DORA anchors

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

Primary text

  • Regulation (EU) 2022/2554 β€” DORA. Published OJEU 27 December 2022. Applicable 17 January 2025.
  • Directive (EU) 2022/2556 β€” companion directive amending sector-specific regulations to enable DORA application.
  • Recitals β€” 106 recitals.
  • Articles β€” 64 articles.

RTS / ITS publications (selected)

ESAs published numerous Regulatory Technical Standards and Implementing Technical Standards specifying technical and operational requirements. Examples:

  • RTS on ICT risk management framework
  • RTS on classification of major ICT-related incidents
  • ITS on reporting of major ICT-related incidents
  • RTS on TLPT β€” threat-led penetration testing
  • RTS on policy on the use of ICT services supporting critical or important functions
  • RTS on register of information
  • RTS on subcontracting of ICT services
  • RTS on harmonization of conditions enabling the conduct of oversight activities
  • ITS on register of information

ESAs (Joint Committee for DORA)

  • EBA (European Banking Authority) β€” eba.europa.eu
  • ESMA (European Securities and Markets Authority) β€” esma.europa.eu
  • EIOPA (European Insurance and Occupational Pensions Authority) β€” eiopa.europa.eu

Joint Committee coordinates cross-ESA work.

National competent authorities (DE example)

  • BaFin (Bundesanstalt fΓΌr Finanzdienstleistungsaufsicht) β€” banking, insurance, securities.
  • Bundesbank β€” central bank cooperation.
  • TIBER-EU β€” Threat Intelligence-Based Ethical Red Teaming framework. Foundation for DORA TLPT.
  • EBA Guidelines on ICT and Security Risk Management β€” predecessor for banking.
  • EBA Outsourcing Guidelines β€” predecessor for outsourcing arrangements.

Adjacent EU legislation

  • NIS2 (Dir 2022/2555) β€” lex generalis; DORA prevails for financial entities.
  • MiCA (Reg 2023/1114) β€” Markets in Crypto-Assets. Applies alongside DORA for CASPs.
  • GDPR β€” co-applies.
  • EU AI Act β€” AI features in financial entities co-apply.

Reference resources

  • eba.europa.eu/dora β€” EBA DORA hub.
  • esma.europa.eu/dora β€” ESMA DORA hub.
  • eiopa.europa.eu β€” EIOPA DORA hub.
  • bafin.de β€” DE supervisor.

See also