DORA Regulation
Definition
DORA Regulation
The DORA regulation is the European Union’s Digital Operational Resilience Act, which applies to financial entities and the technology suppliers they rely on. It regulates those suppliers directly, creating oversight of firms that have never held a financial licence.
Most financial regulation reaches suppliers through the institutions that buy from them.
This one does both. It sets obligations on financial entities and, separately, brings the most systemically important technology providers under direct European oversight.
That second limb is the structural novelty — a cloud provider can now be supervised in its own right rather than only through its customers.
Key takeaways
- The regulation entered into application on 17 January 2025.
- Financial entities must maintain a register of information on all ICT contractual arrangements.
- Contracts must contain specified minimum terms rather than negotiated equivalents.
- Critical providers are designated and supervised directly at European level.
How it works
Application is fixed and recent. The regulation entered into application on 17 Jan 2025, covering ICT risk management, incident reporting, resilience testing, third party risk and information sharing.
The register is the central compliance artefact.
Financial entities must maintain a register of information with all contractual arrangements about the use of ICT services provided by ICT third-party service providers, which supervisors use to see sector-wide dependencies.
Contract content is prescribed rather than suggested — required elements include the functions and services, data processing locations, service levels, accessibility and security guarantees, recovery provisions, incident assistance and termination rights with notice.
| Obligation | Who carries it |
|---|---|
| ICT risk management framework | The financial entity |
| Register of information | The financial entity, submitted to supervisors |
| Minimum contractual terms | Both, through the contract |
| Incident reporting | The financial entity, assisted by the provider |
| Resilience testing | The financial entity, with provider cooperation |
| Direct oversight | Designated critical ICT third party providers |
Criticality is determined rather than self-declared — designation uses quantitative and qualitative criteria that set criticality parameters, aimed at the concentration risk of a sector depending on very few suppliers.
The oversight framework then applies at European level. It addresses systemic and concentration risks arising from the financial sector’s reliance on a limited number of providers, which no earlier instrument attempted.
That is a genuine shift in who answers to whom. A provider’s obligations now run to supervisors as well as to the customers who pay it.
Examples
The regulation changed procurement conversations across European financial services within a single year of applying. What follows are engagements where the compliance question arrived after the pricing did.
A German insurer discovers its register requires fields its contracts never captured. The remediation is contractual, and renewal dates rather than compliance deadlines set the pace.
A Dutch bank’s core provider refuses an exit assistance clause. The clause is a required element, so the negotiation is about wording rather than about whether it appears.
A payments firm depends on one cloud region for everything. Concentration is exactly what the oversight framework targets, and the firm’s own testing has to reflect it.
A technology provider outside the financial sector finds itself designated as critical. It is now supervised directly despite never having held a licence of any kind. Its compliance function was built for customers, and now it has a supervisor.
Related terms
European resilience rules overlap with security standards and with older outsourcing guidance that has not gone away. Each term below appears in the same conversations and carries a different duty.
- Cybersecurity outsourcing: buying security capability rather than regulating resilience.
- ISO 22301: the business continuity management standard used as supporting evidence.
- Business continuity plan (BCP): the operational artefact resilience testing exercises.
- Regulated outsourcing: supervised sector outsourcing across industries.
- Banking outsourcing: one of the populations inside scope.
- Data centre outsourcing: the arrangements most likely to be caught.
- Vendor management outsourcing: the programme that maintains the register.
FAQ
When did the regulation start applying?
It entered into application on 17 January 2025, following its publication in the Official Journal at the end of 2022.
Who does it cover?
Financial entities across banking, insurance, investment and payments, together with the ICT third party service providers supplying them.
What is the register of information?
A structured record of all contractual arrangements for ICT services, maintained by the financial entity and used by supervisors to map dependencies.
Are contract terms really mandatory?
Yes. Specific elements must appear, including service levels, data locations, security guarantees, incident assistance and termination rights.
What does critical designation mean for a provider?
It brings the provider under direct European oversight, with obligations owed to supervisors rather than only to customers.
Does it replace the banking outsourcing guidelines?
No. It applies alongside them, covering technology arrangements while the older guidance continues to govern outsourcing more broadly.
Search verified partners in the Outsource Accelerator directory and start with providers who have read the contractual minimums.







Independent




