Digital Operational Resilience Act

DORA requires EU financial entities to run an ICT risk-management framework, report major ICT incidents to supervisors, test digital operational resilience regularly, and manage risk from critical ICT third-party providers. It has applied in full since 17 January 2025, covering banks, insurers, investment firms, and crypto-asset service providers.

Updated 2026-08-30 · 19 tracked updates

DORA establishes a comprehensive framework for digital operational resilience in the EU financial sector. It sets uniform requirements for the security of network and information systems supporting business processes of financial entities.

19
Regulations Tracked
5
Jurisdictions
10
Upcoming Milestones
2026-08-30
Last Updated

Who Needs to Comply?

Banks, insurance companies, investment firms, crypto-asset service providers, and critical ICT third-party service providers operating in the EU financial sector.

Key Dates & Timeline

Entered into force January 2023. Full compliance required from January 2025. Regulatory Technical Standards (RTS) adopted throughout 2024.

Upcoming Milestones

2026-10-31

ECB-requested comprehensive action plan for significant institutions

ESRB Warning on systemic cyber risks from frontier AI models
2026-12-02

Article 5 prohibitions on realistic intimate synthetic content and CSAM-related AI practices apply

Digital Omnibus on AI amends the EU AI Act
2026-12-02

Providers of AI systems generating synthetic audio, image, video or text must comply with Article 50(2) marking steps if placed on market before 2 Aug 2026

Digital Omnibus on AI amends the EU AI Act
2026-12-31

BAIT continues for some firms during transition period before DORA replacement

BaFin DORA implementation guidance and filing procedures
2027-01-01

Remaining FinmadiG transition ends for certain German institutions

BaFin DORA implementation guidance and filing procedures

Latest DORA Updates

guidancehigh2026-08-30

FINMA sets governance and risk-management expectations for AI use in Swiss financial institutions

FINMA’s 2024 guidance states that Swiss financial institutions using AI must identify, limit, control, and monitor AI-related risks within their existing supervisory framework, so firms should immediately test whether their governance and model-risk controls are adequate.

guidancehigh2026-08-30

EBA, EIOPA and ESMA call for enhanced governance over frontier AI ICT risks in EU financial services

On 2026-07-31, the EU supervisory authorities called for stronger governance and consistent supervision to mitigate ICT risks from frontier AI models in the financial sector, signaling that firms should tighten controls now rather than wait for formal rule changes.

guidancehigh2026-08-23

ESA call for enhanced governance and consistent supervision of frontier AI ICT risks

On 2026-07-31, EBA, EIOPA and ESMA called on EU financial-sector firms and supervisors to tighten governance and supervision of frontier AI-related ICT risks, signaling immediate expectations for stronger control frameworks under existing resilience obligations.

guidancehigh2026-08-16

EU AI Office and supervisors call for enhanced governance for frontier AI in financial services

EU financial supervisors and the AI Office are signaling stronger governance and consistent supervision expectations for frontier AI models in the financial sector, so firms should treat this as an immediate AI Act implementation and risk-governance update rather than a future issue.

guidancehigh2026-08-02

ESAs call for stronger governance over frontier AI ICT risks in EU finance

On 2026-07-31, the EBA, EIOPA and ESMA issued a joint statement urging a cross-sector, risk-based and consistent supervisory approach for frontier AI models because their ICT risks are now a live supervisory concern in the EU financial sector.

amendmentcritical2026-07-26

Digital Omnibus on AI amends the EU AI Act

Regulation (EU) 2026/1744 amends the AI Act and makes the new prohibitions on realistic intimate/deepfake-style synthetic content and the updated Article 50 transparency obligations operative from 2 December 2026, creating immediate implementation work for AI providers and deployers.

guidancehigh2026-07-19

ESRB Warning on systemic cyber risks from frontier AI models

The ESRB warned that frontier AI models can collapse defensive time buffers and materially increase systemic cyber risk for EU financial institutions, and it specifically points to ECB-requested action plans due by 31 October 2026 as the near-term trigger for supervisory attention.

guidancehigh2026-07-12

ESAs support ESRB warning on systemic cyber risks from frontier AI models

On 2026-07-07, the European Supervisory Authorities backed the ESRB’s warning that frontier AI models can create systemic cyber risks for financial markets, elevating AI cyber resilience as a supervisory priority.

guidancehigh2026-07-05

EESC opinion on the AI Omnibus and Digital Omnibus simplification proposals

The EESC backed simplification of the AI Act and digital rulebook while warning that high-risk AI obligations are still expected to become binding as early as August 2026, so firms should not delay compliance planning pending omnibus negotiations.

guidancehigh2026-06-07

ESAs publish first annual report on DORA major ICT-related incidents

On 2026-06-03, the EBA, EIOPA and ESMA published their first annual overview of major ICT-related incidents under DORA, underscoring that borderless ICT and AI-driven risks now require financial entities to tighten cybersecurity and incident-reporting readiness.

Jurisdiction Coverage

Related Frameworks

Key Topics

Frequently Asked Questions

What does DORA require financial firms to do?

DORA requires EU financial entities to run an ICT risk-management framework, report major ICT incidents to supervisors, test digital operational resilience regularly, and manage risk from critical ICT third-party providers. It has applied in full since 17 January 2025, covering banks, insurers, investment firms, and crypto-asset service providers.

What is DORA?

DORA (Digital Operational Resilience Act) is an EU regulation that creates a unified framework for managing ICT risks in the financial sector. It covers ICT risk management, incident reporting, digital operational resilience testing, and third-party risk management.

How does DORA relate to the EU AI Act?

DORA and the EU AI Act are complementary. DORA focuses on ICT operational resilience in financial services, while the EU AI Act governs AI systems across all sectors. Financial firms using AI must comply with both — DORA for operational resilience and the AI Act for AI-specific requirements.

What are the key requirements of DORA?

DORA requires financial entities to establish ICT risk management frameworks, report major ICT-related incidents, conduct digital operational resilience testing, manage third-party ICT service provider risks, and share cyber threat intelligence.

Keep exploring

This hub tracks published DORA-related actions and guidance; it is not legal advice and does not cover every national supervisor's implementation detail.