Chapter 1 of 15
DORA Regulation (EU) 2022/2554 — Origins of a Harmonised Resilience Regime
Why did financial-sector digitalisation require a directly applicable Union regulation rather than another collection of sectoral rules? The opening provisions and recitals situate DORA legally and trace the systemic vulnerabilities that motivated its harmonised approach.
1. Start Here: What Problem Is DORA Addressing?
The instrument
Regulation (EU) 2022/2554, known as DORA, concerns digital operational resilience for the financial sector. This module follows recitals (1) to (14) in their own order.
Read recitals carefully
The recitals explain why DORA was adopted. Their should language remains non-mandatory in this lesson; a mandatory shall must be attributed to an operative Article.
Currency check
As of 24 July 2026, DORA is in force and has applied since 17 January 2025. The supplied recitals remain the focus of this module.
2. Recital (1): Digitalisation Creates ICT Risk
ICT enables finance
Recital (1) says ICT supports complex systems, keeps economies running in key sectors including finance, and enhances the internal market's functioning.
The trade-off
Increased digitalisation and interconnectedness amplify ICT risk, making society and the financial system more vulnerable to cyber threats or ICT disruptions.
The identified gap
ICT use and connectivity are core features of Union financial entities, but their digital resilience has yet to be better addressed and integrated into broader operational frameworks.
3. Recital (2): Where ICT Now Sits in Financial Services
Digital financial functions
Recital (2) lists payments, clearing and settlement, electronic and algorithmic trading, lending, peer-to-peer finance, credit rating, claims, and back-office operations.
Insurance is included
The insurance sector has also been transformed: Recital (2) refers to online intermediaries operating with InsurTech and to digital insurance underwriting.
Dependency chain
A digital premium payment can cross customer systems, payment services, identity checks, internal records, and third-party infrastructure. Interdependence is therefore a resilience issue.
4. Recital (3): From a Local Incident to Systemic Vulnerability
ESRB's systemic framing
Recital (3) links systemic vulnerability to the high interconnectedness of financial entities, markets, market infrastructures, and their ICT systems.
Load-bearing finding
"localised cyber incidents could quickly spread from any of the approximately 22 000 Union financial entities to the entire financial system, unhindered by geographical boundaries"
Possible consequences
Serious ICT breaches may propagate through financial transmission channels and potentially trigger liquidity runs plus an overall loss of confidence and trust in financial markets.
5. Thought Exercise: Trace the Spillover
Trace a local incident
A cyber incident disrupts a technology-dependent function at one financial entity.
Using Recitals (2) and (3) only, sketch a three-stage pathway:
- Local function affected: Choose one function expressly listed in Recital (2), such as payments, clearing and settlement, or claim management.
- Connection: Identify one kind of dependency Recital (2) identifies: another financial-sector connection or a third-party infrastructure or service provider.
- Systemic consequence: Choose a consequence named in Recital (3): propagation through financial transmission channels, liquidity runs, or loss of confidence and trust in financial markets.
Self-check
A strong answer explains how interconnectedness changes the scale of the event. It does not need to assume that every incident produces a systemic crisis. Recital (3) says these consequences can be potential.
6. Recitals (4) to (7): The Policy Path Toward a Union Initiative
International attention
Recital (4) identifies international and Union-level work on ICT risk. A shared concern was consistency of resilience practices in an interconnected global financial system.
The post-2008 imbalance
Recital (5) says post-2008 reforms primarily strengthened financial resilience, while ICT security and digital resilience received less attention in the regulatory agenda.
From policy to initiative
The 2018 FinTech Action Plan and the ESAs' April 2019 technical advice supported a coherent, proportionate, sector-specific Union initiative on ICT risk.
7. Recitals (8) to (10): Why Existing Rules Were Not Enough
Not fully harmonised
Under Recital (8), the Single Rulebook existed, but provisions on digital operational resilience and ICT security were not yet fully or consistently harmonised.
Cross-border friction
Recital (9) links national disparities to obstacles for cross-border financial services, distorted competition, limited testing harmonisation, and absent ICT third-party-risk monitoring harmonisation.
Gaps, overlaps, and cost
Recital (10) identifies gaps or overlaps in incident reporting and resilience testing, as well as the cost of divergent or overlapping rules for cross-border entities.
8. Recitals (11) and (12): Harmonise, Consolidate, and Upgrade
Why harmonise?
Recital (11) says "further harmonisation of key digital operational resilience requirements for all financial entities is required" because no comprehensive ICT or operational-risk framework accompanied the Single Rulebook.
Beyond capital
Recital (12) contrasts a traditional quantitative approach to ICT risk with qualitative capabilities for protection, detection, containment, recovery, repair, reporting, and digital testing.
One legislative act
"all provisions addressing digital risk in the financial sector should for the first time be brought together in a consistent manner in one single legislative act"
9. Recital (13): Common Principles, Proportionate Application
A common approach
"Financial entities should follow the same approach and the same principle-based rules when addressing ICT risk"
The qualification matters
Recital (13) qualifies that common approach: it takes account of size, overall risk profile, and the nature, scale, and complexity of services, activities, and operations.
Cyber hygiene
Recital (13) says observing basic cyber hygiene should minimise the impact and costs of ICT disruptions and thereby avoid heavy costs for the economy.
10. Check Your Understanding: Why a Regulation?
Choose the best answer
According to Recital (14), why was a Regulation considered the most appropriate legal instrument for a common framework on the digital operational resilience of financial entities?
Which answer most closely reflects Recital (14)?
- A Regulation helps reduce regulatory complexity, fosters supervisory convergence, increases legal certainty, limits cross-border compliance costs, reduces competitive distortions, and guarantees homogenous and coherent application of ICT-risk-management components.
- A Regulation lets each Member State choose entirely different resilience requirements while preserving a common financial market.
- A Regulation was chosen because financial entities no longer rely on ICT third-party service providers.
- A Regulation replaces every prudential, market-integrity, and market-conduct rule in Union financial law.
Show Answer
Answer: A) A Regulation helps reduce regulatory complexity, fosters supervisory convergence, increases legal certainty, limits cross-border compliance costs, reduces competitive distortions, and guarantees homogenous and coherent application of ICT-risk-management components.
Correct. Recital (14) says a Regulation helps reduce regulatory complexity, fosters supervisory convergence and legal certainty, limits compliance costs and competitive distortions, and is the most appropriate way to guarantee homogenous and coherent application of all components of ICT risk management. It does not say that all other financial rules are replaced.
Key Terms
- ICT
- Information and communication technology. In Recital (1), ICT supports complex systems used for everyday activities and is central to financial entities' activities.
- ICT risk
- Risk linked to ICT use, including exposure to cyber threats or ICT disruptions. Recitals (1) to (14) present it as a financial-sector resilience and internal-market issue.
- Single Rulebook
- The Union financial sector's common regulatory framework, referred to in Recital (8). The recital says digital operational resilience and ICT security were not yet fully or consistently harmonised within it.
- Article 114 TFEU
- The Treaty on the Functioning of the European Union legal basis identified in Recital (11) for a measure contributing to the smooth functioning of the internal market.
- ICT third-party risk
- Risk associated with dependencies on ICT third-party infrastructure or service providers. Recitals (9) and (12) identify monitoring of this risk as an area needing Union-level attention.
- Principle-based rules
- Rules stated at the level of governing principles rather than identical detailed measures for every entity. Recital (13) pairs them with consideration of size, risk profile, and operational complexity.
- Systemic vulnerability
- A vulnerability that can affect the financial system beyond one entity. Recital (3) links it to ICT interdependencies across entities, markets, and financial market infrastructures.
- Digital operational resilience
- The capacity addressed by DORA's framework for dealing with ICT risk and operational disruption. The supplied recitals explain why it required more coherent Union treatment.
- European Supervisory Authorities (ESAs)
- The collective name used in Recital (7) for the EBA, EIOPA, and ESMA.