EU Digital Operational Resilience Act Scope and implementation hub
DORA has applied since 17 January 2025. Start with the Article 2 legal-entity test, then route each in-scope entity into the ICT risk, incident, testing, and third-party work that applies to it.
Use the topic guides to move from scope classification to concrete work: controls, incident templates, readiness, provider registers, contract clauses, oversight implications, and retained evidence.
Check exclusions and the separately. A lighter framework changes some Chapter II duties; it does not make the entity generally exempt from DORA.
Key dates for DORA implementation
Track DORA publication, entry into force, the 17 January 2025 application date, Level 2 technical standards, register-of-information templates, incident reporting forms, criteria, and critical ICT third-party provider oversight milestones.
Choose the next operational resilience decision
Start by confirming the legal entity, DORA role, exclusions, proportionality and critical functions. Then move to the workstream you own: ICT risk, incidents, testing, third-party dependencies, reporting dates, enforcement or framework overlap.
Start here: scope, roles, and critical functions
Name the regulated legal entity and provider relationship, test exclusions and proportionality, and identify the functions whose disruption would materially impair regulated performance or continuity.
Governance, ICT risk, and evidence
Translate management-body accountability and the ICT risk framework into owned controls, retrievable records, remediation decisions, and an operating compliance baseline.
Incident classification and reporting
Apply the binding classification thresholds, preserve the decision record, and run the initial, intermediate, and final reporting clocks with the official forms and procedures.
Resilience testing and TLPT
Separate the general risk-based testing programme from threat-led penetration testing for entities identified by competent authorities, then retain scope, test, remediation, and attestation evidence.
ICT third parties, contracts, and the register
Connect critical-function dependencies to due diligence, concentration and subcontracting risk, Article 30 contract rights, exit planning, and the linked register-of-information templates.
Dates, recurring work, and enforcement
Distinguish the Regulation's application date from later Level 2 acts and recurring operating deadlines, then understand national enforcement and critical-provider oversight without inventing one EU-wide fine cap.
Compare regimes or answer a focused question
See what DORA changes alongside NIS2, PSD2 reporting, EBA outsourcing guidance, ISO/IEC 27001, and ISO 22301, or use the FAQ for direct scope and implementation answers.
Turn DORA scope into owned operational resilience work
This hub is the shared entry point for legal, risk, technology, security, procurement, incident response, and resilience-testing teams. Confirm the entity and function boundary first, then assign each DORA workstream to the right owner and evidence record.
- Start with one legal entity, financial-service activity, , ICT-supported process, incident pathway, or ICT service contract.
- Use Assessment Autopilot to request the ICT risk framework, function and asset inventories, business continuity and response plans, incident classification records, testing evidence, documentation where applicable, third-party due diligence, contract clauses, exit plans, and register-of-information data.
- Use Research Copilot for cited questions about Article 2 scope, simplified ICT risk management, major ICT-related incident reporting, identification, register templates, subcontracting, and critical ICT third-party provider oversight.
- Keep interpretation questions separate from implementation tasks so teams do not treat an unconfirmed entity classification, incident threshold, provider status, or reporting route as a settled obligation.
