Regulation

    DORA

    Digital Operational Resilience Act

    European Union

    Why It Exists

    Financial services now run almost entirely on digital infrastructure, including cloud providers who are themselves outside financial regulators' direct reach. DORA harmonizes ICT risk management, mandatory incident reporting, resilience testing, and, notably, direct oversight of critical third-party ICT providers across the EU financial sector.

    Who It's For

    Banks, insurers and reinsurers, investment firms, payment and e-money institutions, and crypto-asset service providers operating in the EU, plus the critical ICT third-party providers (including cloud vendors) that serve them, regardless of where that provider is based.

    Current Status

    Entered into force January 16, 2023, and has applied since January 17, 2025. It is EU law, not a versioned standard.

    EIOPA: Digital Operational Resilience Act (DORA)

    Frequently Asked Questions

    KloudSec, built by the team behind Toc Consulting

    See DORA checked automatically, continuously

    What you just read is a manual, one-time check. KloudSec runs this and 400+ more automated checks across 90+ AWS services, continuously, agentless, live in about 5 minutes.

    Try KloudSec free