Glossary · Related frameworksDORA

Digital Operational Resilience Act

Definition

The Digital Operational Resilience Act (Regulation (EU) 2022/2554) is EU law, applying since 17 January 2025, that sets ICT risk management, incident reporting and resilience testing rules for financial entities, and oversees critical ICT third-party providers. It does not apply in the UK, where financial regulators run their own operational resilience rules.

What does DORA require?

DORA applies to EU banks, insurers, investment firms, payment institutions and other financial entities. It requires an ICT risk management framework, classification and reporting of major ICT-related incidents, resilience testing including threat-led penetration testing for larger firms, and management of ICT third-party risk.

It also creates an EU oversight framework for critical ICT third-party providers, such as major cloud providers, led by the European Supervisory Authorities. For financial entities, DORA takes precedence over the equivalent NIS2 provisions.

What is the UK equivalent of DORA?

The UK has no single equivalent. The PRA and FCA operational resilience rules required in-scope firms to operate important business services within impact tolerances by 31 March 2025. Separately, the critical third parties regime under the Financial Services and Markets Act 2023 lets HM Treasury designate critical suppliers to the sector; the regulators’ rules took effect on 1 January 2025 and apply once a designation is made.

These are financial regulation, not NIS. For the Bill, the practical question for a financial firm is whether its cloud and managed service suppliers are regulated, and what their customer notification duties mean for it.

DORA, UK financial rules and the Bill

AreaDORA (EU)UK financial regulationCyber Security and Resilience Bill
WhoEU financial entitiesPRA and FCA regulated firmsOperators of essential services, digital and managed service providers, data centres
Third partiesEU oversight of critical ICT providersCritical third parties regime (designation by HM Treasury)Critical supplier designation by regulators
Financial firms directly in scope?YesYesNo, only indirectly through suppliers

Where it appears in the Bill

  • Clause 7Relevant digital service providers, including cloud services that financial firms rely on.
  • Clause 9Relevant managed service providers.
  • Clause 29Part 3 power to make regulations for essential activities.

References are to HL Bill 32 as brought from the Commons. Read the Bill.

Frequently asked questions

Does DORA apply to UK banks?

Not to their UK activity. DORA is EU law and applies to financial entities authorised in the EU, including EU subsidiaries of UK groups. UK firms are covered by PRA and FCA operational resilience rules and, for their key suppliers, the UK critical third parties regime. Groups operating in both markets need to map the two sets of requirements.

Are financial services in scope of the Cyber Security and Resilience Bill?

Not directly. Banking and financial market infrastructure are not sectors in Schedule 2 of the NIS Regulations, and the Bill does not add them. Financial firms feel the Bill through their suppliers: cloud providers, managed service providers and data centres they rely on can be regulated and may have to notify customers of incidents.

Is the UK critical third parties regime the same as critical supplier designation under the Bill?

No. The critical third parties regime comes from the Financial Services and Markets Act 2023: HM Treasury designates suppliers critical to the financial sector, overseen by the Bank of England, PRA and FCA. Critical supplier designation under the Bill is made by NIS regulators, and cannot start until the first Part 3 activity-critical supply regulations are in force.

Related guidance

Official sources

More in Related frameworks

Full glossary