Seclore | DORA Compliance
Skip to content

DORA includes specific provisions to enforce stringent third-party risk management practices.

DORA requires financial service entities to establish robust digital operational testing programs.

DORA is looking to build on the already existing BASEL II Operational Risk Management Framework and others that have regulated this sector for over 20 years.

What is DORA?

The Digital Operational Resilience Act (DORA) sets out detailed requirements for EU-based financial services industry (FSI) entities and their information and communication technology (ICT) third-party service providers on how to build out a more operationally resilient digital ecosystem. It is a part of the EU’s initiative “An Europe fit for the digital age”. It seeks to build on and harmonize regulations related to ICT technology, cyber risk management incident reporting, resilience testing and third-party risk management.

DORA as a legislative agenda brings forward significant obligations to both FSIs and ICT third-party service providers. The regulation itself is designed to create a unified approach to operational resilience to more effectively manage, monitor, and mitigate the risks associated with the general interconnectedness and concentration of the financial sector.