DORA's five pillars, operating as one system.
The Digital Operational Resilience Act — Regulation (EU) 2022/2554 — pulls the financial sector's ICT rules into one directly applicable regulation. Its five pillars: ICT risk management, incident reporting and classification, digital operational resilience testing, ICT third-party risk management, and information sharing. It has applied across the EU since 17 January 2025.
For a financial entity this is an operating problem, not a documentation problem. A major ICT incident is classified, escalated and reported on a clock measured in hours; the register of information is a live description of the subcontracting chain; resilience testing is executed on a schedule, not described. Documentation assembled for an examination ages faster than the estate it describes.
Who it applies to
EU financial entities — credit institutions, insurers, payment and e-money institutions, investment firms and crypto-asset service providers among other categories. ICT third-party providers that become critical to the sector can additionally be designated for direct oversight by the European Supervisory Authorities. The obligations follow the ICT arrangements supporting critical or important functions, wherever those arrangements are contracted.
The clock
DORA has applied since 17 January 2025. The reporting clocks for a major ICT incident were fixed by Commission Delegated Regulation (EU) 2025/301, in force since 12 March 2025 — the cascade below starts at classification.
| When | What happens |
|---|---|
| 16 January 2023 | Regulation (EU) 2022/2554 entered into force |
| 17 January 2025 | DORA applies — the five pillars become live obligations |
| 12 March 2025 | Incident-reporting rules entered into force (Delegated Regulation (EU) 2025/301, Implementing Regulation (EU) 2025/302), fixing classification, templates and clocks |
| Initial notification | As early as possible and no later than 4 hours after classifying an incident as major — and no later than 24 hours after becoming aware |
| Intermediate report | Within 72 hours of the initial notification |
| Final report | No later than one month after the intermediate report |
What it asks, in operating terms
Read as an operating requirement rather than a legal text, DORA reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when a supervisor asks for it.
| What DORA asks | Where it is answered |
|---|---|
| Classify and report major ICT incidents on the clock | Incident & resilience workflows · clocked from classification, named owner, sealed record |
| Maintain the register of information across the subcontracting chain | Supplier risk register · chains documented, continuously current |
| Manage concentration risk among ICT providers | Supplier risk register · concentration flagged by provider |
| Test digital operational resilience on schedule | Resilience testing · threat-led programs tracked to evidence |
| Answer for ICT risk at board level | Board reporting · sourced from live control state |
What you'd actually look at
In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:
- Register of information
- 112 arrangements · subcontracting chains documented
- Major incidents · YTD
- 2 · initial within 4 hours · final within one month
- Resilience testing
- threat-led · current cycle complete
- Concentration flags
- 1 · under review
- Evidence
- sealed · sha256:8c41…d0b7
Where teams usually start
With a demo walked through by TruSecure — the DORA control set, a sample major-incident drill against the 4-hour clock, the register export an ICT examination will ask for. Onboarding then produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.
Compliance roadmap
Typical timeline: 3–6 months to full compliance readiness
- 1Weeks 1–4
1.Assessment
Gap analysis against DORA, risk review, remediation plan.
- 2Weeks 5–12
2.Implementation
Controls deployed, policies written, evidence flowing.
- 3Weeks 13–16
3.Audit prep
Gaps closed, evidence package assembled for the authority.
- 4Weeks 17–24
4.Steady state
Continuous evidence, reports on demand, drift alerts.
With TruSecure: 3× faster to audit-ready. AI does the evidence work; your team keeps the decisions.
Map once, comply everywhere
unified commitmentsOne control model
Each control exists exactly once. Every obligation cites it — a gap shows up once, as one remediation item, not six findings in six programs.
Regulations
NIS2 · DORA · GDPR · EU AI Act
Frameworks
ISO 27001 · SOC 2 · NIST · CMMC · CIS
Contracts
Customer security requirements
Internal policy
Your own security standards
When the law moves, the model moves. A new transposition or a revised annex lands as a reviewable proposal against the controls it cites — not as a gap-analysis project you commission separately.
DORA Arts. 28-30 require a register of information covering the subcontracting chain supporting critical or important functions, Art. 29 addresses concentration risk, and Art. 28(8) requires an exit you can actually execute. Our register entry is one line, there is no hyperscaler concentration behind it, and full export works today — with the open core intended to make the exit demonstrable once Community Edition is released.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
DORA (Regulation (EU) 2022/2554) requires EU financial entities and their critical ICT third-party providers to manage ICT risk, report incidents on a defined classification and timeline, test digital operational resilience, and maintain a register of information on ICT third-party arrangements. TruSecure maintains that register continuously.