Skip to main content
All answers

What is DORA?

DORA (Digital Operational Resilience Act) is the EU regulation for financial-sector ICT risk management, fully applicable since January 17, 2025. It mandates ICT risk management (Articles 5-16), incident reporting, operational resilience testing, and third-party ICT risk management for EU financial entities. CIS benchmarks satisfy the technical-controls layer underpinning DORA Articles 9-11.

The longer answer.

DORA is Regulation (EU) 2022/2554 and has applied since 17 January 2025. It is supervised by the European Supervisory Authorities (EBA, ESMA and EIOPA) together with national authorities, and it covers ICT risk management, incident reporting, resilience testing and ICT third-party risk.

Articles 5 to 15 set out the ICT risk-management framework, including protection and prevention (Article 9) and detection (Article 10). Hardened, continuously verified configurations and drift alerts give technical evidence for those articles; the governance, testing and third-party parts are evidenced elsewhere.

More questions on Frameworks?

Our compliance engineers can show you exactly how CISGuard handles Frameworks in a briefing scoped to your environment.