DORA – Digital Operational Resilience Act

With Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience in the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011, the European Union obliges financial institutions to strengthen their digital operational resilience. The English term “Digital Operational Resilience Act” and its abbreviation DORA have also become established in German-speaking countries.

The legislation aims to improve the digital operational resilience of EU financial institutions and their third-party ICT service providers and to create a uniform supervisory framework across the EU. The aim is to reduce vulnerability to cyber threats and ICT disruptions across the entire value chain of the financial sector. In addition, DORA intends to harmonize national regulations for the security of IT systems in the financial sector. This will strengthen the European financial market as a whole against cyber risks and information and communication technology incidents[1].

