DORA's five pillars, operating as one system.
The Digital Operational Resilience Act — Regulation (EU) 2022/2554 — pulls the financial sector's ICT rules into one directly applicable regulation. Its five pillars: ICT risk management, incident reporting and classification, digital operational resilience testing, ICT third-party risk management, and information sharing. It has applied across the EU since 17 January 2025.
For a financial entity this is an operating problem, not a documentation problem. A major ICT incident is classified, escalated and reported on a clock measured in hours; the register of information is a live description of the subcontracting chain; resilience testing is executed on a schedule, not described. Documentation assembled for an examination ages faster than the estate it describes.
Who it applies to
EU financial entities — credit institutions, insurers, payment and e-money institutions, investment firms and crypto-asset service providers among other categories. ICT third-party providers that become critical to the sector can additionally be designated for direct oversight by the European Supervisory Authorities. The obligations follow the ICT arrangements supporting critical or important functions, wherever those arrangements are contracted.
The clock
DORA has applied since 17 January 2025. The reporting clocks for a major ICT incident were fixed by Commission Delegated Regulation (EU) 2025/301, in force since 12 March 2025 — the cascade below starts at classification.
| When | What happens |
|---|---|
| 16 January 2023 | Regulation (EU) 2022/2554 entered into force |
| 17 January 2025 | DORA applies — the five pillars become live obligations |
| 12 March 2025 | Incident-reporting rules entered into force (Delegated Regulation (EU) 2025/301, Implementing Regulation (EU) 2025/302), fixing classification, templates and clocks |
| Initial notification | As early as possible and no later than 4 hours after classifying an incident as major — and no later than 24 hours after becoming aware |
| Intermediate report | Within 72 hours of the initial notification |
| Final report | No later than one month after the intermediate report |
What it asks, in operating terms
Read as an operating requirement rather than a legal text, DORA reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when a supervisor asks for it.
| What DORA asks | Where it is answered |
|---|---|
| Classify and report major ICT incidents on the clock | Incident & resilience workflows · clocked from classification, named owner, sealed record |
| Maintain the register of information across the subcontracting chain | Supplier risk register · chains documented, continuously current |
| Manage concentration risk among ICT providers | Supplier risk register · concentration flagged by provider |
| Test digital operational resilience on schedule | Resilience testing · threat-led programmes tracked to evidence |
| Answer for ICT risk at board level | Board reporting · sourced from live control state |
What you'd actually look at
In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:
- Register of information
- 112 arrangements · subcontracting chains documented
- Major incidents · YTD
- 2 · initial within 4 hours · final within one month
- Resilience testing
- threat-led · current cycle complete
- Concentration flags
- 1 · under review
- Evidence
- sealed · sha256:8c41…d0b7
Where teams usually start
With a demo walked through by TruSecure — the DORA control set, a sample major-incident drill against the 4-hour clock, the register export an ICT examination will ask for. A Resilience Sprint then produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.
DORA Arts. 28-30 require a register of information covering the subcontracting chain supporting critical or important functions, Art. 29 addresses concentration risk, and Art. 28(8) requires an exit you can actually execute. Our register entry is one line, there is no hyperscaler concentration behind it, and full export works today — with the open core intended to make the exit demonstrable once Community Edition is released.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
DORA (Regulation (EU) 2022/2554) requires EU financial entities and their critical ICT third-party providers to manage ICT risk, report incidents on a defined classification and timeline, test digital operational resilience, and maintain a register of information on ICT third-party arrangements. TruSecure maintains that register continuously.