Skip to content

Regulation Guide

DORA Has Applied Since January 2025. Here Is What EU Financial Entities Need to Know.

Every EU financial entity and its ICT third-party providers are in scope. Communications platforms used to support regulated business processes are generally ICT systems within DORA's scope. Supervisors may request evidence demonstrating how ICT incidents were managed and how resilience controls operated.

The Digital Operational Resilience Act (Regulation (EU) 2022/2554) has applied across the EU since 17 January 2025. It requires financial entities to manage technology risks, report major ICT incidents to regulators, regularly test their ability to withstand and recover from disruptions, and make sure their contracts with ICT providers include DORA’s required protections. Communications platforms used to support regulated business processes are generally ICT systems within DORA’s scope. Records generated by those platforms may form part of the operational evidence supervisors request during investigations, inspections, or incident reviews.

At a Glance

DORAInformation
Full nameDigital Operational Resilience Act (Regulation (EU) 2022/2554)
Issued byEuropean Parliament and Council of the EU
Applies from17 January 2025
Who it applies to20 categories of EU financial entities, plus ICT third-party service providers serving them
Five pillarsICT risk management, incident management and reporting, resilience testing, third-party risk management, information sharing
Supervised byNational competent authorities (NCAs); EBA, ESMA, and EIOPA for critical ICT third parties
Covers communications platforms?Generally yes — communications platforms used to support regulated business processes are typically ICT systems within scope

Who DORA Applies To

DORA covers 20 categories of financial entities operating in the EU, including:

  • Credit institutions (banks)
  • Investment firms
  • Payment and e-money institutions
  • Insurance and reinsurance undertakings
  • Crypto-asset service providers (CASPs)
  • Central counterparties (CCPs) and trade repositories
  • UCITS and alternative investment fund managers
  • Pension institutions
  • Data reporting service providers

It also applies directly to ICT third-party service providers that are designated as critical by the European Supervisory Authorities, subjecting them to direct oversight by a lead overseer (EBA, ESMA, or EIOPA depending on the sector served).

For non-critical ICT providers, DORA’s requirements flow through the contractual obligations financial entities must impose on their vendors under Article 30.

The Five Pillars

ICT risk management (Articles 5–16). Financial entities must maintain a comprehensive ICT risk management framework covering identification, protection, detection, response, and recovery. This includes documented asset inventories, classification of critical systems, backup and recovery procedures, and board-level accountability for ICT risk.

Incident management and reporting (Articles 17–23). Firms must identify and classify ICT incidents, maintain procedures for responding to them, and report major incidents to regulators within the timelines set by DORA. Significant cyber threats that have not yet materialised into incidents may also require voluntary notification.

Digital operational resilience testing (Articles 24–27). All in-scope entities must conduct basic digital resilience testing regularly. Significant entities must also undergo Threat-Led Penetration Testing (TLPT) at least every three years, conducted by certified external testers and covering live production systems.

ICT third-party risk management (Articles 28–44). Financial entities must evaluate ICT providers, track their provider relationships, manage dependency risks, and ensure contracts meet Article 30 requirements.

Information sharing (Articles 45–49). DORA encourages financial entities to participate in voluntary cyber threat intelligence sharing arrangements to improve sector-wide resilience.

Where Communications Archiving Fits

DORA does not replace sector-specific recordkeeping rules such as MiFID II or the national transpositions of the Market Abuse Regulation. It operates alongside them, adding an operational resilience layer.

Communications platforms are ICT systems. Any platform used for business communications in a regulated workflow, including messaging platforms and the archiving systems that support them, is an ICT system subject to DORA’s risk management and third-party requirements. This includes the systems used to capture, store, retrieve, and provide access to communications records.

Records support incident reconstruction. DORA requires firms to be able to reconstruct ICT-related incidents and demonstrate their response. Archived communications may assist with incident reconstruction, forensic analysis, and demonstrating operational response where those communications are relevant to the incident.

Audit logs and access records are in scope. Article 9 requires firms to have detection capabilities covering anomalous activity. Article 12 requires backup and recovery procedures. The logs and records generated by a communications archiving system should meet these standards.

Third-party concentration risk. Article 29 requires firms to assess concentration risk from ICT providers. A communications archiving provider can create ICT concentration risk if it becomes difficult to replace the service or recover stored data. Firms should assess and document that risk as part of their broader ICT third-party risk management framework.

Article 30: What Contracts with ICT Providers Must Include

Article 30 sets out the minimum contractual provisions financial entities must include in agreements with ICT third-party providers. These apply to any ICT vendor, not only those designated critical.

  • Clear description of the services provided, including the locations from which services are delivered and where data is processed and stored
  • Data quality, availability, integrity, and confidentiality provisions
  • Service level targets, including quantitative and qualitative performance indicators
  • Audit rights: the financial entity (and its competent authority) must have the right to audit the ICT provider and inspect relevant facilities
  • Data portability and exit assistance: the provider must support orderly transition to another provider or in-house solution
  • Incident notification obligations from the provider to the financial entity
  • Appropriate cooperation by the ICT provider in security awareness, resilience testing, and supervisory activities where required by contract and regulation

Financial entities are responsible for ensuring their ICT vendor contracts meet these requirements.

How Comma Addresses DORA Obligations

Data location transparency. Comma discloses where communications data is processed and stored. Contract schedules identify the specific regions used for capture, storage, and processing, satisfying Article 30’s data residency documentation requirement.

Audit rights. Comma supports audit rights for financial entities and their competent authorities. Customers with contractual audit requirements can request technical and security documentation, including architecture overviews, penetration test summaries, and access control records.

Data portability and exit. All archived communications are exportable in standard formats. Customers retain ownership of their records and can migrate to an alternative archive or on-premise storage. DORA’s exit assistance requirement is addressed contractually and technically.

Incident notification. Comma maintains incident response procedures and notifies affected customers of ICT incidents affecting their data in accordance with agreed contractual timelines, supporting customers’ own DORA incident reporting obligations.

Resilience and backup. Archived records are stored with redundancy and backup procedures designed to align with Article 12’s recovery objectives. The archive is not a single point of failure for the communications record.

FAQ about DORA

Does DORA apply to non-EU firms serving EU financial entities?
Yes, indirectly. DORA does not have direct extraterritorial reach over non-EU ICT providers in the way the GDPR applies to non-EU processors. However, EU financial entities must ensure their ICT provider contracts include the Article 30 mandatory provisions regardless of where the provider is domiciled. A non-EU archiving vendor serving an EU bank must meet those contractual requirements or the bank is in breach.
What counts as a major ICT incident under DORA?
DORA sets classification criteria based on the number of clients affected, duration of the disruption, geographic spread, data losses, criticality of services impacted, and reputational or financial consequences. The European Supervisory Authorities have published regulatory technical standards specifying the thresholds and reporting timeframes. Major incidents must be reported to the competent authority within the timeframes set out in those implementing standards.
Does DORA replace MiFID II recordkeeping requirements?
No. DORA and MiFID II address different obligations. MiFID II requires investment firms to record and retain communications relating to financial instruments transactions. DORA requires firms to manage the ICT systems used in those workflows and ensure operational resilience. Both apply simultaneously. The MiFID II archive is itself an ICT system subject to DORA's risk management and third-party requirements.
Are crypto-asset service providers subject to DORA?
Yes. Crypto-asset service providers authorized under MiCA (Markets in Crypto-Assets Regulation) are in scope for DORA. This applies from the date they are authorized under MiCA, which itself applies from 30 December 2024 for most categories of CASPs.
How does DORA interact with the GDPR?
Both regulations apply simultaneously to EU financial entities. DORA governs the operational resilience of ICT systems; GDPR governs how personal data within those systems is processed. DORA's data processing location disclosure requirement (Article 30) and GDPR's data transfer rules both apply to ICT provider contracts. Where communications archives contain personal data, GDPR lawful basis, data subject rights, and transfer safeguards must be satisfied alongside DORA's contractual requirements.

Related regulations

See how Comma keeps you compliant

Last updated: