EU Regulation 2022/2554 · DORA Compliance · STORM GRC
What is DORA and Why It Matters
The Digital Operational Resilience Act (DORA) (EU Regulation 2022/2554) is a key EU regulation focused on strengthening cybersecurity and operational resilience in the financial sector.
DORA aims to ensure that financial institutions can maintain secure and resilient operations, both within their own systems and across third-party ICT providers. This includes strengthening ICT capabilities to protect networks and systems, while ensuring financial services remain available during disruptions.
DORA is not just another compliance requirement—it changes how organisations approach ICT risk and operational resilience. It represents a shift toward continuous risk management and accountability across systems, processes, and third-party relationships.
Who Needs to Comply with DORA?
DORA applies to a range of financial entities, covering 21 different types of organisations, as defined in Article 2 of the Regulation.
| Category | Entities |
|---|---|
| Credit & Payment Institutions | Credit institutions, payment institutions, e-money institutions, account information service providers, electronic money institutions |
| Investment & Market Entities | Investment firms, trading venues, central counterparties, trade repositories |
| Post-Trade & Infrastructure | Central securities depositories (CSDs), securitisation repositories |
| Funds & Management Entities | Managers of alternative investment funds (AIFMs), management companies |
| Insurance Sector | Insurance and reinsurance undertakings, insurance, reinsurance and ancillary insurance intermediaries |
| Pensions | Institutions for occupational retirement provision |
| Market Support & Data Services | Credit rating agencies, benchmark administrators, data reporting service providers |
| Digital Financial Services | Crypto-asset service providers, crowdfunding platforms |
| ICT Providers | ICT third-party service providers |
Key DORA Requirements
ICT Risk Management and Governance
DORA requires financial institutions to adopt a proactive, risk-based approach to ICT risk management, ensuring resilience across systems and operations.
Organisations must go beyond prevention and establish capabilities for detection, containment, and effective recovery.
In practice, this means:
DORA requires organisations to move from static risk assessments to continuously managed ICT risk environments.
Incident Response and Reporting
DORA requires organisations to establish effective processes for detecting, managing, and reporting ICT-related incidents in a timely manner.
Digital Operational Resilience Testing
Organisations must regularly test their ability to withstand and recover from ICT disruptions.
For critical entities, this may include advanced testing such as Threat-Led Penetration Testing (TLPT).
Third-Party Risk Management
DORA extends beyond internal systems and requires structured management of ICT third-party risk.
Information Sharing
DORA encourages organisations to participate in threat intelligence sharing to strengthen resilience.

STORM GRC brings DORA compliance into daily operations for financial institutions, covering ICT risk management, incident reporting, third-party oversight, and resilience testing in one place.
How STORM Supports DORA Compliance
STORM supports DORA compliance by bringing ICT risk, resilience, and third-party management into a single, structured platform.
In practice, this enables organisations to:
Conclusion
DORA pushes financial institutions toward continuous resilience and accountability.
Compliance can no longer be treated as a periodic exercise. It requires structured processes, real-time visibility, and continuous control.
STORM helps financial institutions move from fragmented compliance processes to continuous control, with real-time visibility across ICT risk, resilience, and third-party dependencies.
To see how this works in practice, request a demo or get in touch with our team to learn more.