Overview
The Digital Operational Resilience Act, Regulation (EU) 2022/2554, has applied since January 17, 2025. It sets one set of ICT risk rules for about 20 types of EU financial entities, from banks and insurers to payment institutions, crypto-asset service providers, and trading venues. As a regulation it applies directly. Detailed rules sit in regulatory and implementing technical standards adopted by the Commission. The incident reporting standard, Delegated Regulation (EU) 2025/301, sets an initial notification within 4 hours of classifying an incident as major and no later than 24 hours after becoming aware of it, an intermediate report within 72 hours, and a final report within one month.
The act rests on 5 pillars. ICT risk management covers governance by the management body, asset identification, protection, detection, response, recovery, and backups. Incident management covers classification and reporting. Resilience testing runs from vulnerability scans to threat-led penetration testing (TLPT), which entities named by their supervisors must run at least every 3 years following the TIBER-EU approach. Third-party risk requires a register of information on all ICT contracts, set contract terms under Article 30, and exit strategies. Information sharing on threats is voluntary.
Canadian technology vendors meet DORA mainly through their EU financial clients. Contracts must cover service locations, security, access and audit rights, help during incidents, cooperation with supervisors, and termination rights, with fuller terms, exit plans, and participation in TLPT for services supporting critical or important functions. On November 18, 2025 the European Supervisory Authorities (EBA, EIOPA, and ESMA) published the first list of 19 designated critical ICT third-party providers (CTPPs), mainly large cloud, data centre, telecom, and IT services firms. Most vendors aren't on it. Each designated provider comes under direct oversight by a Lead Overseer, which can impose periodic penalty payments of up to 1% of average daily worldwide turnover. EU financial entities may only use a designated provider established outside the EU if it sets up an EU subsidiary within 12 months of designation. Canadian financial institutions will see overlap with OSFI Guidelines B-10 and B-13.
Who it applies to in Canada
About 20 types of EU financial entities, including banks, insurers, investment firms, payment and e-money institutions, crypto-asset service providers, and trading venues, plus ICT third-party providers designated for direct oversight.
Canadian technology vendors serving EU financial entities must accept DORA contract terms, support incident reporting and testing, and allow audits. Canadian financial groups with EU subsidiaries apply DORA there alongside OSFI guidance at home.
Controls at a glance
DORA is organized into 5 pillars, with oversight of designated ICT providers set out as part of the third-party chapter.
ICT risk management (Articles 5 to 16)
- Management body defines, approves, and is accountable for ICT risk
- Documented ICT risk framework reviewed at least yearly
- Identify ICT assets, functions, and dependencies
- Protection and prevention controls
- Detection of anomalous activity
- Response, recovery, and backup policies with restoration tests
- Learning from incidents and crisis communication plans
- Simplified framework for small and less complex entities
Incident management and reporting (Articles 17 to 23)
- Incident management process and record of incidents
- Classify incidents using set criteria
- Initial notice within 4 hours of classification, 24 hours of awareness
- Intermediate report within 72 hours of initial notice
- Final report within one month
- Inform clients when their financial interests are affected
- Voluntary notice of significant cyber threats
Digital operational resilience testing (Articles 24 to 27)
- Risk-based testing program within the risk framework
- Yearly tests of systems supporting important functions
- Vulnerability scans, scenario tests, and penetration tests
- TLPT at least every 3 years for designated entities
- TLPT on live production systems, aligned with TIBER-EU
- Use qualified internal or external testers
ICT third-party risk (Articles 28 to 30)
- Strategy and policy on ICT third-party risk
- Register of information on all ICT contracts
- Due diligence and risk assessment before contracting
- Assess concentration risk and subcontracting chains
- Article 30 contract terms on security, audit, and termination
- Exit strategies for services supporting important functions
Oversight of designated ICT providers (Articles 31 to 44)
- ESAs designate providers based on systemic importance
- Lead Overseer assigned to each designated provider
- Information requests, investigations, and on-site inspections
- Recommendations that financial entities and supervisors follow up
- Periodic penalties up to 1% of average daily worldwide turnover
- Non-EU designated providers need an EU subsidiary within 12 months
Information sharing (Article 45)
- Voluntary exchange of threat intelligence
- Sharing within trusted communities of financial entities
- Protect confidentiality and personal data
- Notify competent authorities of participation
Certification and assessment
Financial entities show compliance to their supervisors through their ICT risk framework, register of information, incident reports, and test results. Supervisors review these in ongoing supervision and inspections. ICT vendors are assessed indirectly through their clients' due diligence and audits, unless designated for direct oversight.
Dates to know
- 2023-01-16
- DORA enters into force
- 2025-01-17
- DORA becomes applicable to financial entities
- 2025-02-20
- Delegated Regulation (EU) 2025/301 on incident reporting content and time limits published
- 2025-11-18
- ESAs publish the first list of 19 designated ICT third-party providers
Resources
Official texts and free tools for DORA. Links open the publisher’s site.
- Regulation (EU) 2022/2554 (DORA), official text, EUR-Lex, Publications Office of the European Union
- Digital operational resilience regulation: implementing and delegated acts, European Commission
- DORA oversight, European Banking Authority
- List of designated critical ICT third-party providers, European Securities and Markets Authority
- Digital Operational Resilience Act (DORA), European Insurance and Occupational Pensions Authorityguidance
Need help? Browse the directory or read the guides.
References
- Regulation (EU) 2022/2554 (DORA), EUR-Lex, Publications Office of the European Union
- European Supervisory Authorities designate critical ICT third-party providers under the Digital Operational Resilience Act, European Insurance and Occupational Pensions Authority
- List of designated critical ICT third-party providers, European Securities and Markets Authority
- DORA oversight, European Banking Authority
General information, reviewed 2026-10-11. Not legal advice. Confirm requirements with the publisher, your regulator, or a qualified advisor.