Digital Operational Resilience for European Finance

Regulation & securityBy: Parsa Aghabarari2 min readSource: EIOPA
DORA: Digital Operational Resilience for European Finance

1Introduction

The Digital Operational Resilience Act, Regulation (EU) 2022/2554, applies from 17 January 2025 to banks, insurers, payment firms and many other financial entities.

2Discussion

Its pillars are ICT risk management, reporting of major incidents, regular resilience testing, third-party ICT risk management and cyber threat information sharing.

3Conclusion

A key innovation: critical ICT third-party providers, such as large cloud providers, come under direct oversight by EU financial supervisors for the first time.

Share:TelegramWhatsAppLinkedIn

Sources

  1. EIOPA — Digital Operational Resilience Act (DORA) ↗
همفکران فناوری شریفThis article summarises the official sources cited, prepared by the Hamfekran Fanavari Sharif team for finance leaders.
Want to see these solutions in your organisation?Book a free demo

Related articles

Regulation & securityDigital customer onboarding (eKYC): opening accounts without visiting a branchRemote identity verification is the gateway to digital banking; the challenge is balancing convenience with fraud resistance.Regulation & securityPCI DSS v4: card data security in the digital payments eraAny organisation storing, processing or transmitting card data faces PCI DSS; v4 introduces a more flexible, risk-based approach.Regulation & securityInformation security risk management: from assets to management decisionsAbsolute security does not exist; informed risk management targets security spending.Regulation & securityRespected cybersecurity certifications: from CISSP to OSCPProfessional certifications are the global job market’s common language; knowing each one’s role helps choose well.