← All frameworks
Cyber

DORA (Digital Operational Resilience Act)

EU / ESAs · Brussels, EU · effective 17 Jan 2025

Binding ICT & operational-resilience regime for EU financial entities — including AI models used in finance. ICT risk management, incident reporting, resilience testing and third-party (cloud/AI) oversight.

Who must comply
  • Banks, insurers, investment firms, crypto-asset providers
  • Their critical ICT/AI third parties
Penalties

Regulator-set; critical third parties face fines up to 1% of daily worldwide turnover per day.

Key obligations
ICT risk framework
Board-owned ICT risk management across the lifecycle.
Resilience testing
Regular testing incl. threat-led penetration testing.
Incident reporting
Classify and report major ICT-related incidents.
Third-party oversight
Register of, and controls over, critical ICT/AI providers.
Sectors in scope
BankingInsuranceInvestmentCrypto / digital assetsPayments
Threats & cybersecurity it addresses
Financial-system outageModel-driven trading failureCloud concentration riskICT third-party compromise
Crosswalks — comply once, cover many
CSOAI Layer 0 mapping

Charter Art. 21, 39

Governed MCP tools — open source, pip/npx install