DORA Definition.
Digital Operational Resilience Act, Regulation (EU) 2022/2554, applicable since January 17, 2025. It harmonizes ICT risk management across the EU financial sector: governance, major incident reporting, resilience testing, and oversight of critical third-party providers such as cloud vendors. Payment institutions, EMIs, and PSPs are fully in scope, under the supervision of the ACPR and the European supervisory authorities. A major operational incident must now be reported to the regulator within strict deadlines.
See also
Where this term appears
GuidePayment regulationGuideAgents, distributors, and banking-as-a-service: who is liable for whatGuidePayments in the Baltics and FinlandGuideWhat a payment service provider must reportGuideWhen no authorization is required: exclusions from the scope of payment servicesGuideLuxembourg and Europe’s licensing hubsGuidePayments in ArgentinaGuidePayments in BrazilGuidePayments in Portuguese-speaking and southern AfricaGuidePayment licenses and authorizations around the worldGuideSwitching payment providers: how to run a PSP migrationGuidePayment orchestration