The Digital Operational Resilience Act (DORA) is EU Regulation (EU) 2022/2554 and has been fully applicable since 17 January 2025. It requires financial entities and their critical ICT service providers to systematically build and demonstrate resilience against cyberattacks and ICT disruptions. For the first time, DORA harmonizes ICT risk management requirements across the EU financial sector and replaces national frameworks such as BAIT, VAIT and KAIT as the primary benchmark.
The regulation applies directly in all EU Member States without requiring national transposition legislation. In Germany, BaFin acts as the central reporting hub for ICT-related incidents and has actively conducted special audits under Section 44 of the German Banking Act (KWG) to assess DORA implementation since 2025.
DORA complements other European cybersecurity frameworks such as the NIS2 Directive and the Cyber Resilience Act, while placing a particular focus on ICT risk management, resilience testing and the secure operation of digital financial services.