IATE Term of the Week: Digital Operational Resilience Act (DORA)

The growing digitisation of financial markets forces the EU to define a uniform regulation for network security and digital resilience. Presented by the European Commission for the first time in September 2020, the Digital Operational Resilience Act (DORA) aims to introduce a comprehensive regulatory framework at the EU level that includes regulations on digital operational resilience for all supervised financial institutions. Based on existing information and communications technology (ICT) risk management requirements already developed by other EU institutions, the proposal ties together several recent EU initiatives into one regulation. Indeed, DORA is part of the larger digital finance package, which aims to develop a European approach that fosters technological development and ensures financial stability and consumer protection. 

The measures taken after the 2008 financial crisis did not consider the risks related to ICT. Therefore, the Digital Operational Resilience Act is necessary to protect and support digital finance, strengthening supervisory effectiveness. The goal is to promote a more careful and secure technological development of digital finance. In addition to reducing cyber risks and ICT-related incidents faced by financial entities, the cornerstones of DORA include the testing activities on ICT system and some measures to unify the mechanisms for reporting incidents.

The Act seeks to standardise, in favour of a European approach, the requirements and management of network security to ensure digital finance capable of protecting consumers and investors at the same time.

The Digital Operational Resilience Act is based on the 2016 NIS (Network and Information Security) directive, which protects infrastructures from cyber-attacks and offers to become the new paradigm for managing cybersecurity and ICT within Financial Services. The measure will involve the traditional financial sector, cryptocurrency providers and issuers of crypto-assets and tokens.

On 11 May 2022, the Council and the European Parliament reached the first provisional agreement on the new legislation, which is expected to come into force by the end of 2022. Following the declaration of operation of the DORA, companies will have to adapt to current regulations and guarantee, within 24 months, to be able to cope with the threats deriving from ICT.


