The Digital Operational Resilience Act (DORA) is an EU regulation that came into force on January 2023. It is part of the EU Commission's digital financial package with the aim of increasing the digital resilience of the European financial market.
The aim is to ensure that financial market participants can continue to operate reliably even in the event of incidents concerning ICT (information and communications technology) or key suppliers.
For participants affected by the regulation, there is a transition period until January 2025 for full implementation. During this timeline, we expect further expectations from the European Supervisory Authorities (ESAs) through regulatory technical standards and guidelines.
The new requirements focus on ICT security, operational resilience and reporting obligations in the event of cyber-attacks, for example, and other ICT incidents. These are explained below and illustrated by examples.