European Union Digital Operational Resilience Act (DORA) Regulation

Assess your organisation’s compliance with the EU Digital Operational Resilience Act, identify critical ICT and third-party risk gaps, and develop a practical roadmap for achieving and maintaining DORA compliance.

The Digital Operational Resilience Act (DORA) is an EU regulation designed to strengthen the digital operational resilience of the financial sector. It requires regulated financial organisations to demonstrate that they can prevent, withstand, respond to and recover from cyberattacks, technology failures and other Information and Communication Technology (ICT) disruptions. DORA has applied since 17 January 2025 and covers a wide range of organisations, including banks, insurance companies, investment firms, payment institutions, pension providers, crypto-asset service providers and certain ICT third-party service providers.

European Union Digital Operational Resilience Act (DORA) Regulation