The Digital Operational Resilience Act (Regulation (EU) 2022/2554) has applied across the EU since 17 January 2025. It requires financial entities to manage technology risks, report major ICT incidents to regulators, regularly test their ability to withstand and recover from disruptions, and make sure their contracts with ICT providers include DORA’s required protections. Communications platforms used to support regulated business processes are generally ICT systems within DORA’s scope. Records generated by those platforms may form part of the operational evidence supervisors request during investigations, inspections, or incident reviews.
At a Glance
| DORA | Information |
|---|---|
| Full name | Digital Operational Resilience Act (Regulation (EU) 2022/2554) |
| Issued by | European Parliament and Council of the EU |
| Applies from | 17 January 2025 |
| Who it applies to | 20 categories of EU financial entities, plus ICT third-party service providers serving them |
| Five pillars | ICT risk management, incident management and reporting, resilience testing, third-party risk management, information sharing |
| Supervised by | National competent authorities (NCAs); EBA, ESMA, and EIOPA for critical ICT third parties |
| Covers communications platforms? | Generally yes — communications platforms used to support regulated business processes are typically ICT systems within scope |
Who DORA Applies To
DORA covers 20 categories of financial entities operating in the EU, including:
- Credit institutions (banks)
- Investment firms
- Payment and e-money institutions
- Insurance and reinsurance undertakings
- Crypto-asset service providers (CASPs)
- Central counterparties (CCPs) and trade repositories
- UCITS and alternative investment fund managers
- Pension institutions
- Data reporting service providers
It also applies directly to ICT third-party service providers that are designated as critical by the European Supervisory Authorities, subjecting them to direct oversight by a lead overseer (EBA, ESMA, or EIOPA depending on the sector served).
For non-critical ICT providers, DORA’s requirements flow through the contractual obligations financial entities must impose on their vendors under Article 30.
The Five Pillars
ICT risk management (Articles 5–16). Financial entities must maintain a comprehensive ICT risk management framework covering identification, protection, detection, response, and recovery. This includes documented asset inventories, classification of critical systems, backup and recovery procedures, and board-level accountability for ICT risk.
Incident management and reporting (Articles 17–23). Firms must identify and classify ICT incidents, maintain procedures for responding to them, and report major incidents to regulators within the timelines set by DORA. Significant cyber threats that have not yet materialised into incidents may also require voluntary notification.
Digital operational resilience testing (Articles 24–27). All in-scope entities must conduct basic digital resilience testing regularly. Significant entities must also undergo Threat-Led Penetration Testing (TLPT) at least every three years, conducted by certified external testers and covering live production systems.
ICT third-party risk management (Articles 28–44). Financial entities must evaluate ICT providers, track their provider relationships, manage dependency risks, and ensure contracts meet Article 30 requirements.
Information sharing (Articles 45–49). DORA encourages financial entities to participate in voluntary cyber threat intelligence sharing arrangements to improve sector-wide resilience.
Where Communications Archiving Fits
DORA does not replace sector-specific recordkeeping rules such as MiFID II or the national transpositions of the Market Abuse Regulation. It operates alongside them, adding an operational resilience layer.
Communications platforms are ICT systems. Any platform used for business communications in a regulated workflow, including messaging platforms and the archiving systems that support them, is an ICT system subject to DORA’s risk management and third-party requirements. This includes the systems used to capture, store, retrieve, and provide access to communications records.
Records support incident reconstruction. DORA requires firms to be able to reconstruct ICT-related incidents and demonstrate their response. Archived communications may assist with incident reconstruction, forensic analysis, and demonstrating operational response where those communications are relevant to the incident.
Audit logs and access records are in scope. Article 9 requires firms to have detection capabilities covering anomalous activity. Article 12 requires backup and recovery procedures. The logs and records generated by a communications archiving system should meet these standards.
Third-party concentration risk. Article 29 requires firms to assess concentration risk from ICT providers. A communications archiving provider can create ICT concentration risk if it becomes difficult to replace the service or recover stored data. Firms should assess and document that risk as part of their broader ICT third-party risk management framework.
Article 30: What Contracts with ICT Providers Must Include
Article 30 sets out the minimum contractual provisions financial entities must include in agreements with ICT third-party providers. These apply to any ICT vendor, not only those designated critical.
- Clear description of the services provided, including the locations from which services are delivered and where data is processed and stored
- Data quality, availability, integrity, and confidentiality provisions
- Service level targets, including quantitative and qualitative performance indicators
- Audit rights: the financial entity (and its competent authority) must have the right to audit the ICT provider and inspect relevant facilities
- Data portability and exit assistance: the provider must support orderly transition to another provider or in-house solution
- Incident notification obligations from the provider to the financial entity
- Appropriate cooperation by the ICT provider in security awareness, resilience testing, and supervisory activities where required by contract and regulation
Financial entities are responsible for ensuring their ICT vendor contracts meet these requirements.
How Comma Addresses DORA Obligations
Data location transparency. Comma discloses where communications data is processed and stored. Contract schedules identify the specific regions used for capture, storage, and processing, satisfying Article 30’s data residency documentation requirement.
Audit rights. Comma supports audit rights for financial entities and their competent authorities. Customers with contractual audit requirements can request technical and security documentation, including architecture overviews, penetration test summaries, and access control records.
Data portability and exit. All archived communications are exportable in standard formats. Customers retain ownership of their records and can migrate to an alternative archive or on-premise storage. DORA’s exit assistance requirement is addressed contractually and technically.
Incident notification. Comma maintains incident response procedures and notifies affected customers of ICT incidents affecting their data in accordance with agreed contractual timelines, supporting customers’ own DORA incident reporting obligations.
Resilience and backup. Archived records are stored with redundancy and backup procedures designed to align with Article 12’s recovery objectives. The archive is not a single point of failure for the communications record.
FAQ about DORA
Does DORA apply to non-EU firms serving EU financial entities?
What counts as a major ICT incident under DORA?
Does DORA replace MiFID II recordkeeping requirements?
Are crypto-asset service providers subject to DORA?
How does DORA interact with the GDPR?
Related regulations
Off-Channel Communications Compliance
What off-channel compliance requires, where firms get cited, and what examiners check across jurisdictions.
Read the guide →
SEC Rule 17a-4
The US broker-dealer recordkeeping standard. For firms operating in both the EU and US, DORA and 17a-4 apply simultaneously.
Read the guide →
