DORA · Regulation (EU) 2022/2554Financial operational resilience

    DORA: digital operational resilience for finance

    DORA has applied since 17 January 2025, unifying digital operational resilience rules across the EU financial sector. Policies alone aren't enough. You must prove you manage, test and report ICT risk. Kybit delivers the operational half.

    Financial operational resilience

    What DORA requires

    Five pillars, one goal: an ICT outage or attack must not take you down. Verify exact requirements against the RTS/ITS and your regulator.

    • 01

      Applicability

      Regulation (EU) 2022/2554 has been directly applicable since 17 January 2025 across all EU member states.

    • 02

      Who is in scope

      Banks, insurers, investment and payment firms, crypto-asset providers and other financial entities, plus their critical ICT providers.

    • 03

      ICT risk management

      A management-owned ICT risk-management framework: identify, protect, detect, respond and recover.

    • 04

      Incident reporting

      Classify and report major ICT-related incidents to the competent authority within the set deadlines.

    • 05

      Resilience testing

      Regular testing, and for entities identified by their competent authority, threat-led penetration testing (TLPT) aligned with TIBER-EU, at least every 3 years.

    • 06

      Third-party risk

      Manage ICT third-party risk and a register of contracts; critical ICT providers are overseen by the European Supervisory Authorities (ESAs).

    FAQ

    Frequently asked questions

    Straight answers to what clients ask us most.

    DORA (Regulation (EU) 2022/2554) has been directly applicable since 17 January 2025 across all EU member states. As a regulation it needs no transposition and applies directly.

    Financial entities: banks, insurers, investment and payment firms, crypto-asset providers and more. It also covers the critical ICT service providers serving them. Kybit can act both as an ICT service provider and as your compliance partner.

    Threat-led penetration testing is advanced, threat-intelligence-driven testing aligned with the TIBER-EU framework. It is required for financial entities individually identified by their competent authority, at least every three years (microenterprises and simplified-regime entities are excluded). Kybit performs TLPT and follow-on red-team operations.

    For the financial sector DORA is lex specialis: it takes precedence over the general NIS2 rules where they overlap. Many organisations still face both; we align the obligations so the work isn't done twice.

    Prove operational resilience, not just policies

    We'll review your ICT risk framework, testing plan and incident-reporting process, then put them into operation.