Skip to main content
FRAMEWORK

DORA's five pillars, operating as one system.

The Digital Operational Resilience Act — Regulation (EU) 2022/2554 — pulls the financial sector's ICT rules into one directly applicable regulation. Its five pillars: ICT risk management, incident reporting and classification, digital operational resilience testing, ICT third-party risk management, and information sharing. It has applied across the EU since 17 January 2025.

For a financial entity this is an operating problem, not a documentation problem. A major ICT incident is classified, escalated and reported on a clock measured in hours; the register of information is a live description of the subcontracting chain; resilience testing is executed on a schedule, not described. Documentation assembled for an examination ages faster than the estate it describes.

Who it applies to

EU financial entities — credit institutions, insurers, payment and e-money institutions, investment firms and crypto-asset service providers among other categories. ICT third-party providers that become critical to the sector can additionally be designated for direct oversight by the European Supervisory Authorities. The obligations follow the ICT arrangements supporting critical or important functions, wherever those arrangements are contracted.

The clock

DORA has applied since 17 January 2025. The reporting clocks for a major ICT incident were fixed by Commission Delegated Regulation (EU) 2025/301, in force since 12 March 2025 — the cascade below starts at classification.

DORA · timeline and reporting clocks
WhenWhat happens
16 January 2023Regulation (EU) 2022/2554 entered into force
17 January 2025DORA applies — the five pillars become live obligations
12 March 2025Incident-reporting rules entered into force (Delegated Regulation (EU) 2025/301, Implementing Regulation (EU) 2025/302), fixing classification, templates and clocks
Initial notificationAs early as possible and no later than 4 hours after classifying an incident as major — and no later than 24 hours after becoming aware
Intermediate reportWithin 72 hours of the initial notification
Final reportNo later than one month after the intermediate report

What it asks, in operating terms

Read as an operating requirement rather than a legal text, DORA reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when a supervisor asks for it.

DORA requirements · how TruSecure answers them
What DORA asksWhere it is answered
Classify and report major ICT incidents on the clockIncident & resilience workflows · clocked from classification, named owner, sealed record
Maintain the register of information across the subcontracting chainSupplier risk register · chains documented, continuously current
Manage concentration risk among ICT providersSupplier risk register · concentration flagged by provider
Test digital operational resilience on scheduleResilience testing · threat-led programmes tracked to evidence
Answer for ICT risk at board levelBoard reporting · sourced from live control state

What you'd actually look at

In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:

DORA readiness file · group excerptSample data
Register of information
112 arrangements · subcontracting chains documented
Major incidents · YTD
2 · initial within 4 hours · final within one month
Resilience testing
threat-led · current cycle complete
Concentration flags
1 · under review
Evidence
sealed · sha256:8c41…d0b7

Where teams usually start

With a demo walked through by TruSecure — the DORA control set, a sample major-incident drill against the 4-hour clock, the register export an ICT examination will ask for. A Resilience Sprint then produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.

Sovereignty

DORA Arts. 28-30 require a register of information covering the subcontracting chain supporting critical or important functions, Art. 29 addresses concentration risk, and Art. 28(8) requires an exit you can actually execute. Our register entry is one line, there is no hyperscaler concentration behind it, and full export works today — with the open core intended to make the exit demonstrable once Community Edition is released.

See the whole chain

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

The short answer

DORA (Regulation (EU) 2022/2554) requires EU financial entities and their critical ICT third-party providers to manage ICT risk, report incidents on a defined classification and timeline, test digital operational resilience, and maintain a register of information on ICT third-party arrangements. TruSecure maintains that register continuously.