EU Resilience & Security Acts

DORA

Digital Operational Resilience Act

Law / regulation EU European Union Since 2022

ICT risk management, incident classification and reporting, resilience testing, and third-party risk oversight for financial entities, plus a supervisory regime for critical ICT providers serving them.

The third-party chapter is what reaches data platforms: a register of information on every ICT contract, mandated contractual terms, exit strategies, and concentration risk analysis. Your data vendors become items in a supervisory filing.

At a glance

Category
EU Resilience & Security Acts
Jurisdiction
EU
Governance
European Union
Status
Regulation (EU) 2022/2554; applies since 17 January 2025
First released
2022

Links

Related regulation

Other entries under EU Resilience & Security Acts.

See DORA in context

Open the interactive Data Landscape for Regulation to compare DORA against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.