DORA Regulation

Glossary category

What is the DORA Regulation?

The DORA Regulation is the common name for Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector. It establishes a unified EU framework for managing information and communication technology risk in financial entities. According to the Official Journal of the European Union, the regulation entered into force on 16 January 2023 and applies from 17 January 2025.

DORA is directly applicable in all EU Member States, including Poland. Its purpose is to ensure that financial entities can withstand, respond to and recover from ICT-related disruptions. This includes cyberattacks, system failures, data loss, outsourcing failures, operational incidents and other events that may affect the continuity, integrity, security or availability of financial services.

The regulation applies to a broad range of financial sector entities, including banks, payment institutions, electronic money institutions, investment firms, crypto-asset service providers, insurance and reinsurance undertakings, certain insurance intermediaries, trading venues, central securities depositories, central counterparties, management companies, alternative investment fund managers, credit rating agencies, crowdfunding service providers and other entities listed in Regulation (EU) 2022/2554. It also introduces rules affecting ICT third-party service providers, especially providers considered critical for the financial sector.


What does the DORA Regulation cover?

DORA is built around several core areas of digital operational resilience. The first is ICT risk management. Financial entities must maintain internal governance, policies, procedures and controls that allow them to identify, protect, detect, respond to and recover from ICT risks. This includes responsibilities at management body level, incident handling procedures, backup policies, business continuity arrangements and disaster recovery capabilities.

The second area is ICT-related incident management, classification and reporting. Financial entities must classify major ICT-related incidents and, where required, report them to competent authorities. The detailed reporting templates, time limits and classification criteria are further specified in regulatory and implementing technical standards developed by the European Supervisory Authorities under DORA.

The third area is digital operational resilience testing. Entities must test their ICT systems, tools and processes to verify whether they are resilient and secure. For selected financial entities, DORA also requires advanced threat-led penetration testing. This requirement is linked to the entity’s risk profile and systemic relevance, as specified in Regulation (EU) 2022/2554 and related technical standards.

The fourth area is ICT third-party risk management. DORA requires financial entities to manage risks connected with outsourcing, cloud services, software providers, data centres and other ICT suppliers. Contracts with ICT service providers must include specific provisions, including service descriptions, locations of data processing, access and audit rights, security requirements, termination rights and exit strategies.

The fifth area is information sharing. DORA allows financial entities to exchange cyber threat information and intelligence, provided that such sharing is conducted in accordance with applicable law, including data protection, competition and confidentiality rules.


When is legal support with DORA useful?

Legal support may be needed when a financial entity assesses whether DORA applies to its activity, maps ICT dependencies, reviews internal governance or prepares documentation required under the regulation. This is particularly important for regulated entities operating in banking, payments, investment services, insurance, fintech, crypto-assets, crowdfunding or capital markets infrastructure.

Support may also be necessary when negotiating or reviewing ICT contracts. DORA has a significant impact on agreements with cloud providers, software vendors, outsourcing providers, cybersecurity suppliers and group service companies. Contracts that were acceptable before DORA may require amendment to include mandatory clauses and practical mechanisms for audit, access, reporting, subcontracting control and exit management.

Entrepreneurs providing ICT services to financial entities may also need to understand DORA. Even if they are not financial entities themselves, their clients may require contractual compliance, additional reporting duties, security obligations, audit rights and evidence of resilience measures. In some cases, ICT providers may fall within the EU oversight framework for critical ICT third-party service providers under Regulation (EU) 2022/2554.

A timely legal and compliance review can help avoid regulatory gaps, contractual disputes, operational disruption, liability exposure and financial losses. Early assessment is especially important where an entity relies on complex outsourcing structures, cross-border ICT services, cloud environments, group IT arrangements or critical systems supporting regulated financial activity.


Legal support in relation to the DORA Regulation

Support in matters relating to DORA may include in particular:

  • assessing whether and how DORA applies to a given entity or business model;
  • reviewing ICT governance, internal policies and reporting procedures from a legal perspective;
  • preparing or updating ICT risk management documentation;
  • reviewing contracts with ICT third-party service providers, including cloud and outsourcing agreements;
  • drafting DORA-compliant contractual clauses, exit provisions and audit mechanisms;
  • supporting incident reporting processes and communication with competent authorities;
  • advising ICT providers cooperating with financial entities subject to DORA;
  • coordinating DORA requirements with GDPR, financial regulatory obligations, outsourcing rules and corporate governance requirements.


Need assistance with the DORA Regulation? Contact us.


See also

  • Financial reporting
  • Commercial Law
  • Corporate secretary
  • Business restructuring