Digital Operational Resilience Act
DORA requires EU financial entities to run an ICT risk-management framework, report major ICT incidents to supervisors, test digital operational resilience regularly, and manage risk from critical ICT third-party providers. It has applied in full since 17 January 2025, covering banks, insurers, investment firms, and crypto-asset service providers.
Updated 2026-08-30 · 19 tracked updates
DORA establishes a comprehensive framework for digital operational resilience in the EU financial sector. It sets uniform requirements for the security of network and information systems supporting business processes of financial entities.
Who Needs to Comply?
Banks, insurance companies, investment firms, crypto-asset service providers, and critical ICT third-party service providers operating in the EU financial sector.
Key Dates & Timeline
Entered into force January 2023. Full compliance required from January 2025. Regulatory Technical Standards (RTS) adopted throughout 2024.
Upcoming Milestones
ECB-requested comprehensive action plan for significant institutions
ESRB Warning on systemic cyber risks from frontier AI modelsArticle 5 prohibitions on realistic intimate synthetic content and CSAM-related AI practices apply
Digital Omnibus on AI amends the EU AI ActProviders of AI systems generating synthetic audio, image, video or text must comply with Article 50(2) marking steps if placed on market before 2 Aug 2026
Digital Omnibus on AI amends the EU AI ActBAIT continues for some firms during transition period before DORA replacement
BaFin DORA implementation guidance and filing proceduresRemaining FinmadiG transition ends for certain German institutions
BaFin DORA implementation guidance and filing proceduresLatest DORA Updates
FINMA sets governance and risk-management expectations for AI use in Swiss financial institutions
FINMA’s 2024 guidance states that Swiss financial institutions using AI must identify, limit, control, and monitor AI-related risks within their existing supervisory framework, so firms should immediately test whether their governance and model-risk controls are adequate.
EBA, EIOPA and ESMA call for enhanced governance over frontier AI ICT risks in EU financial services
On 2026-07-31, the EU supervisory authorities called for stronger governance and consistent supervision to mitigate ICT risks from frontier AI models in the financial sector, signaling that firms should tighten controls now rather than wait for formal rule changes.
ESA call for enhanced governance and consistent supervision of frontier AI ICT risks
On 2026-07-31, EBA, EIOPA and ESMA called on EU financial-sector firms and supervisors to tighten governance and supervision of frontier AI-related ICT risks, signaling immediate expectations for stronger control frameworks under existing resilience obligations.
EU AI Office and supervisors call for enhanced governance for frontier AI in financial services
EU financial supervisors and the AI Office are signaling stronger governance and consistent supervision expectations for frontier AI models in the financial sector, so firms should treat this as an immediate AI Act implementation and risk-governance update rather than a future issue.
ESAs call for stronger governance over frontier AI ICT risks in EU finance
On 2026-07-31, the EBA, EIOPA and ESMA issued a joint statement urging a cross-sector, risk-based and consistent supervisory approach for frontier AI models because their ICT risks are now a live supervisory concern in the EU financial sector.
Digital Omnibus on AI amends the EU AI Act
Regulation (EU) 2026/1744 amends the AI Act and makes the new prohibitions on realistic intimate/deepfake-style synthetic content and the updated Article 50 transparency obligations operative from 2 December 2026, creating immediate implementation work for AI providers and deployers.
ESRB Warning on systemic cyber risks from frontier AI models
The ESRB warned that frontier AI models can collapse defensive time buffers and materially increase systemic cyber risk for EU financial institutions, and it specifically points to ECB-requested action plans due by 31 October 2026 as the near-term trigger for supervisory attention.
ESAs support ESRB warning on systemic cyber risks from frontier AI models
On 2026-07-07, the European Supervisory Authorities backed the ESRB’s warning that frontier AI models can create systemic cyber risks for financial markets, elevating AI cyber resilience as a supervisory priority.
EESC opinion on the AI Omnibus and Digital Omnibus simplification proposals
The EESC backed simplification of the AI Act and digital rulebook while warning that high-risk AI obligations are still expected to become binding as early as August 2026, so firms should not delay compliance planning pending omnibus negotiations.
ESAs publish first annual report on DORA major ICT-related incidents
On 2026-06-03, the EBA, EIOPA and ESMA published their first annual overview of major ICT-related incidents under DORA, underscoring that borderless ICT and AI-driven risks now require financial entities to tighten cybersecurity and incident-reporting readiness.
Jurisdiction Coverage
Related Frameworks
Key Topics
Frequently Asked Questions
What does DORA require financial firms to do?
DORA requires EU financial entities to run an ICT risk-management framework, report major ICT incidents to supervisors, test digital operational resilience regularly, and manage risk from critical ICT third-party providers. It has applied in full since 17 January 2025, covering banks, insurers, investment firms, and crypto-asset service providers.
What is DORA?
DORA (Digital Operational Resilience Act) is an EU regulation that creates a unified framework for managing ICT risks in the financial sector. It covers ICT risk management, incident reporting, digital operational resilience testing, and third-party risk management.
How does DORA relate to the EU AI Act?
DORA and the EU AI Act are complementary. DORA focuses on ICT operational resilience in financial services, while the EU AI Act governs AI systems across all sectors. Financial firms using AI must comply with both — DORA for operational resilience and the AI Act for AI-specific requirements.
What are the key requirements of DORA?
DORA requires financial entities to establish ICT risk management frameworks, report major ICT-related incidents, conduct digital operational resilience testing, manage third-party ICT service provider risks, and share cyber threat intelligence.
Keep exploring
This hub tracks published DORA-related actions and guidance; it is not legal advice and does not cover every national supervisor's implementation detail.