DORA

Digital Operational Resilience Act (Regulation (EU) 2022/2554)

In application since 17 January 2025

DORA is the EU's digital operational resilience regime for the financial sector: ICT risk management, incident reporting, resilience testing, and — its sharpest edge — direct oversight of critical third-party ICT providers. It applies to banks, payment and e-money institutions, investment firms, crypto-asset service providers and insurers operating in the EU.

Since 17 January 2025 DORA applies directly, and supervisory attention has shifted to implementation detail: registers of information, threat-led penetration testing, subcontracting chains and incident-classification practice. Third-country firms serving EU clients feel it through their EU entities and vendors.

This page tracks DORA-related supervisory publications, guidance and equivalent operational-resilience regimes emerging in other jurisdictions, updated same-day.

Instrument:
Regulation (EU) 2022/2554 — directly applicable
In application:
17 January 2025
Scope:
Banks, PSPs/EMIs, investment firms, CASPs, insurers + critical ICT providers
Analogues:
APRA CPS 230 (AU), Bank of England/PRA operational-resilience rules (UK)

Latest tracked documents (231)

Regulation on Outsourcing of Functions and Activities by Insurance or Reinsurance Undertakings (Decision No 242/2024)

National Bank of Moldova

Moldova

NBM

Final report on amending Guidelines on ICT risk and security management

European Banking Authority

European Union

EBA

Insurance Act – Unofficial Consolidated Text (Official Gazette Nos. 30/15, 112/18, 63/20, 133/20, 151/22, 152/24, 151/25)

Croatian Financial Services Supervisory Agency

Croatia

HANFA

Bank of Zambia Cyber and Information Risk Management Guidelines 2023

Bank of Zambia

Zambia

BOZ

Law on Digital Operational Resilience for the Financial Sector

Central Bank of Montenegro

Montenegro

CBCG

Finansinspektionen’s regulations and general guidelines regarding supervisory reporting for insurance business (FFFS 2015:13)

Finansinspektionen

Sweden

FI

Law on Voluntary Pension Funds – Unofficial Consolidated Text (NN, Nos. 19/14, 29/18, 115/18, 156/23 and 52/25)

Croatian Financial Services Supervisory Agency

Croatia

HANFA

Finansinspektionen Regulations and General Guidelines on Operational Risk Management

Finansinspektionen

Sweden

FI

Capital Markets Act (Official Gazette, Nos. 65/18, 17/20, 83/21, 151/22, 85/24 and 126/25) – Unofficial Consolidated Text

Croatian Financial Services Supervisory Agency

Croatia

HANFA

Regulation on Audit in Pension Insurance Companies (NN, Nos. 131/24 and 139/25)

Croatian Financial Services Supervisory Agency

Croatia

HANFA

Data Model for DORA RoI

European Banking Authority

European Union

EBA

Finansinspektionen’s regulations and general guidelines regarding occupational pension undertakings (FFFS 2019:21)

Finansinspektionen

Sweden

FI

Finansinspektionen’s Regulations and General Guidelines regarding governance, risk management and control at credit institutions

Finansinspektionen

Sweden

FI

Cybersecurity and Resilience Guideline

Reserve Bank of Zimbabwe

Zimbabwe

RBZ

Regulatory Impact Statement on the Central Depositories (Regulation of Central Depositories) (Amendment) Rules 2025

Capital Markets Authority Kenya

Kenya

CMA

Finansinspektionen’s regulations regarding alternative investment fund managers

Finansinspektionen

Sweden

FI

2026-08-21

Pakistan Virtual Asset Services Activity Specific Regulations, 2026

Pakistan Virtual Assets Regulatory Authority

Pakistan

PVARA

2026-08-06

ESMA launches a Common Supervisory Action with NCAs on CASPs’ digital operational resilience for custody

Cyprus Securities and Exchange Commission

Cyprus

CySEC

2026-08-05

Frontier Artificial Intelligence Models and the Evolving Cyber-Threat Landscape

Malta Financial Services Authority

Malta

MFSA

2026-07-27

Operational Risk Management Regulation

Central Bank of UAE

United Arab Emirates

CBUAE

2026-07-15

Supervisory Expectations on Geopolitical Risk Management

Banco de Portugal

Portugal

BDP

2026-07-07

ESRB warns of vulnerabilities in the financial system linked to advanced AI models

Sveriges Riksbank

Sweden

Riksbank

2026-07-07

Financial Policy Committee Record – July 2026

Bank of England

United Kingdom

BOE

2026-07-02

Minutes of the London FXJSC Operations Sub-Committee Meeting – 18 March 2026

Bank of England

United Kingdom

BOE

2026-06-26

Final Report on revised SREP and supervisory stress testing Guidelines

European Banking Authority

European Union

EBA

2026-06-25

Warning of the European Systemic Risk Board on systemic cyber risks from frontier AI models

European Systemic Risk Board

European Union

ESRB

2026-06-16

Comparing the TIBER-EU Framework with other established Non-EU TLPT Frameworks

Malta Financial Services Authority

Malta

MFSA

2026-06-15

Summary of the RTGS CHAPS Industry Forum

Bank of England

United Kingdom

BOE

2026-06-11

ICT Self-Assessment Tool 2026

Central Bank of Ireland

Ireland

CBI

2026-06-09

General Observations on Digital Operational Resilience in Authorisation Applications Received in 2025

Malta Financial Services Authority

Malta

MFSA

Showing the 30 most recent of 231.