DORA

Where ICT risk, incidents, testing, and third-party oversight meet in day-to-day operations.

Anchor the program in critical services

The Digital Operational Resilience Act applies to EU financial entities and creates a common framework for ICT risk. A practical program starts with the services customers and markets depend on, the technology that supports them, and the failure scenarios that could disrupt them.

Map governance, ICT assets, dependencies, recovery objectives, and existing controls to those services. This makes investment decisions sharper than a list of policy gaps alone.

Connect incidents, testing, and recovery

Incident handling is more than a reporting workflow. Teams need a shared view of classification, escalation, response, recovery, and learning. Resilience testing should challenge assumptions about important systems, people, and suppliers, then feed findings into remediation.

Exercises are most useful when they force decisions: who declares an incident, how an essential service is restored, which communication is required, and what evidence is retained. The answers should update plans and controls.

Treat third-party oversight as a live dependency map

ICT providers are woven into financial services. Contracts, concentration risk, service dependencies, exit planning, and registers of information need consistent ownership. The register should reflect the actual service landscape, not be assembled at the last minute from disconnected procurement records.

Bring procurement, technology, legal, and risk teams into a common process for onboarding, monitoring, change, and exit. That process should reveal when an outsourced service becomes critical to an important business function.

Use evidence to manage, not only to report

DORA has applied since 17 January 2025. A mature response shows management how resilience is performing: unresolved vulnerabilities, test results, incident trends, third-party concerns, and accepted risks. Evidence should support decisions and regulatory engagement at the same time.

Put it into practice

  • Map critical services to ICT assets and external providers.
  • Connect incident response, recovery plans, and testing findings in one improvement cycle.
  • Reconcile the ICT third-party register with procurement and technology records.
  • Give management a view of unresolved resilience risks and accountable remediation.

Primary sources

Normstone resources are general information, not legal advice or an independent assessment.

All resources