DORA¶

Regulation (EU) 2022/2554: the Digital Operational Resilience Act. In application since 17 January 2025 for financial entities and their critical ICT third-party providers.
DORA is the lead branch of this library. The regulation is organized around five pillars, and the resources here will follow the same structure:
Branches¶
| Pillar | Planned artefacts |
|---|---|
| ICT risk management (Ch. II) | Clauses corner · policy template · responsibility matrix for the management body · control mapping |
| Incident management & reporting (Ch. III) | Clauses corner · classification checklist · reporting timeline reference · evidence examples |
| Digital operational resilience testing (Ch. IV) | Clauses corner · testing programme checklist · TLPT readiness overview |
| ICT third-party risk (Ch. V) | Clauses corner · register of information starter kit · contract clause checklist (Art. 30) · exit strategy template |
| Information sharing (Ch. VI) | Short practical note |
New: clauses corner
The clauses corner is the working index of every document BaFin asks to see in a DORA review, with the article numbers that justify each ask and the RTS/ITS that complete the picture. The companion policy template is a copy-paste skeleton for filling the gaps. Both pages are ready for review, not yet published.
Tool: DORA documentation builder
A downloadable Excel tool that drafts any DORA required document (policy, standard, procedure, strategy or guideline) with the regulation references and section structure built in, transcribed from the BaFin overview. Download the builder, or open the clauses corner it is built from.
From my library¶
Links from my reading library that I actually use for DORA work.
ISO 27001 & ISO 22301 free templates
Free policy and procedure templates. A sensible baseline for a DORA gap assessment, since most DORA requirements trace back to these standards.
law-tracker.europa.euEU Law Tracker
The Commission's own tracker. Use it to check the current status of DORA RTS and ITS before you rely on any of them.
enisa.europa.euENISA cloud computing risk assessment
Old but still useful for structuring ICT third-party risk analysis under Chapter V.
risk-engineering.orgRisk metrics
How to measure safety and risk performance properly. Helps when you have to define risk indicators for the management body.
github.comAudit-Agent (open source)
An open-source EU CRA and DORA compliance platform built on GCP. Early-stage, but interesting to see how others automate evidence collection.
patreon.comAndrey Prozorov
ISMS and privacy practitioner who publishes hands-on templates and mind maps. Some free, some paid, consistently practical.
The official texts¶
The full DORA family on EUR-Lex, every title and mandate checked against the primary text in July 2026. Start here, not with summaries.
| Act | What it covers |
|---|---|
| Regulation (EU) 2022/2554 | DORA itself, the Level 1 text |
| DR 2024/1502 | Criteria for designating an ICT third-party service provider as critical. The test that decides who lands under EU-level oversight |
| DR 2024/1505 | Amount of the oversight fees the Lead Overseer charges designated critical providers, and how those fees are paid |
| RTS 2024/1772 | Classification of ICT incidents and cyber threats, materiality thresholds |
| RTS 2024/1773 | Policy on contractual arrangements for ICT services supporting critical or important functions |
| RTS 2024/1774 | ICT risk management tools, methods, processes and policies, plus the simplified framework |
| ITS 2024/2956 | Standard templates for the register of information |
| RTS 2025/295 | Harmonised conditions for how oversight of critical providers is actually conducted |
| RTS 2025/301 | Content and time limits for major incident notifications and reports |
| ITS 2025/302 | Standard forms and templates for reporting major incidents, with the templates as annexes |
| RTS 2025/420 | Composition, designation, tasks and working arrangements of the joint examination teams that carry out that oversight |
| RTS 2025/532 | What a financial entity must determine and assess before ICT services supporting critical or important functions are subcontracted |
| RTS 2025/1190 | Criteria for identifying entities required to perform threat-led penetration testing |
Four of these bind the supervisors more than they bind you. 2024/1502, 2024/1505, 2025/295 and 2025/420 build the oversight machinery that sits over critical ICT providers, so read them to understand what your provider is being put through, not to find new obligations of your own. 2025/532 is the exception. It lands squarely on the financial entity, and it is the one to read if anything you depend on is subcontracted.
Official tools and templates¶
What the regulation demands, and the official tool that exists for it.
Register of information: reporting technical package
DORA Art. 28(3) requires a register of all ICT third-party arrangements, filed in the ITS 2024/2956 template structure. This EBA page has the whole toolkit: validation rules, data point model, taxonomy, sample files and FAQs used for the 2025 submissions.
eba.europa.euRegister of information: illustrative Excel templates
The ITS development page, including an illustrative Excel workbook of the fifteen register templates. The fastest way to see what your Art. 8(5) third-party mapping has to feed.
eba.europa.euIncident reporting standards, final report
DORA Arts. 17 to 20 govern incident reporting; RTS 2025/301 sets content and deadlines, ITS 2025/302 carries the report templates in its annexes. This page has the ESAs' final report behind both.
ecb.europa.euTIBER-EU framework
DORA Arts. 26 to 27 require threat-led penetration testing for selected entities (criteria in RTS 2025/1190). TIBER-EU is the ECB-developed red-teaming framework most member states use to run TLPT in practice.
ecb.europa.euECB cyber resilience oversight expectations
The ECB's maturity-based framework (CROE) for assessing cyber resilience of financial market infrastructures. Useful self-assessment structure even outside FMI land.
bafin.deBaFin: DORA documentation requirements overview (PDF, English)
DORA's documentation duties are scattered across the regulation and all its RTS and ITS. BaFin collected every one of them into a single structured overview, published December 2024, with an accompanying guidance note. The official master checklist of what documents you need.
bafin.deBaFin DORA hub (German)
Germany's supervisor is the national reporting point for DORA incidents. The hub covers all six DORA areas from a German entity's perspective, including the transition from BAIT and VAIT.
The supervisory hubs of the three ESAs are the places where new Level 2 material lands first: EBA, ESMA and EIOPA. The European Commission's DORA delegated and implementing acts page is the one-stop check that a given Level 2 act is in force, and ENISA's finance-sector page gives the threat context DORA sits on.
National supervisors¶
DORA is one regulation, but you report to your national competent authority, and several have published their own DORA hubs, guidance and reporting channels. A selection I have checked, across the larger markets. Each link is the supervisor's own DORA page.
France, ACPR
The French prudential supervisor's DORA hub for banking and insurance, including its December 2024 notice on the ICT risk management framework for insurers.
amf-france.orgFrance, AMF
The French markets authority's DORA hub for investment firms, fund managers, market infrastructures and crypto-asset service providers, with its incident and register notification channels.
bundesbank.deGermany, Deutsche Bundesbank
The Bundesbank's DORA reporting page, confirming the German split where BaFin is competent authority and the Bundesbank receives reports and joins on-site inspections.
centralbank.ieIreland, Central Bank of Ireland
The CBI DORA hub, with its DORA FAQ, incident notification templates and the ICT self-assessment tool. One of the clearer national resources.
bancaditalia.itItaly, Banca d'Italia
Banca d'Italia's DORA deep-dive, covering the Italian reporting platform and the joint approach with CONSOB (securities) and IVASS (insurance).
cssf.luLuxembourg, CSSF
The CSSF DORA hub, including how DORA takes precedence over its earlier outsourcing circulars and the eDesk register submission process.
knf.gov.plPoland, KNF
The Polish Financial Supervision Authority's DORA page and its official position on DORA applying from 17 January 2025 regardless of national implementing law.
cnmv.esSpain, CNMV
The Spanish securities regulator's cybersecurity and DORA hub, with a detailed DORA FAQ covering scope, proportionality and third-party risk.
finanstilsynet.dkDenmark, Finanstilsynet
The Danish FSA's DORA page, with a five-pillar walkthrough and the Danish implementation timeline.
fi.seSweden, Finansinspektionen
The Swedish supervisor's DORA page and its regulations (FFFS 2024:20) on incident and register reporting, notable for a 28 February annual register deadline.
fsma.beBelgium, FSMA
The Belgian markets authority's DORA page, with educational documentation and its DORA readiness survey results, plus the FSMA and NBB supervisory split.
More national authorities (Austria's FMA, the Netherlands' DNB, Greece, Portugal, Malta and others) publish DORA hubs too. They are being confirmed and will be added.