Skip to main content
All answers

What is DORA?

DORA (Digital Operational Resilience Act) is the EU regulation for financial-sector ICT risk management, fully applicable since January 17, 2025. It mandates ICT risk management (Articles 5-16), incident reporting, operational resilience testing, and third-party ICT risk management for EU financial entities. CIS benchmarks satisfy the technical-controls layer underpinning DORA Articles 9-11.

The longer answer.

DORA arose from a recognition that the stability of the financial system now depends as much on technology resilience as on capital adequacy. Before it, ICT risk was addressed unevenly across different European financial rules, so the regulation consolidates the expectations into one binding framework covering banks, insurers, investment firms, and the technology providers they rely on, with the goal that a financial entity can withstand, respond to, and recover from disruptions to its systems.

Unlike a voluntary standard, DORA is a regulation that applies directly and includes obligations that reach outside the financial entity to the critical third parties serving it. Its ICT risk-management articles expect systems to be securely configured, monitored, and protected, so hardening infrastructure to a recognized benchmark and continuously evidencing that state addresses the concrete technical layer beneath the broader resilience-testing and governance duties the regulation imposes.

More questions on Frameworks?

Our compliance engineers can show you exactly how CISGuard handles Frameworks in a briefing scoped to your environment.