DORAFree Resource

EU Digital Operational Resilience Act Scope and implementation hub

DORA has applied since 17 January 2025. Start with the Article 2 legal-entity test, then route each in-scope entity into the ICT risk, incident, testing, and third-party work that applies to it.

By Sorena AIUpdated 2026-07Based on official sources
Quick scan
DORA
Scope and proportionality
DORA's financial-entity duties cover listed categories such as credit institutions, payment and e-money institutions, investment firms, crypto-asset service providers, market infrastructures, insurers, IORPs, credit rating agencies, crowdfunding providers, and securitisation repositories. Specific Article 2 exclusions apply, while Article 16 places certain smaller or sectorally exempt entities under a simplified ICT risk management framework. ICT third-party service providers have a different role: financial entities manage the dependency, while providers designated as critical enter Union-level oversight.
Operational resilience duties
The core program is not one control. It combines management-body governance, a documented ICT risk management framework, identification of ICT-supported functions and assets, incident management and reporting, testing, communication, learning, and continuous improvement.
Third-party and register work
Financial entities must manage ICT third-party risk as part of ICT risk, maintain a for ICT service contracts, distinguish critical or important functions, assess concentration and subcontracting risk, and keep exit strategies for ICT services supporting critical or important functions.

Use the topic guides to move from scope classification to concrete work: controls, incident templates, readiness, provider registers, contract clauses, oversight implications, and retained evidence.

Key dates
2022/2554
Regulation
17 Jan 2025
Applies
Art. 28
Register
TLPT
Testing
DORA questions this hub helps resolve
Who is in scope
Check whether the organization is a , an excluded entity, or an ICT third-party service provider that may be relevant through contracts or critical-provider oversight.
Which workstream owns the issue
Separate governance and ICT risk management from incident reporting, resilience testing, , third-party risk, register-of-information reporting, and oversight of designated critical ICT providers. DORA and its applicable delegated and implementing regulations are binding EU law; voluntary standards and common control frameworks can support evidence, but they do not replace the legal tests.
What evidence should exist
Connect policies, asset and function inventories, incident records, testing results, attestations, contract clauses, exit plans, LEI/EUID provider identifiers, and register templates to the same operational resilience file.
ICT risk framework
Incident reporting
Register of information
TLPT readiness
Publication details
Editorial metadata for this artifact
Author
Sorena AI
Published
Feb 23, 2026
Updated
Jul 25, 2026

Check exclusions and the separately. A lighter framework changes some Chapter II duties; it does not make the entity generally exempt from DORA.

DORA Timeline

Key dates for DORA implementation

Track DORA publication, entry into force, the 17 January 2025 application date, Level 2 technical standards, register-of-information templates, incident reporting forms, criteria, and critical ICT third-party provider oversight milestones.

Loading timeline...
Recommended DORA path

Choose the next operational resilience decision

Start by confirming the legal entity, DORA role, exclusions, proportionality and critical functions. Then move to the workstream you own: ICT risk, incidents, testing, third-party dependencies, reporting dates, enforcement or framework overlap.

1

Start here: scope, roles, and critical functions

Name the regulated legal entity and provider relationship, test exclusions and proportionality, and identify the functions whose disruption would materially impair regulated performance or continuity.

2

Governance, ICT risk, and evidence

Translate management-body accountability and the ICT risk framework into owned controls, retrievable records, remediation decisions, and an operating compliance baseline.

3

Incident classification and reporting

Apply the binding classification thresholds, preserve the decision record, and run the initial, intermediate, and final reporting clocks with the official forms and procedures.

4

Resilience testing and TLPT

Separate the general risk-based testing programme from threat-led penetration testing for entities identified by competent authorities, then retain scope, test, remediation, and attestation evidence.

5

ICT third parties, contracts, and the register

Connect critical-function dependencies to due diligence, concentration and subcontracting risk, Article 30 contract rights, exit planning, and the linked register-of-information templates.

DORA ICT third-party risk and contract clauses guide
Official source DORA guide for financial entities in scope, ICT third-party risk, contract clauses, subcontracting controls, register evidence, audit rights, exit planning, and oversight.
Read guide
EU DORA ICT subcontracting chain controls for critical functions
DORA guide to ICT subcontracting chains for critical or important functions: prior assessment, contract conditions, register fields, monitoring, exit rights, and evidence.
Read guide
DORA ICT Third-Party Contract Remediation Workflow
A DORA workflow for remediating ICT third-party contracts covering critical or important functions, subcontracting, audit rights, exits, register updates, and evidence.
Read guide
DORA Register of Information Template: ICT Provider Fields and Evidence
An official source DORA register of information template for ICT third-party contracts, provider hierarchy, critical functions, dates, statuses, reporting, and evidence.
Read guide
EU DORA Register of Information Data Model: templates, fields, and evidence
Field-level guide to the EU DORA register of information data model: templates B_01 to B_07, provider identifiers, contract links, subcontracting chains, critical-function assessments, dates, and export evidence.
Read guide
How to build a DORA register of information
Build a DORA register of information from contracts, ICT services, providers, functions, subcontractors, risk assessments, audit evidence, exit plans, and export checks.
Read guide
DORA Register of Information Import and Build Workflow
Build a DORA register of information from procurement, vendor, contract, service, function, and subcontractor data using the official register templates and validation checks.
Read guide
7

Compare regimes or answer a focused question

See what DORA changes alongside NIS2, PSD2 reporting, EBA outsourcing guidance, ISO/IEC 27001, and ISO 22301, or use the FAQ for direct scope and implementation answers.

DORA vs NIS2: financial-sector obligations, overlap, and evidence
Compare DORA and NIS2 for financial entities, ICT providers, incident reporting, management accountability, third-party risk, supervisory routes, and reusable evidence.
Read guide
DORA vs PSD2 incident reporting: major ICT and payment incidents
Compare DORA major ICT-related incident reporting with PSD2 major operational or security payment incident reporting, including scope, triggers, report stages, recipients, and evidence.
Read guide
DORA vs EBA outsourcing guidelines: ICT third-party risk comparison
Compare binding DORA ICT third-party risk duties with the EBA outsourcing baseline for registers, critical functions, contracts, subcontracting, exit, incident reporting, and evidence.
Read guide
DORA vs ISO/IEC 27001: legal ICT resilience obligations and ISMS controls
Compare EU DORA and ISO/IEC 27001 across scope, governance, incident reporting, testing, ICT third-party risk, certification, evidence, overlap, and gaps.
Read guide
DORA vs ISO 22301: ICT resilience and business continuity compared
Compare DORA's binding ICT operational resilience duties for financial entities with ISO 22301's business continuity management system requirements.
Read guide
EU DORA FAQ: scope, incidents, ICT contracts, testing, and evidence
Concise DORA FAQ covering who is in scope, proportionality, ICT third-party contracts, register-of-information records, major ICT incident thresholds and reporting, TLPT, testing, enforcement, and evidence.
Read guide
Next step

Turn DORA scope into owned operational resilience work

This hub is the shared entry point for legal, risk, technology, security, procurement, incident response, and resilience-testing teams. Confirm the entity and function boundary first, then assign each DORA workstream to the right owner and evidence record.

What this unlocks
  • Start with one legal entity, financial-service activity, , ICT-supported process, incident pathway, or ICT service contract.
  • Use Assessment Autopilot to request the ICT risk framework, function and asset inventories, business continuity and response plans, incident classification records, testing evidence, documentation where applicable, third-party due diligence, contract clauses, exit plans, and register-of-information data.
  • Use Research Copilot for cited questions about Article 2 scope, simplified ICT risk management, major ICT-related incident reporting, identification, register templates, subcontracting, and critical ICT third-party provider oversight.
  • Keep interpretation questions separate from implementation tasks so teams do not treat an unconfirmed entity classification, incident threshold, provider status, or reporting route as a settled obligation.
EU DORA artifact preview
Share it internally
Download the timeline export to align legal, product, engineering, and commercial teams on milestones and deadlines.