• Home
  • About us
    • About Compliance Champs
    • Our team
  • Our services
    • Compliance Risk Management
    • Crypto as a Service
    • Financial Economic Crime (FEC)
    • Integrity & Investigations
    • Training & Awareness
  • Sectors
    • Banking
    • Insurance companies
    • Crypto Asset Service Providers (CASPs)
    • Trust Offices
    • Football Sector
    • Investment Firms
    • Payment Service Providers (PSPs)
  • Cases & References
  • Learning & Development
  • Careers
  • Updates
  • Contact
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu

About us

  • About Compliance Champs
  • Our team

Sectors

  • Banking
  • Insurance companies
  • Crypto Asset Service Providers (CASPs)
  • Trust Offices
  • Football Sector
  • Investment Firms
  • Payment Service Providers (PSPs)

Our Services

  • Compliance Risk Management
  • Crypto as a Service
  • Financial Economic Crime (FEC)
  • Integrity & Investigations
  • Training & Awareness

Careers

Contact

Dutch
You are here: Home1 / Articles2 / Digital Operational Resilience Act (DORA)

Digital Operational Resilience Act (DORA)

We like to discuss the 5 primary areas which DORA focusses on:

  • ICT risk management (Chapter II DORA): Financial entities need to have a framework in place setting principles and requirements on ICT risk management, including a business continuity policy and a disaster recovery procedure. When distributing resources and capabilities for the implementation of the ICT risk management framework, financial entities need to balance their ICT-related needs to their size and overall risk profile, and the nature, scale, and complexity of their operations. The ICT risk management framework shall include at least strategies, policies, procedures, ICT protocols and tools that are necessary to adequately protect all information assets and ICT assets from risks including damage and unauthorized access or usage.
  • ICT-related incident management, classification, and reporting (Chapter III DORA): Financial entities need to define, establish and implement an ICT-related incident management process to detect, manage and notify ICT-related incidents. They need to establish appropriate procedures and processes to ensure a consistent and integrated monitoring, handling, and follow-up of ICT-related incidents, to ensure that root causes are identified, documented, and addressed to prevent the occurrence of such incidents.
  • Digital operational resilience testing (Chapter IV DORA): Financial entities need to establish, maintain, and review a comprehensive digital operational resilience testing program, including a range of assessments, tests, methodologies, practices and tools for the testing and advanced testing of the ICT tools, systems and processes based on threat-led penetration testing.
  • Managing of ICT third-party risks (Chapter V DORA): Financial entities need to manage ICT third-party risks as an integral component of ICT risk within their ICT risk management framework. This entails that, among other things, contracts in relation to the provision of ICT services will be required to contain certain key contractual provisions. The management of ICT third-party risks need to be implemented considering the nature, scale, complexity, and importance of ICT-related dependencies.
  • Information-sharing arrangements (Chapter VI DORA): Financial entities may, under certain circumstances, exchange amongst themselves cyber threat information and intelligence. The sharing arrangement needs to be in accordance with the GDPR, take place within trusted communities of financial entities and aim to enhance the digital operational resilience of financial entities.

In addition to the DORA, Regulatory Technical Standards are being published by the EBA, EIOPA and ESMA to ensure the consistent harmonization of the requirements laid down in DORA. Financial entities which are under the scope of DORA need to take these into account when implementing DORA.

On 27 December 2022, DORA was published in the Official Journal of the EU. It entered into force on 16 January 2023 and will apply as of 17 January 2025.

Share this entry
  • Share on Facebook
  • Share on X
  • Share on WhatsApp
  • Share on LinkedIn
https://en.compliancechamps.com/wp-content/uploads/sites/2/2024/10/DORA-e1712749583610.png 682 684 Compliance Champs https://en.compliancechamps.com/wp-content/uploads/2024/05/logo-compliance-champs.svg Compliance Champs2024-04-10 11:45:342024-11-06 15:50:49Digital Operational Resilience Act (DORA)

Recent articles

  • FIU-NL gets a pause button, but crypto keeps moving4 June 2026
  • AMLA Update 3 June 2026
  • Everyone Wants Compliance… Until It Conflicts with the Business1 June 2026

Curious about the possibilities?

Contact one of our consultants

T: +31 6 25 21 22 87
E: info@compliancechamps.com

Logo Compliance Champs
LinkedIn

Contact details

COOLS Urban Office Lofts

Coolsingel 6
3011 AD Rotterdam

T: +31 6 25 21 22 87
E: info@compliancechamps.com

Compliance Champs
Chamber of Commerce number: 84800844
VAT number: NL863377464B01
IBAN: NL44 ABNA 0106 9436 26

Compliance Champs Integrity & Investigations
Chamber of Commerce number: 98134388
VAT number: NL8683.70.289.B.01
IBAN: NL47 ABNA 0149 4612 91

Over Compliance Champs

How we work
Our team
Working at
Cases & references
Learning & development
Updates & knowledge
Contact

Services

Compliance Risk Management
Crypto as a Service
Financial Economic Crime (FEC)
Integrity and Investigations
Training & Awareness

© Copyright Compliance Champs | Kwaaijongens, rebels in oplossingen
  • Terms and Conditions
  • Privacy Statements
Link to: FinCrime & Surveillance summit event Link to: FinCrime & Surveillance summit event FinCrime & Surveillance summit event Link to: The European Central Bank competes with Bitcoin Link to: The European Central Bank competes with Bitcoin The European Central Bank competes with Bitcoin
Scroll to top Scroll to top Scroll to top