# DORA (Digital Operational Resilience Act) | Comma Compliance

DORA applies to every EU financial entity and the ICT providers that serve them. What it requires, who it covers, and where communications archiving fits.

Source: https://commacompliance.com/regulations/dora
Last updated: 2026-07-22

---
The Digital Operational Resilience Act (Regulation (EU) 2022/2554) has applied across the EU since 17 January 2025. It requires financial entities to manage technology risks, report major ICT incidents to regulators, regularly test their ability to withstand and recover from disruptions, and make sure their contracts with ICT providers include DORA's required protections. Communications platforms used to support regulated business processes are generally ICT systems within DORA's scope. Records generated by those platforms may form part of the operational evidence supervisors request during investigations, inspections, or incident reviews.

## **At a Glance**

| DORA | Information |
| ---- | ----------- |
| Full name | Digital Operational Resilience Act (Regulation (EU) 2022/2554) |
| Issued by | European Parliament and Council of the EU |
| Applies from | 17 January 2025 |
| Who it applies to | 20 categories of EU financial entities, plus ICT third-party service providers serving them |
| Five pillars | ICT risk management, incident management and reporting, resilience testing, third-party risk management, information sharing |
| Supervised by | National competent authorities (NCAs); EBA, ESMA, and EIOPA for critical ICT third parties |
| Covers communications platforms? | Generally yes — communications platforms used to support regulated business processes are typically ICT systems within scope |

## Who DORA Applies To

DORA covers 20 categories of financial entities operating in the EU, including:

It also applies directly to ICT third-party service providers that are designated as critical by the European Supervisory Authorities, subjecting them to direct oversight by a lead overseer (EBA, ESMA, or EIOPA depending on the sector served).

For non-critical ICT providers, DORA's requirements flow through the contractual obligations financial entities must impose on their vendors under Article 30.

## The Five Pillars

**ICT risk management (Articles 5–16).** Financial entities must maintain a comprehensive ICT risk management framework covering identification, protection, detection, response, and recovery. This includes documented asset inventories, classification of critical systems, backup and recovery procedures, and board-level accountability for ICT risk.

**Incident management and reporting (Articles 17–23).** Firms must identify and classify ICT incidents, maintain procedures for responding to them, and report major incidents to regulators within the timelines set by DORA. Significant cyber threats that have not yet materialised into incidents may also require voluntary notification.

**Digital operational resilience testing (Articles 24–27).** All in-scope entities must conduct basic digital resilience testing regularly. Significant entities must also undergo Threat-Led Penetration Testing (TLPT) at least every three years, conducted by certified external testers and covering live production systems.

**ICT third-party risk management (Articles 28–44).** Financial entities must evaluate ICT providers, track their provider relationships, manage dependency risks, and ensure contracts meet Article 30 requirements.

**Information sharing (Articles 45–49).** DORA encourages financial entities to participate in voluntary cyber threat intelligence sharing arrangements to improve sector-wide resilience.

## Where Communications Archiving Fits

DORA does not replace sector-specific recordkeeping rules such as MiFID II or the national transpositions of the Market Abuse Regulation. It operates alongside them, adding an operational resilience layer.

**Communications platforms are ICT systems.** Any platform used for business communications in a regulated workflow, including messaging platforms and the archiving systems that support them, is an ICT system subject to DORA's risk management and third-party requirements. This includes the systems used to capture, store, retrieve, and provide access to communications records.

**Records support incident reconstruction.** DORA requires firms to be able to reconstruct ICT-related incidents and demonstrate their response. Archived communications may assist with incident reconstruction, forensic analysis, and demonstrating operational response where those communications are relevant to the incident.

**Audit logs and access records are in scope.** Article 9 requires firms to have detection capabilities covering anomalous activity. Article 12 requires backup and recovery procedures. The logs and records generated by a communications archiving system should meet these standards.

**Third-party concentration risk.** Article 29 requires firms to assess concentration risk from ICT providers. A communications archiving provider can create ICT concentration risk if it becomes difficult to replace the service or recover stored data. Firms should assess and document that risk as part of their broader ICT third-party risk management framework.

## Article 30: What Contracts with ICT Providers Must Include

Article 30 sets out the minimum contractual provisions financial entities must include in agreements with ICT third-party providers. These apply to any ICT vendor, not only those designated critical.

Financial entities are responsible for ensuring their ICT vendor contracts meet these requirements.

## How Comma Addresses DORA Obligations

**Data location transparency.** Comma discloses where communications data is processed and stored. Contract schedules identify the specific regions used for capture, storage, and processing, satisfying Article 30's data residency documentation requirement.

**Audit rights.** Comma supports audit rights for financial entities and their competent authorities. Customers with contractual audit requirements can request technical and security documentation, including architecture overviews, penetration test summaries, and access control records.

**Data portability and exit.** All archived communications are exportable in standard formats. Customers retain ownership of their records and can migrate to an alternative archive or on-premise storage. DORA's exit assistance requirement is addressed contractually and technically.

**Incident notification.** Comma maintains incident response procedures and notifies affected customers of ICT incidents affecting their data in accordance with agreed contractual timelines, supporting customers' own DORA incident reporting obligations.

**Resilience and backup.** Archived records are stored with redundancy and backup procedures designed to align with Article 12's recovery objectives. The archive is not a single point of failure for the communications record.
