Framework · DORA
DORA is in force. Your ICT risk framework needs to be too.
The EU Digital Operational Resilience Act for financial entities, applicable since 17 January 2025: ICT risk, incident reporting, testing and ICT third parties.
The Digital Operational Resilience Act (DORA, Regulation (EU) 2022/2554) has applied since 17 January 2025. It applies to credit institutions, payment institutions, investment firms, insurance companies, crypto-asset service providers, and their critical ICT third-party providers. Financial entities operating in the EU must demonstrate ICT risk management, incident reporting, resilience testing, and third-party oversight, or face supervisory sanctions.
Key facts
- 17 January 2025: DORA application date; supervisory examinations and sanctions are active across the EU.
- 5 pillars: ICT risk, incident reporting, resilience testing, ICT third-party risk, and information sharing.
- 4 hours: maximum time to submit an initial notification to the competent authority for a major ICT incident.
- Article 28: register of all contractual arrangements with ICT third-party providers, maintained continuously.
What DORA requires
The regulation requires a documented ICT risk framework, a register of all ICT third-party arrangements, major incident classification and reporting to competent authorities, and an annual digital operational resilience testing programme.
- Chapter II (Art. 5–16): ICT risk management framework with Board-level accountability
- Chapter III (Art. 17–23): major ICT incident classification, reporting, and root cause analysis
- Chapter IV (Art. 24–27): digital operational resilience testing, including threat-led penetration testing (TLPT) for significant entities
- Chapter V (Art. 28–44): ICT third-party risk management and register of all contractual arrangements
- Article 30: mandatory contractual clauses; exit strategy, audit rights, incident notification
- Chapter VI (Art. 45): information and intelligence sharing arrangements
What Sentrix provides for DORA
ICT risk framework documentation
Board-approved ICT risk policy, risk tolerance statements, and risk management procedures required by Articles 5–16. Templates adapted to your entity type and supervisory jurisdiction.
Incident classification and reporting
Incident classification matrix (major versus significant), 4-hour initial notification timer, intermediate report and final root cause analysis, all workflow-automated with regulatory templates.
ICT third-party register (Article 28)
Your ICT register cannot be a spreadsheet. Sentrix builds it from your vendor data and monitors it continuously: full inventory with criticality classification and sub-outsourcing chains, Article 30 clause tracking, and a supervisory-ready export in the format required by your competent authority.
Concentration risk analysis
DORA requires analysis of ICT concentration risk. Sentrix identifies single points of failure in your ICT supply chain, across critical and non-critical providers, and generates the report required for supervisory examinations.
TLPT programme management
Threat-led penetration testing programme tracking for significant entities: scheduling, scope documentation, tester credential verification, and remediation tracking in the format expected by the Joint Committee of the European Supervisory Authorities.
Board reporting
DORA places ICT risk accountability at Board level. Sentrix generates ICT risk dashboards, incident summaries, and third-party risk reports in the format financial regulators expect to see.
Crosswalks
- NIS2: DORA is the lex specialis for financial entities; the substantial control overlap is mapped for entities subject to both regimes.
- OSFI B-10 / B-13: B-10 mapped to DORA's third-party provisions and B-13 to its ICT risk framework, for Canadian institutions operating in the EU.
- PCI DSS: for financial entities handling card data.
- ISO 27001: Annex A controls address part of the ICT risk framework.
Further reading
Third-party risk and financial services solution.
See your DORA posture on your real register.
Frequently asked questions
- Who does DORA apply to?
- DORA applies to credit institutions, payment institutions, investment firms, insurance companies, crypto-asset service providers, and their critical ICT third-party providers. Since 17 January 2025, financial entities operating in the EU must demonstrate ICT risk management, incident reporting, resilience testing, and third-party oversight, or face supervisory sanctions.
- What must the Article 28 ICT third-party register contain?
- A complete, continuously maintained register of all contractual arrangements with ICT third-party providers, including sub-outsourcing chains, criticality classification, concentration risk analysis and compliance with the Article 30 contractual clauses: exit strategy, audit rights, incident notification. Sentrix builds this register from your vendor data and exports it in the format required by your competent authority.
- What are the notification deadlines for a major ICT incident?
- DORA requires an initial notification to the competent authority within 4 hours of classifying an incident as major, followed by an intermediate report and a final report with root cause analysis. Sentrix provides the classification matrix (major versus significant), the initial notification timer and the regulatory templates for each stage, automated through workflows.
Related pages
Framework · NIS2
NIS2: ten measures, management liability, 24-hour warning
The EU network and information security directive: ten minimum measures under Article 21, management body accountability and 24-hour incident early warning.
Framework · OSFI B-10 / B-13
OSFI B-10 and B-13: outsourcing, technology and cyber risk
OSFI guidelines on outsourcing (B-10) and technology and cyber risk management (B-13) for Canada's federally regulated financial institutions, in one program.
Framework · PCI DSS v4.0.1
PCI DSS v4.0.1: 12 requirements, one evidence program
Payment Card Industry Data Security Standard: twelve requirements, quarterly vulnerability scans and annual validation by a QSA report or self-assessment.
Framework · ISO 27001:2022
ISO 27001:2022: from ISMS to certification in one program
The international standard for information security management systems: clauses 4 to 10, 93 Annex A controls, and a two-stage certification audit.
Let's talk about your compliance program.
Last updated: 2026-09-17
