
DORA (EU 2022/2554)
Digital Operational Resilience Act
What is DORA (EU 2022/2554)?
The EU Digital Operational Resilience Act (DORA) came into force on 17 January 2025 and applies to banks, insurers, investment firms, crypto-asset providers, and their critical ICT third-party service providers operating in or serving the EU. DORA sets binding requirements for ICT risk management, incident reporting, digital operational resilience testing, third-party risk management, and information sharing — replacing a patchwork of national rules with a single EU-wide framework.
Key Focus Areas
How ICyberWave Helps
Our end-to-end consulting, implementation, and audit support approach
DORA Gap Assessment
We assess your current ICT risk, incident, testing, and third-party programs against DORA's five pillars.
ICT Risk Management Framework
We design and document the ICT risk framework, policies, and governance the regulation requires.
Register of Information
We help build and maintain the DORA register of ICT third-party contractual arrangements.
Resilience Testing Program
We define and support advanced testing programs, including threat-led penetration testing (TLPT) where applicable.
Incident Reporting Readiness
We build classification, escalation, and regulator-reporting workflows aligned to DORA templates and timelines.
Benefits of DORA (EU 2022/2554)
Who Needs This?
EU-authorised banks, insurers, investment firms, payment institutions, crypto-asset service providers, and any critical ICT third-party provider (cloud, SaaS, data analytics) serving EU financial entities.
Typical Timeline
4–8 months for a baseline DORA implementation; ongoing program required for testing, reporting, and third-party oversight.
Ready to Get Started with DORA (EU 2022/2554)?
Speak with our experts about consulting, implementation, and audit support for Digital Operational Resilience Act.
