Skip to content

DORA

Miniature classical bank with a cutaway server room, control room and gold vault, under a teal dome deflecting a storm

Regulation (EU) 2022/2554: the Digital Operational Resilience Act. In application since 17 January 2025 for financial entities and their critical ICT third-party providers.

DORA is the lead branch of this library. The regulation is organized around five pillars, and the resources here will follow the same structure:

Branches

Pillar Planned artefacts
ICT risk management (Ch. II) Clauses corner · policy template · responsibility matrix for the management body · control mapping
Incident management & reporting (Ch. III) Clauses corner · classification checklist · reporting timeline reference · evidence examples
Digital operational resilience testing (Ch. IV) Clauses corner · testing programme checklist · TLPT readiness overview
ICT third-party risk (Ch. V) Clauses corner · register of information starter kit · contract clause checklist (Art. 30) · exit strategy template
Information sharing (Ch. VI) Short practical note

New: clauses corner

The clauses corner is the working index of every document BaFin asks to see in a DORA review, with the article numbers that justify each ask and the RTS/ITS that complete the picture. The companion policy template is a copy-paste skeleton for filling the gaps. Both pages are ready for review, not yet published.

Tool: DORA documentation builder

A downloadable Excel tool that drafts any DORA required document (policy, standard, procedure, strategy or guideline) with the regulation references and section structure built in, transcribed from the BaFin overview. Download the builder, or open the clauses corner it is built from.

From my library

Links from my reading library that I actually use for DORA work.

The official texts

The full DORA family on EUR-Lex, every title and mandate checked against the primary text in July 2026. Start here, not with summaries.

Act What it covers
Regulation (EU) 2022/2554 DORA itself, the Level 1 text
DR 2024/1502 Criteria for designating an ICT third-party service provider as critical. The test that decides who lands under EU-level oversight
DR 2024/1505 Amount of the oversight fees the Lead Overseer charges designated critical providers, and how those fees are paid
RTS 2024/1772 Classification of ICT incidents and cyber threats, materiality thresholds
RTS 2024/1773 Policy on contractual arrangements for ICT services supporting critical or important functions
RTS 2024/1774 ICT risk management tools, methods, processes and policies, plus the simplified framework
ITS 2024/2956 Standard templates for the register of information
RTS 2025/295 Harmonised conditions for how oversight of critical providers is actually conducted
RTS 2025/301 Content and time limits for major incident notifications and reports
ITS 2025/302 Standard forms and templates for reporting major incidents, with the templates as annexes
RTS 2025/420 Composition, designation, tasks and working arrangements of the joint examination teams that carry out that oversight
RTS 2025/532 What a financial entity must determine and assess before ICT services supporting critical or important functions are subcontracted
RTS 2025/1190 Criteria for identifying entities required to perform threat-led penetration testing

Four of these bind the supervisors more than they bind you. 2024/1502, 2024/1505, 2025/295 and 2025/420 build the oversight machinery that sits over critical ICT providers, so read them to understand what your provider is being put through, not to find new obligations of your own. 2025/532 is the exception. It lands squarely on the financial entity, and it is the one to read if anything you depend on is subcontracted.

Official tools and templates

What the regulation demands, and the official tool that exists for it.

eba.europa.eu

Register of information: reporting technical package

DORA Art. 28(3) requires a register of all ICT third-party arrangements, filed in the ITS 2024/2956 template structure. This EBA page has the whole toolkit: validation rules, data point model, taxonomy, sample files and FAQs used for the 2025 submissions.

eba.europa.eu

Register of information: illustrative Excel templates

The ITS development page, including an illustrative Excel workbook of the fifteen register templates. The fastest way to see what your Art. 8(5) third-party mapping has to feed.

eba.europa.eu

Incident reporting standards, final report

DORA Arts. 17 to 20 govern incident reporting; RTS 2025/301 sets content and deadlines, ITS 2025/302 carries the report templates in its annexes. This page has the ESAs' final report behind both.

ecb.europa.eu

TIBER-EU framework

DORA Arts. 26 to 27 require threat-led penetration testing for selected entities (criteria in RTS 2025/1190). TIBER-EU is the ECB-developed red-teaming framework most member states use to run TLPT in practice.

ecb.europa.eu

ECB cyber resilience oversight expectations

The ECB's maturity-based framework (CROE) for assessing cyber resilience of financial market infrastructures. Useful self-assessment structure even outside FMI land.

bafin.de

BaFin: DORA documentation requirements overview (PDF, English)

DORA's documentation duties are scattered across the regulation and all its RTS and ITS. BaFin collected every one of them into a single structured overview, published December 2024, with an accompanying guidance note. The official master checklist of what documents you need.

bafin.de

BaFin DORA hub (German)

Germany's supervisor is the national reporting point for DORA incidents. The hub covers all six DORA areas from a German entity's perspective, including the transition from BAIT and VAIT.

The supervisory hubs of the three ESAs are the places where new Level 2 material lands first: EBA, ESMA and EIOPA. The European Commission's DORA delegated and implementing acts page is the one-stop check that a given Level 2 act is in force, and ENISA's finance-sector page gives the threat context DORA sits on.

National supervisors

DORA is one regulation, but you report to your national competent authority, and several have published their own DORA hubs, guidance and reporting channels. A selection I have checked, across the larger markets. Each link is the supervisor's own DORA page.

acpr.banque-france.fr

France, ACPR

The French prudential supervisor's DORA hub for banking and insurance, including its December 2024 notice on the ICT risk management framework for insurers.

amf-france.org

France, AMF

The French markets authority's DORA hub for investment firms, fund managers, market infrastructures and crypto-asset service providers, with its incident and register notification channels.

bundesbank.de

Germany, Deutsche Bundesbank

The Bundesbank's DORA reporting page, confirming the German split where BaFin is competent authority and the Bundesbank receives reports and joins on-site inspections.

centralbank.ie

Ireland, Central Bank of Ireland

The CBI DORA hub, with its DORA FAQ, incident notification templates and the ICT self-assessment tool. One of the clearer national resources.

bancaditalia.it

Italy, Banca d'Italia

Banca d'Italia's DORA deep-dive, covering the Italian reporting platform and the joint approach with CONSOB (securities) and IVASS (insurance).

cssf.lu

Luxembourg, CSSF

The CSSF DORA hub, including how DORA takes precedence over its earlier outsourcing circulars and the eDesk register submission process.

knf.gov.pl

Poland, KNF

The Polish Financial Supervision Authority's DORA page and its official position on DORA applying from 17 January 2025 regardless of national implementing law.

cnmv.es

Spain, CNMV

The Spanish securities regulator's cybersecurity and DORA hub, with a detailed DORA FAQ covering scope, proportionality and third-party risk.

finanstilsynet.dk

Denmark, Finanstilsynet

The Danish FSA's DORA page, with a five-pillar walkthrough and the Danish implementation timeline.

fi.se

Sweden, Finansinspektionen

The Swedish supervisor's DORA page and its regulations (FFFS 2024:20) on incident and register reporting, notable for a 28 February annual register deadline.

fsma.be

Belgium, FSMA

The Belgian markets authority's DORA page, with educational documentation and its DORA readiness survey results, plus the FSMA and NBB supervisory split.

More national authorities (Austria's FMA, the Netherlands' DNB, Greece, Portugal, Malta and others) publish DORA hubs too. They are being confirmed and will be added.