• 4,000 firms
  • Independent
  • Trusted
Save up to 70% on staff

Home » Glossary » DORA Regulation

DORA Regulation

Definition

DORA Regulation

The DORA regulation is the European Union’s Digital Operational Resilience Act, which applies to financial entities and the technology suppliers they rely on. It regulates those suppliers directly, creating oversight of firms that have never held a financial licence.

Most financial regulation reaches suppliers through the institutions that buy from them.

This one does both. It sets obligations on financial entities and, separately, brings the most systemically important technology providers under direct European oversight.

That second limb is the structural novelty — a cloud provider can now be supervised in its own right rather than only through its customers.

Key takeaways

  • The regulation entered into application on 17 January 2025.
  • Financial entities must maintain a register of information on all ICT contractual arrangements.
  • Contracts must contain specified minimum terms rather than negotiated equivalents.
  • Critical providers are designated and supervised directly at European level.

How it works

Application is fixed and recent. The regulation entered into application on 17 Jan 2025, covering ICT risk management, incident reporting, resilience testing, third party risk and information sharing.

The register is the central compliance artefact.

Financial entities must maintain a register of information with all contractual arrangements about the use of ICT services provided by ICT third-party service providers, which supervisors use to see sector-wide dependencies.

Contract content is prescribed rather than suggested — required elements include the functions and services, data processing locations, service levels, accessibility and security guarantees, recovery provisions, incident assistance and termination rights with notice.

ObligationWho carries it
ICT risk management frameworkThe financial entity
Register of informationThe financial entity, submitted to supervisors
Minimum contractual termsBoth, through the contract
Incident reportingThe financial entity, assisted by the provider
Resilience testingThe financial entity, with provider cooperation
Direct oversightDesignated critical ICT third party providers

Criticality is determined rather than self-declared — designation uses quantitative and qualitative criteria that set criticality parameters, aimed at the concentration risk of a sector depending on very few suppliers.

The oversight framework then applies at European level. It addresses systemic and concentration risks arising from the financial sector’s reliance on a limited number of providers, which no earlier instrument attempted.

That is a genuine shift in who answers to whom. A provider’s obligations now run to supervisors as well as to the customers who pay it.

Examples

The regulation changed procurement conversations across European financial services within a single year of applying. What follows are engagements where the compliance question arrived after the pricing did.

A German insurer discovers its register requires fields its contracts never captured. The remediation is contractual, and renewal dates rather than compliance deadlines set the pace.

A Dutch bank’s core provider refuses an exit assistance clause. The clause is a required element, so the negotiation is about wording rather than about whether it appears.

A payments firm depends on one cloud region for everything. Concentration is exactly what the oversight framework targets, and the firm’s own testing has to reflect it.

A technology provider outside the financial sector finds itself designated as critical. It is now supervised directly despite never having held a licence of any kind. Its compliance function was built for customers, and now it has a supervisor.

Related terms

European resilience rules overlap with security standards and with older outsourcing guidance that has not gone away. Each term below appears in the same conversations and carries a different duty.

FAQ

When did the regulation start applying?

It entered into application on 17 January 2025, following its publication in the Official Journal at the end of 2022.

Who does it cover?

Financial entities across banking, insurance, investment and payments, together with the ICT third party service providers supplying them.

What is the register of information?

A structured record of all contractual arrangements for ICT services, maintained by the financial entity and used by supervisors to map dependencies.

Are contract terms really mandatory?

Yes. Specific elements must appear, including service levels, data locations, security guarantees, incident assistance and termination rights.

What does critical designation mean for a provider?

It brings the provider under direct European oversight, with obligations owed to supervisors rather than only to customers.

Does it replace the banking outsourcing guidelines?

No. It applies alongside them, covering technology arrangements while the older guidance continues to govern outsourcing more broadly.

Search verified partners in the Outsource Accelerator directory and start with providers who have read the contractual minimums.

Companies you might be interested in

Get Inside Outsourcing

An insider's view on why remote and offshore staffing is radically changing the future of work.

Order now

Start your
journey today

  • Independent
  • Secure
  • Transparent

About OA

Outsource Accelerator is the trusted source of independent information, advisory and expert implementation of Business Process Outsourcing (BPO).

The #1 outsourcing authority

Outsource Accelerator offers the world’s leading aggregator marketplace for outsourcing. It specifically provides the conduit between world-leading outsourcing suppliers and the businesses – clients – across the globe.

The Outsource Accelerator website has over 5,000 articles, 450+ podcast episodes, and a comprehensive directory with 4,700+ BPO companies… all designed to make it easier for clients to learn about – and engage with – outsourcing.

About Derek Gallimore

Derek Gallimore has been in business for 20 years, outsourcing for over eight years, and has been living in Manila (the heart of global outsourcing) since 2014. Derek is the founder and CEO of Outsource Accelerator, and is regarded as a leading expert on all things outsourcing.

“Excellent service for outsourcing advice and expertise for my business.”

Learn more
Banner Image
Get 3 Free Quotes Verified Outsourcing Suppliers
4,000 firms.Just 2 minutes to complete.
SAVE UP TO
70% ON STAFF COSTS
Learn more

Connect with over 4,000 outsourcing services providers.

Banner Image

Transform your business with skilled offshore talent.

  • 4,000 firms
  • Simple
  • Transparent
Banner Image