DORA — EU Digital Operational Resilience Act: regulation, RTS/ITS and Q&A
Covers Regulation (EU) 2022/2554 (DORA) and its technical standards on the ICT risk management framework and simplified framework, major incident classification and notification deadlines, the register of information, Article 30 contractual provisions, subcontracting, threat-led penetration testing (TLPT) and the oversight regime for critical ICT third-party providers, together with the ESAs' Q&A and practical reporting guidance. Built for CISOs and risk officers at banks, insurers, investment firms and payment institutions, and for ICT third-party providers, to answer precise questions on scope, thresholds, deadlines and contractual clauses. Curated by Kopik from public sources: EUR-Lex (reuse authorised, Decision 2011/833/EU), EBA and ESMA (reproduction authorised with acknowledgement).
Posez votre question
Compte gratuit requisLes réponses sont rédigées par un modèle de langage à partir des seuls documents de cette base, avec leurs sources numérotées. Elles peuvent être inexactes et ne constituent pas un conseil juridique, médical ou financier : vérifiez les sources avant toute décision importante.
This assistant answers precise questions on the EU Digital Operational Resilience Act (Regulation (EU) 2022/2554, DORA) and its technical standards: scope, ICT risk management, incident reporting, the register of information, contracts with ICT providers, testing and oversight. It is built for risk officers, CISOs and compliance teams at banks, insurers, investment firms and payment institutions, and for the ICT providers that serve them. Answers rely on the regulation text and delegated acts published on EUR-Lex, and on Q&A and guidance from the European Supervisory Authorities (EBA, ESMA).
Proportionality: the simplified ICT risk management framework
Article 16 of DORA lifts Articles 5 to 15 for certain smaller entities: small and non-interconnected investment firms, exempted payment institutions, exempted electronic money institutions, certain exempted credit institutions and small institutions for occupational retirement provision.
These entities are not exempt from managing ICT risk. They must still put in place a sound and documented ICT risk management framework, continuously monitor the security and functioning of all their ICT systems, and use sound, resilient and updated systems and tools. The details are set out in Delegated Regulation (EU) 2024/1774.
The ESAs have confirmed in Q&A 2025_7388 that the simplified regime does not remove the register of information: all financial entities subject to DORA must maintain one, with proportionality already built into its requirements.
The register of information on ICT third-party arrangements
Article 28(3) of DORA requires financial entities to maintain and update a register of information covering all their contractual arrangements on the use of ICT services provided by ICT third-party service providers. Implementing Regulation (EU) 2024/2956 sets the templates to use, found in its Annexes I to IV.
The register is kept at entity level and, for groups, at sub-consolidated and consolidated level. In a group, the parent undertaking determines which entities are included, and the entities responsible for the consolidated register must ensure that entity-level data is correct and consistent with it.
According to the ESAs, the scope of a sub-consolidated or consolidated register should reflect all financial entities and their branches within the consolidation scope. Providers are categorised by the type of service they supply, using the typology of services in Annex III of the implementing regulation, and each entity designates its own functions with a function identifier.
What counts as an ICT service under DORA
DORA defines ICT services broadly, covering any digital service that directly contributes to the functioning of a financial entity's information and communication systems. The only telephony exclusion concerns traditional analogue telephone services.
According to Q&A 2025_7539, that exclusion cannot be extended to fibre optic networks, including dark fibre. What matters is the transmission technology, not the cable: fibre carries digital signals and is therefore part of an ICT service.
Public authorities are treated differently. Q&A 2025_7466 reads Recital 63 broadly: public authorities providing ICT-related services in the context of State functions are not ICT third-party service providers, so the Article 30(2) contractual requirements do not apply to them.
Oversight of critical ICT third-party providers
Some ICT providers are designated as critical by the ESAs and placed under a direct oversight framework run by a Lead Overseer. The designation criteria are detailed in Delegated Regulation (EU) 2024/1502.
A provider that has not been designated may ask to be, by sending a reasoned application to the ESAs. According to the ESMA oversight page, the ESAs reply within 6 months of formal receipt, and applications should be written in English.
If a critical provider does not comply with measures required by the Lead Overseer, a periodic penalty payment can be imposed after at least 30 calendar days. It is applied daily, for no more than six months, and can reach up to 1 % of the provider's average daily worldwide turnover in the preceding business year.
Questions fréquentes
Does a phishing attack on a customer count as a major ICT-related incident?
Not when it happens in the customer's private sphere and does not affect the financial entity's services, according to Q&A 2025_7613. It then cannot trigger the major incident thresholds. If the entity itself is targeted, for example through phishing emails to employees leading to an intrusion, it can qualify as an ICT-related incident and possibly a major one.
Do staff overtime and incident handling hours count in the cost of an incident?
Yes. Q&A 2025_7439 states that overtime clearly attributable to an incident counts towards staff costs even when compensated through working time arrangements, and so does working time clearly allocated to handling it. Preventive staff training is excluded, as a day-to-day operating cost.
Is a vLAN enough for a separate and dedicated administration network?
DORA and its standards are technology agnostic, so logical separation, physical separation or both may be adequate depending on the entity's risk assessment. Q&A 2024_7178 warns that a vLAN alone may not be sufficient and suggests complementing it with controls such as a firewall with an appropriate filtering policy.
How is the register of information sent to supervisors?
Competent authorities provide the registers to the ESAs on a yearly basis, which generally fulfils the requirement. Financial entities must also make the register available to their competent authority on request, and inform it in a timely manner of planned arrangements supporting critical or important functions.
Must ICT subcontractors of a non-ICT provider appear in the register?
No. Under Q&A 2024_7089, where the direct provider does not supply an ICT service, the service is outside the register, and so are the ICT subcontractors it uses. Chapter V requirements may still apply if the entity's risk assessment shows the subcontracted service is in substance equivalent to a direct ICT service supporting a critical or important function.
Intégrer / API / MCP
Branchez cette base à Claude, Cursor, ChatGPT ou votre propre application. Chaque requête API ou MCP coûte 0,10 €, débitée de votre crédit Kopik (non facturée si rien n'est trouvé). Il vous faut une clé API : créez-la depuis votre tableau de bord.
MCP pour vos agents
Adresse du serveur MCP de cette base (outils ask_base et search_base) :
https://kopik.io/api/mcp?base=eu-dora-ict-resilienceClaude Code, Cursor et autres clients
claude mcp add --transport http kopik-eu-dora-ict-resilience "https://kopik.io/api/mcp?base=eu-dora-ict-resilience" --header "Authorization: Bearer kpk_…"{
"mcpServers": {
"kopik-eu-dora-ict-resilience": {
"url": "https://kopik.io/api/mcp?base=eu-dora-ict-resilience",
"headers": {
"Authorization": "Bearer kpk_…"
}
}
}
}API REST pour vos applications
mode vaut "answer" (réponse rédigée + sources) ou "passages" (passages bruts seulement). Ajoutez un maxPriceCents facultatif pour plafonner le prix : si la base coûte plus cher, l'appel est refusé sans rien débiter.
curl -X POST https://kopik.io/api/v1/bases/eu-dora-ict-resilience/query \
-H "Authorization: Bearer kpk_…" \
-H "Content-Type: application/json" \
-d '{"question": "Votre question ici", "mode": "answer"}'Pour commencer
- Créez une clé dans votre tableau de bord et rechargez votre crédit.
- Remplacez
kpk_…par votre clé. - Tout le détail (réponses, erreurs, exemples JS et Python) : documentation développeurs.