The Digital Operational Resilience Act is an EU regulation on the operational resilience of the financial sector, in force since 17 January 2025. It applies directly across member states — as a regulation rather than a directive, it is not transposed into national law and does not vary between them — and it covers a wide population of financial entities: banks, insurers, investment firms, payment and e-money institutions, crypto-asset service providers, trading venues and more.
Its premise is that a financial firm's resilience is inseparable from the resilience of its technology suppliers. So alongside obligations on firms, DORA creates an oversight regime for critical ICT third-party service providers, in which designated providers are supervised directly by a Lead Overseer at European level. That is a genuine novelty: the regulator reaches past the regulated firm to the vendor behind it.
The obligations sit across five pillars — ICT risk management, incident reporting, resilience testing, third-party risk, and information sharing. For third-party risk specifically, Article 28 is the load-bearing one: a register of information covering every ICT contractual arrangement, specified contract terms, pre-contractual due diligence, concentration risk assessment and documented exit strategies for anything supporting a critical or important function.