- Full name
- Digital Operational Resilience Act
- Region
- European Union
- Applies to
- Financial entities operating in the EU — banks, insurers, investment firms, payment and e-money institutions, crypto-asset service providers — plus critical ICT third-party service providers designated by the European Supervisory Authorities.
Regulation (EU) 2022/2554 (DORA) applies from 17 January 2025 and brings ICT risk management for financial services under a unified, supervised regime. It covers ICT risk management, incident reporting, digital operational resilience testing (including threat-led penetration tests), and the management of ICT third-party risk. Identity sits inside every one of those pillars.