European Union regulation

DORA

DORA (Digital Operational Resilience Act) is EU Regulation 2022/2554 which, since 17 January 2025, imposes uniform digital resilience requirements on financial entities: ICT risk management, incident reporting, resilience testing and oversight of ICT providers.

Start assessmentRead about the standard
45
controls in Guardiso
30
free-test questions
PL · EN
two languages

What is DORA?

DORA is Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector. As a regulation it applies directly in all Member States — without national transposition — and has applied since 17 January 2025.

The goal of DORA is to ensure that the EU financial sector can maintain the continuity of critical services even during severe ICT disruptions and cyberattacks. The regulation consolidates and harmonises previously fragmented supervisory guidelines into a single, coherent and enforceable set of requirements. Technical details are specified in regulatory and implementing technical standards (RTS/ITS) developed by the European Supervisory Authorities (EBA, EIOPA, ESMA).

In Poland, the supervisory authority responsible for enforcing DORA against financial entities is the Polish Financial Supervision Authority (KNF) — it receives, among other things, major ICT incident reports and registers of information on ICT contractual arrangements.

Who does it apply to?

DORA covers more than twenty categories of financial entities operating in the European Union — from the largest banks to smaller payment institutions. Importantly, the regulation also reaches beyond the financial sector itself: critical third-party ICT service providers (for example cloud computing providers), once designated as critical, fall under the direct oversight of the European Supervisory Authorities.

  • Credit institutions (banks), payment institutions and electronic money institutions
  • Investment firms, managers of alternative investment funds and management companies
  • Insurance and reinsurance undertakings and insurance intermediaries (excluding the smallest ones)
  • Crypto-asset service providers and issuers of asset-referenced tokens (under MiCA)
  • Central securities depositories, central counterparties, trading venues, trade repositories
  • Institutions for occupational retirement provision, credit rating agencies, crowdfunding service providers
  • Critical third-party ICT service providers to the financial sector — including cloud providers

The 5 pillars of DORA

DORA requirements are organised around five pillars which together form a complete system of digital operational resilience:

  • ICT risk management (Arts. 5-16) — an ICT risk management framework with full accountability of the management body: asset identification, protection, detection, response and recovery, backups, continuous improvement.
  • ICT incident management and reporting (Arts. 17-23) — a uniform process for handling and classifying incidents and an obligation to report major incidents to the supervisor (in Poland: the KNF) in three stages: initial notification, intermediate report, final report.
  • Digital operational resilience testing (Arts. 24-27) — an annual testing programme for critical systems and, for entities designated by the supervisor, advanced threat-led penetration testing (TLPT) at least every 3 years.
  • ICT third-party risk management (Arts. 28-44) — a register of information on all ICT contractual arrangements, mandatory contractual clauses, concentration risk assessment, exit strategies and EU-level oversight of critical ICT providers.
  • Cyber threat information sharing (Art. 45) — voluntary arrangements to exchange threat information and intelligence between financial entities, respecting data protection and professional secrecy.

Relationship with NIS 2

DORA is lex specialis in relation to the NIS 2 Directive — for financial entities covered by DORA, its ICT risk management and incident reporting requirements take precedence over the corresponding NIS 2 provisions. A financial entity applying DORA therefore does not report the same incidents twice under the NIS 2 regime.

In practice this means a bank or an insurer implements DORA requirements, while NIS 2 (implemented in Poland through the amendment of the National Cybersecurity System Act) covers the remaining essential and important sectors. Both regimes are conceptually aligned — risk analysis, incident handling, supply chain security — so organisations operating across sectors can share a substantial part of the implementation.

How does Guardiso help?

Guardiso includes the full DORA standard as 45 controls mapping all five pillars of the regulation (Articles 5-45). Each control has a requirement description in Polish and English, an implementation status, an owner and a place for compliance evidence — so you can see your organisation’s real level of readiness at any time.

The vendor management module lets you maintain the register of contractual arrangements with third-party ICT service providers — a key obligation of DORA’s fourth pillar — together with provider risk assessments and the full set of information required by the supervisor. The incident module supports logging, classifying and handling ICT incidents, organising the material needed to report major incidents to the KNF.

Cross-mapping with ISO 27001 shows which DORA requirements you already cover with existing information security management system controls — an organisation with ISO 27001 in place starts from a high baseline and focuses only on DORA-specific gaps instead of building everything from scratch.

Official sources
01Select standard›02Complete the self assessment›03Close gaps in Guardiso
—
DORA readiness score
0/30 answered
The score updates live as you answer.

Other standards to assess

ISO 27001GlobalGDPREUNIS 2 (Polish KSC act)EU · PLSOC 2GlobalTISAXAutomotiveISO 9001GlobalISO 42001 (AI)GlobalKRIPLPCI DSSGlobalNIST CSFUSANIST 800-53USAHIPAAUSACMMC 2.0USACyber EssentialsUKSOX ITGCUSABIO2NLEU AI ActEUISO 27701GlobalISO 22301GlobalISO 14001GlobalISO 45001GlobalISO 13485MedicalIEC 62304MedicalMDREU · MedicalISO 14971MedicalDCB0129UKMiCAEUIEC 62443GlobalISO 21434Automotive
Browse all 30 standards