EU Resilience & Security Acts
DORA
Digital Operational Resilience Act
ICT risk management, incident classification and reporting, resilience testing, and third-party risk oversight for financial entities, plus a supervisory regime for critical ICT providers serving them.
The third-party chapter is what reaches data platforms: a register of information on every ICT contract, mandated contractual terms, exit strategies, and concentration risk analysis. Your data vendors become items in a supervisory filing.
At a glance
- Category
- EU Resilience & Security Acts
- Jurisdiction
- EU
- Governance
- European Union
- Status
- Regulation (EU) 2022/2554; applies since 17 January 2025
- First released
- 2022
Links
Related regulation
Other entries under EU Resilience & Security Acts.
See DORA in context
Open the interactive Data Landscape for Regulation to compare DORA against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.