
DORA Regulation (EU) 2022/2554: A Section-by-Section Deep Dive
This course walks section by section through Regulation (EU) 2022/2554 on digital operational resilience for the financial sector and two Commission Delegated Regulations governing ICT risk management controls and incident reporting. Learners will be able to interpret DORA’s scope, governance, resilience, testing, third-party oversight, enforcement, detailed control requirements, and reporting timelines as an integrated regulatory framework.
The first lecture plays free — no account needed.
What you'll learn
- Students will be able to identify the issuing institutions, legal form, and regulatory purpose of Regulation (EU) 2022/2554.
- Students will be able to relate financial-sector interconnectedness and digital dependence to the rationale for harmonised ICT-risk requirements.
- Students will be able to describe the role of recitals in framing DORA's operative provisions.
- Students will be able to distinguish DORA's sector-specific role from the general NIS2 framework.
- Students will be able to connect harmonised reporting and testing requirements to cross-border financial resilience.
- Students will be able to summarize the policy case for critical-provider oversight and voluntary threat-information exchange.
- Students will be able to explain how proportionality modifies DORA's application without removing accountability.
- Students will be able to connect management-body responsibility with continuity, recovery, and reporting expectations.
- Students will be able to describe the risk-based rationale for threat-led penetration testing.
- Students will be able to identify the strategic and contractual safeguards used to manage ICT dependencies.
Prerequisites
- DORA's legal status and harmonisation rationale
- Systemic ICT vulnerability
- DORA's relationship with NIS2
- Harmonised resilience requirements
- DORA proportionality
- Financial entities' continuing responsibility for ICT risk
Course Content
15 modules · 8h 10m total
DORA Regulation (EU) 2022/2554 — Origins of a Harmonised Resilience Regime
Why did financial-sector digitalisation require a directly applicable Union regulation rather than another collection of sectoral rules? The opening provisions and recitals situate DORA legally and trace the systemic vulnerabilities that motivated its harmonised approach.
DORA Regulation (EU) 2022/2554 — Cybersecurity Law, Reporting, Testing, and Third-Party Risk
DORA must coexist with wider Union cybersecurity law while addressing risks specific to finance. These recitals reveal how incident reporting, resilience testing, provider oversight, and voluntary intelligence sharing fit together.
DORA Regulation (EU) 2022/2554 — Proportionality, Governance, Recovery, and TLPT
A single regime cannot treat every financial entity identically. This chapter examines how DORA combines broad ICT coverage with proportionality, management accountability, recovery duties, streamlined reporting, and advanced threat-led penetration testing.
DORA Regulation (EU) 2022/2554 — Contracts and Critical ICT Provider Oversight
Outsourcing technology does not outsource regulatory responsibility. These recitals map the safeguards expected before, during, and after ICT contracts and justify Union oversight where provider concentration becomes systemically important.
DORA Regulation (EU) 2022/2554 — Oversight Architecture, Enforcement, and Legal Design
The final recitals turn policy into institutional machinery. They introduce Lead Overseers, examination teams, recommendations, penalties, technical standards, legislative amendments, and the constitutional principles supporting Union action.
DORA Regulation (EU) 2022/2554 — Scope, Definitions, and General Provisions
Who is covered, who is excluded, and what does DORA mean by its core terminology? Chapter I establishes the boundaries and vocabulary that control every later obligation.
DORA Regulation (EU) 2022/2554 — Governance, Identification, Protection, and Detection
Operational resilience begins before an incident occurs. Articles 5–10 move from management accountability to an auditable ICT framework, resilient systems, asset knowledge, protective controls, and rapid anomaly detection.
DORA Regulation (EU) 2022/2554 — Response, Recovery, Learning, and the Simplified Framework
What happens after disruption, and how should the regime scale for specified smaller entities? Articles 11–16 combine continuity and recovery engineering with post-incident learning, crisis communication, technical harmonisation, and a simplified but testable framework.
DORA Regulation (EU) 2022/2554 — ICT Incident Classification and Reporting
A disruption becomes a regulatory event through classification and reporting rules. Chapter III follows an incident from detection and impact assessment through initial, intermediate, and final reports, authority coordination, and possible future centralisation.
DORA Regulation (EU) 2022/2554 — Resilience Testing and Threat-Led Penetration Testing
Controls that exist only on paper do not establish resilience. Chapter IV sets a graduated testing programme and then imposes tightly governed threat-led penetration testing on selected entities.
DORA Regulation (EU) 2022/2554 — Financial Entities' ICT Third-Party Risk Duties
Cloud and technology contracts become part of the regulated control environment under Articles 28–30. This chapter examines strategy, registers, due diligence, concentration analysis, mandatory clauses, audit rights, contingency planning, and viable exits.
DORA Regulation (EU) 2022/2554 — Critical Provider Designation and Lead Overseer Powers
DORA's oversight framework begins with designation and extends into intrusive supervisory powers. Articles 31–36 show how critical providers are selected, organised under a Lead Overseer, examined, directed toward remediation, and addressed across Union borders.
DORA Regulation (EU) 2022/2554 — Oversight Procedures, Follow-Up, Fees, and Cooperation
Power must be exercised through defined procedures and followed by consequences. Articles 37–44 detail requests, investigations, inspections, examination teams, provider responses, possible service suspension, cost recovery, and international cooperation.
DORA Regulation (EU) 2022/2554 — Information Sharing, Supervision, Penalties, and Review
The wider supervisory ecosystem depends on trusted information exchange and coordinated enforcement. Articles 45–58 connect threat-sharing communities, competent authorities, sanctions, publication, secrecy, data protection, delegated powers, and scheduled reviews.
DORA Regulation (EU) 2022/2554 — Sectoral Amendments, Application, and Legislative References
DORA concludes by rewiring existing financial-services legislation around one consolidated ICT-risk regime. The final provisions and footnotes establish the amended instruments, application date, direct effect, legislative lineage, and authoritative cross-references.
Read the Textbook
Read every chapter for free, right here in your browser.
DORA Regulation (EU) 2022/2554 — Origins of a Harmonised Resilience Regime
Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector is commonly called DORA.
This lesson follows recitals (1) to (14), which explain why the Union adopted a single Regulation on digital operational resilience for the financial sector. These recitals provide the legal and policy rationale; they often say financial entities or Union action should do something. They do not themselves use the operative Articles' mandatory formulation, shall.
Study Flashcards
Key concepts from this course as flashcard pairs.
DORA Regulation (EU) 2022/2554 — Cybersecurity Law, Reporting, Testing, and Third-Party Risk
Lex specialis
Recital (16) states: "this Regulation constitutes lex specialis with regard to Directive (EU) 2022/2555". It describes DORA as the more specific framework in the relationship stated.
Single streamlined framework
Recital (24) describes harmonisation by "requiring all financial entities to report to their competent authorities through a single streamlined framework as set out in this Regulation".
Advanced testing
Recital (26) says a coordinated testing regime is necessary to facilitate mutual recognition of advanced testing for financial entities meeting DORA's criteria.
ICT third-party concentration
Recital (30) identifies systemic risk from financial-sector exposure to a limited number of critical ICT third-party service providers.
Intra-group ICT services
Recital (31) says they should not automatically be considered less risky than external ICT services, although higher control ought to be considered in overall risk assessment.
Voluntary information sharing
Recital (34) describes voluntary arrangements in trusted environments, subject to applicable competition law, data-protection rules, and an appropriate GDPR Article 6 legal basis.
DORA Regulation (EU) 2022/2554 — Proportionality, Governance, Recovery, and TLPT
How does Recital (35) describe ICT services?
"the definition of ICT services in the context of this Regulation should be understood in a broad manner, encompassing digital and data services provided through ICT systems to one or more internal or external users on an ongoing basis"
Which telephone services does Recital (35) exclude?
Only the limited category of traditional analogue telephone services qualifying as PSTN, landline services, POTS, or fixed-line telephone services.
What is the Recital (38) microenterprise rule?
"only financial entities that are not microenterprises in the sense of this Regulation should be required to establish more complex governance arrangements"
What is the management body's overarching principle in Recital (45)?
"The ultimate responsibility of the management body in managing a financial entity’s ICT risk should be an overarching principle of that comprehensive approach"
What does direct incident reporting enable under Recital (52)?
"The direct reporting should enable financial supervisors to have immediate access to information about major ICT-related incidents."
What conditions apply to using internal TLPT testers?
Supervisory approval, no conflicts of interest, and "periodical alternation of the use of internal and external testers (every three tests)". Threat intelligence must always be external.
DORA Regulation (EU) 2022/2554 — Contracts and Critical ICT Provider Oversight
Continuing responsibility
Recital (64): "A financial entity should at all times remain fully responsible for complying with its obligations set out in this Regulation."
Register of information
Recital (65) says all financial entities should be required to maintain it with all contractual arrangements concerning ICT services provided by ICT third-party service providers.
Concentration-risk approach
Financial entities should thoroughly assess concentration risk, including subcontracting; Recital (67) says strict caps and limits to ICT third-party exposures are not considered appropriate.
Audit rights for critical or important functions
Contracts should contain access, inspection, audit, and copy-taking rights for the financial entity or an appointed third party, with provider cooperation.
Third-country critical provider deadline
Within 12 months of designation, it should undertake all necessary arrangements to ensure incorporation within the Union by establishing a subsidiary.
Data localisation
DORA does not impose a data localisation obligation: it does not require data storage or processing to occur in the Union.
DORA Regulation (EU) 2022/2554 — Oversight Architecture, Enforcement, and Legal Design
Coordination point
Under recital (84), a critical ICT third-party service provider that is part of a group should designate one legal person as coordination point for communication with the Lead Overseer and adequate representation.
Oversight Forum
A new Subcommittee supporting the Joint Committee of the ESAs. It carries out preparatory work for individual decisions and collective recommendations, including oversight-programme benchmarking and ICT concentration-risk best practices.
Lead Overseer
Any of the three ESAs could be designated. Assignment should reflect the preponderance of financial entities in sectors for which that ESA has responsibilities.
JON
The joint oversight network identified in recital (91) as a means of close coordination among the ESAs in their Lead Overseer roles.
RTS
Draft regulatory technical standards developed by ESAs without policy choices and submitted to the Commission; recital (99) links them to Article 290 TFEU.
ITS
Draft implementing technical standards for standardised templates, forms, and procedures, including incident reports and the register of information; recital (100) links them to Article 291 TFEU.
+2 more flashcards
DORA Regulation (EU) 2022/2554 — Scope, Definitions, and General Provisions
Digital operational resilience
The ability of a financial entity to build, assure and review operational integrity and reliability by ensuring the full range of ICT-related capabilities needed for system security and continued financial services and quality, including throughout disruptions.
ICT-related incident
A single event or linked series of events unplanned by the financial entity that compromises system security and adversely affects availability, authenticity, integrity, confidentiality of data, or services.
Major ICT-related incident
An ICT-related incident with a high adverse impact on the network and information systems that support critical or important functions.
Critical or important function
A function whose disruption materially impairs financial performance, soundness, or continuity, or whose discontinued, defective, or failed performance materially impairs continuing legal compliance.
ICT third-party risk
ICT risk arising from use of ICT services provided by ICT third-party service providers or their subcontractors, including outsourcing arrangements.
Microenterprise
A financial entity, except a trading venue, central counterparty, trade repository, or central securities depository, with fewer than 10 persons and turnover and/or balance sheet total not exceeding EUR 2 million.
+2 more flashcards
DORA Regulation (EU) 2022/2554 — Governance, Identification, Protection, and Detection
Article 5: ultimate ICT-risk responsibility
The management body shall "bear the ultimate responsibility for managing the financial entity’s ICT risk".
Article 6(1): framework requirement
Financial entities shall have a sound, comprehensive and well-documented ICT risk management framework as part of their overall risk management system.
Article 6(4): independence model
Other than microenterprises, entities shall assign ICT-risk oversight to a control function and ensure segregation and independence according to the three lines of defence model, or an internal risk management and control model.
Article 6(5): review timing
The framework is reviewed at least once a year, or periodically in the case of microenterprises, plus after specified incidents, supervisory instructions, testing conclusions or audit conclusions.
Article 8(1): classification review
Financial entities shall review as needed, and at least yearly, the adequacy of this classification and of any relevant documentation.
Article 8(7): legacy systems
Other than microenterprises, entities shall assess all legacy ICT systems regularly and at least yearly, and in any case before and after connecting technologies, applications or systems.
+1 more flashcards
DORA Regulation (EU) 2022/2554 — Response, Recovery, Learning, and the Simplified Framework
Article 11(1): What is the central continuity obligation?
Financial entities shall put in place a comprehensive ICT business continuity policy. It may be a dedicated policy, but must form an integral part of the overall business continuity policy.
Article 11(6): What is the minimum testing frequency?
Financial entities shall test the ICT business continuity plans and ICT response and recovery plans for ICT systems supporting all functions at least yearly, and after substantive changes to systems supporting critical or important functions.
Article 12(3): What protects restoration from the compromised environment?
When restoring backup data using own systems, financial entities shall use ICT systems that are physically and logically segregated from the source ICT system.
Article 13(2): When is a post ICT-related incident review required?
After a major ICT-related incident disrupts the financial entity's core activities.
Article 14(3): Who handles public and media communication?
At least one person in the financial entity shall implement the communication strategy for ICT-related incidents and fulfil the public and media function.
Article 16: Does simplified mean no resilience duties?
No. Listed entities still shall maintain a sound, documented ICT risk management framework, ensure continuity, test plans and controls regularly, and review and improve the framework.
DORA Regulation (EU) 2022/2554 — ICT Incident Classification and Reporting
Article 17 recordkeeping rule
"Financial entities shall record all ICT-related incidents and significant cyber threats."
When is Article 19 reporting mandatory?
For major ICT-related incidents: "Financial entities shall report major ICT-related incidents to the relevant competent authority".
Are significant cyber threats reported in the same mandatory way?
No. Financial entities may, on a voluntary basis, notify significant cyber threats when they deem the threat relevant to the financial system, service users, or clients.
Name the three Article 19(4) reporting stages
An initial notification; an intermediate report after the initial notification; and a final report.
When is the final report submitted?
When root-cause analysis is completed and actual impact figures are available to replace estimates, regardless of whether mitigation measures have already been implemented.
Does outsourcing reporting remove responsibility?
No. The financial entity remains fully responsible for fulfilling incident-reporting requirements.
DORA Regulation (EU) 2022/2554 — Resilience Testing and Threat-Led Penetration Testing
Article 24(1): What must relevant entities establish?
They shall, other than microenterprises and taking Article 4(2) criteria into account, establish, maintain and review a sound and comprehensive digital operational resilience testing programme as an integral part of the Article 6 ICT risk-management framework.
Article 24(6): What is the annual minimum?
At least yearly, appropriate tests must be conducted on all ICT systems and applications supporting critical or important functions. The rule applies to financial entities other than microenterprises.
Article 26(1): How often is TLPT required?
Identified financial entities within the provision's scope shall carry out at least every 3 years advanced testing by means of TLPT. The competent authority may request a reduced or increased frequency where necessary.
Article 26(2): Where is TLPT performed?
On live production systems supporting the several or all critical or important functions covered by the threat-led penetration test.
Article 26(8): What is the internal-tester rotation rule?
When financial entities use internal testers for TLPT, they shall contract external testers every three tests.
Article 27(2)(c): What is required for internal-tester use?
The threat-intelligence provider is external to the financial entity, in addition to the Article 27(1) requirements and the other Article 27(2) conditions.
DORA Regulation (EU) 2022/2554 — Financial Entities' ICT Third-Party Risk Duties
Who remains responsible after ICT outsourcing?
Under Article 28(1)(a), the financial entity shall, at all times, remain fully responsible for compliance with and discharge of DORA and applicable financial services law obligations.
What does the Article 28(3) register cover?
All contractual arrangements on the use of ICT services provided by ICT third-party service providers, maintained and updated at entity, sub-consolidated, and consolidated levels.
How often is Article 28(3) reporting required?
At least yearly, covering the number of new arrangements, provider categories, contract types, and ICT services and functions provided.
Name one Article 29 concentration-risk indicator.
An envisaged critical-or-important-function arrangement would use a provider that is not easily substitutable, or create multiple such arrangements with the same or closely connected providers.
What three outcomes must an Article 28(8) exit avoid?
Disruption to business activities, limiting compliance with regulatory requirements, and detriment to continuity and quality of services provided to clients.
What is the central Article 30(3) audit-rights phrase?
Unrestricted rights of access, inspection and audit by the financial entity, or an appointed third party, and by the competent authority.
DORA Regulation (EU) 2022/2554 — Critical Provider Designation and Lead Overseer Powers
Who designates critical ICT third-party service providers?
The ESAs, through the Joint Committee and upon recommendation from the Oversight Forum, shall designate them under Article 31(1)(a).
What is the Article 31(2)(a) systemic-impact phrase?
The assessment considers "the systemic impact on the stability, continuity or quality of the provision of financial services".
How often is the Union list updated?
The ESAs, through the Joint Committee, shall establish, publish and update yearly the list of critical ICT third-party service providers at Union level.
What is the deadline for a reasoned statement after assessment notification?
Within 6 weeks from the date of notification under Article 31(5).
What is the third-country subsidiary condition?
Financial entities shall use the designated critical provider only if it has established a subsidiary in the Union within the 12 months following designation.
What does the Oversight Forum support?
It is established as a sub-committee for supporting the work of the Joint Committee and of the Lead Overseer.
+4 more flashcards
DORA Regulation (EU) 2022/2554 — Oversight Procedures, Follow-Up, Fees, and Cooperation
Article 37: What is the difference between a simple request and a decision?
A simple request informs the representative that he or she is not obliged to provide information, although any voluntary reply must not be incorrect or misleading. A decision adds Article 35(6) periodic penalty-payment information and appeal and Court of Justice review rights.
Article 38: What is the central examination power?
The Lead Overseer may "examine records, data, procedures and any other material relevant to the execution of its tasks, irrespective of the medium on which they are stored".
Article 39: What must inspections cover?
"Inspections shall cover the full range of relevant ICT systems, networks, devices, information and data" used for, or contributing to, ICT services for financial entities.
Article 40: What team supports oversight?
The Lead Overseer shall be assisted by a joint examination team established for each critical ICT third-party service provider.
Article 40: When are recommendations adopted?
Within 3 months of completion of an investigation or inspection, after consulting the Oversight Forum.
Article 42: How long does a provider have to respond to recommendations?
Within 60 calendar days of receipt, it shall notify an intention to follow them or give a reasoned explanation for not following them.
+2 more flashcards
DORA Regulation (EU) 2022/2554 — Information Sharing, Supervision, Penalties, and Review
Article 45: What is the central permission?
"Financial entities may exchange amongst themselves cyber threat information and intelligence, including indicators of compromise, tactics, techniques, and procedures".
Article 45: Where must sharing take place?
It "takes places within trusted communities of financial entities" and must meet the other Article 45 conditions.
Article 45: What must an entity notify?
"Financial entities shall notify competent authorities of their participation in the information-sharing arrangements" upon membership validation, and of cessation, as applicable, once effective.
Article 48: What is mandatory?
"Competent authorities shall cooperate closely among themselves and, where applicable, with the Lead Overseer."
Article 50: What standard applies to penalties and measures?
"Those penalties and measures shall be effective, proportionate and dissuasive."
Article 54: How long may a publication remain online?
"This period shall not exceed five years after its publication."
+2 more flashcards
DORA Regulation (EU) 2022/2554 — Sectoral Amendments, Application, and Legislative References
Credit rating agency ICT wording
It shall have **effective control and safeguard arrangements for managing ICT systems in accordance with Regulation (EU) 2022/2554**.
CCP ICT systems wording
A CCP shall employ appropriate and proportionate systems, resources and procedures, including **ICT systems managed in accordance with Regulation (EU) 2022/2554**.
CSD recovery object
The plan shall provide for recovery of **all transactions and participants' positions at the time of disruption**.
Data reporting services duty
An APA, CTP, or ARM **shall comply with the requirements concerning the security of network and information systems set out in Regulation (EU) 2022/2554**.
Critical benchmark qualifier
Article 63 adds the ICT-governance requirement **for critical benchmarks**.
Application date
**It shall apply from 17 January 2025.**
+2 more flashcards
More in Legal
See all →
Mastering the EU NIS2 Directive: From Legal Framework to Practical Compliance

Commission Implementing Regulation (EU) 2024/2690: Cybersecurity Measures and Significant-Incident Thresholds

EU:s AI-förordning artikel för artikel

Understanding the EU’s New Legislative Framework

Förstå EU:s allmänna produktsäkerhetsförordning (GPSR) i detalj
