Skip to content
All frameworks

What is DORA?

The EU's Digital Operational Resilience Act. It is a regulation, not a directive, so it applies directly without national transposition — one rulebook for ICT risk across the EU financial sector.

Who it binds

Around twenty categories of financial entity: banks, insurers, investment firms, payment and e-money institutions, crypto-asset service providers, fund managers, trading venues and more — plus the ICT third-party providers they rely on.

15
Register templates

The Register of Information, made under Art. 28(9).

4
exported by Vivid Risk

B_02.01, B_02.02, B_05.01 and B_06.01, as plain CSV.

45
columns mapped

Verified against Annex I and the EBA XBRL taxonomy.

Dates that matter

  • 16 January 2023Entered into force.
  • 17 January 2025Applies. No transposition step — it binds directly.

What people get wrong

The Register of Information is the hardest deliverable

Article 28(3) requires a register of all contractual arrangements for ICT services, at entity, sub-consolidated and consolidated level. The templates come from Implementing Regulation (EU) 2024/2956, and the column numbering was corrected by a corrigendum of 19 September 2025 — the original published Annex numbers one template differently, and that original PDF is still the copy most easily found.

It reaches your suppliers, not just you

Chapter V sets requirements for contractual arrangements with ICT third-party providers, and designates critical providers for direct oversight. Substitutability, exit strategies and sub-outsourcing chains are all in scope.

Threat-led penetration testing, for some

Advanced testing under Article 26 applies to entities identified by their competent authority, on a TIBER-EU-aligned basis. Vivid Risk does not perform or arrange testing.

What Vivid Risk does with DORA

Article citations verified against the Official Journal, plus a Register of Information export covering 4 of the 15 templates as plain CSV.

The export is a data-preparation aid. It is not xBRL-CSV, not validated against the EBA taxonomy, and cannot be filed with a competent authority.

Article 30, point by point

The register tells you who your ICT providers are. Article 30 governs what the contracts behind it have to say. 9 elements under Article 30(2) bind every contractual arrangement for the use of ICT services, and 6 more under Article 30(3) apply where the service supports a critical or important function — so 15 in total for those. Each is quoted below in the Regulation's own words.

ART. 30 CLAUSE REGISTER — YOUR RECORD, NOT A CONTRACT REVIEW

Article 30(2) applies to every contractual arrangement for the use of ICT services. Article 30(3) adds six further elements where the service supports a critical or important function. Vivid Risk does not read your contracts — nothing is uploaded here and nothing is parsed. Each row records what you tell us your contract contains, and where to find it. Whether a clause you point at actually satisfies the point is a question for your counsel.

Every arrangement — Article 30(2)

9 elements

These bind any contractual arrangement for the use of ICT services, whatever the service supports.

  • 30(2)(a)Description of functions and services, and whether subcontracting is permitted

    a clear and complete description of all functions and ICT services to be provided by the ICT third-party service provider, indicating whether subcontracting of an ICT service supporting a critical or important function, or material parts thereof, is permitted and, when that is the case, the conditions applying to such subcontracting

  • 30(2)(b)Locations of provision, processing and storage, and advance notice of change

    the locations, namely the regions or countries, where the contracted or subcontracted functions and ICT services are to be provided and where data is to be processed, including the storage location, and the requirement for the ICT third-party service provider to notify the financial entity in advance if it envisages changing such locations

  • 30(2)(c)Availability, authenticity, integrity and confidentiality of data

    provisions on availability, authenticity, integrity and confidentiality in relation to the protection of data, including personal data

  • 30(2)(d)Access, recovery and return of data on insolvency or termination

    provisions on ensuring access, recovery and return in an easily accessible format of personal and non-personal data processed by the financial entity in the event of the insolvency, resolution or discontinuation of the business operations of the ICT third-party service provider, or in the event of the termination of the contractual arrangements

  • 30(2)(e)Service level descriptions

    service level descriptions, including updates and revisions thereof

  • 30(2)(f)Incident assistance at no cost, or at a cost fixed in advance

    the obligation of the ICT third-party service provider to provide assistance to the financial entity at no additional cost, or at a cost that is determined ex-ante, when an ICT incident that is related to the ICT service provided to the financial entity occurs

  • 30(2)(g)Full cooperation with competent and resolution authorities

    the obligation of the ICT third-party service provider to fully cooperate with the competent authorities and the resolution authorities of the financial entity, including persons appointed by them

  • 30(2)(h)Termination rights and minimum notice periods

    termination rights and related minimum notice periods for the termination of the contractual arrangements, in accordance with the expectations of competent authorities and resolution authorities

  • 30(2)(i)Participation in your awareness programmes and resilience training

    the conditions for the participation of ICT third-party service providers in the financial entities' ICT security awareness programmes and digital operational resilience training in accordance with Article 13(6)

Critical or important functions — Article 30(3)

6 elements

These apply in addition, where the ICT service supports a critical or important function.

  • 30(3)(a)Full service levels with quantitative and qualitative targets

    full service level descriptions, including updates and revisions thereof with precise quantitative and qualitative performance targets within the agreed service levels to allow effective monitoring by the financial entity of ICT services and enable appropriate corrective actions to be taken, without undue delay, when agreed service levels are not met

  • 30(3)(b)Notice periods and reporting of developments with material impact

    notice periods and reporting obligations of the ICT third-party service provider to the financial entity, including notification of any development that might have a material impact on the ICT third-party service provider's ability to effectively provide the ICT services supporting critical or important functions in line with agreed service levels

  • 30(3)(c)Contingency plans tested, and ICT security measures in place

    requirements for the ICT third-party service provider to implement and test business contingency plans and to have in place ICT security measures, tools and policies that provide an appropriate level of security for the provision of services by the financial entity in line with its regulatory framework

  • 30(3)(d)Participation in your threat-led penetration testing

    the obligation of the ICT third-party service provider to participate and fully cooperate in the financial entity's TLPT as referred to in Articles 26 and 27

  • 30(3)(e)Ongoing monitoring: access, inspection and audit rights

    the right to monitor, on an ongoing basis, the ICT third-party service provider's performance, which entails the following: (i) unrestricted rights of access, inspection and audit by the financial entity, or an appointed third party, and by the competent authority, and the right to take copies of relevant documentation on-site if they are critical to the operations of the ICT third-party service provider, the effective exercise of which is not impeded or limited by other contractual arrangements or implementation policies; (ii) the right to agree on alternative assurance levels if other clients' rights are affected; (iii) the obligation of the ICT third-party service provider to fully cooperate during the onsite inspections and audits performed by the competent authorities, the Lead Overseer, financial entity or an appointed third party; and (iv) the obligation to provide details on the scope, procedures to be followed and frequency of such inspections and audits

    By way of derogation from point (e), the ICT third-party service provider and the financial entity that is a microenterprise may agree that the financial entity's rights of access, inspection and audit can be delegated to an independent third party, appointed by the ICT third-party service provider, and that the financial entity is able to request information and assurance on the ICT third-party service provider's performance from the third party at any time.

  • 30(3)(f)Exit strategy and a mandatory transition period

    exit strategies, in particular the establishment of a mandatory adequate transition period: (i) during which the ICT third-party service provider will continue providing the respective functions, or ICT services, with a view to reducing the risk of disruption at the financial entity or to ensure its effective resolution and restructuring; (ii) allowing the financial entity to migrate to another ICT third-party service provider or change to in-house solutions consistent with the complexity of the service provided

Questions

Can I file my Register of Information from Vivid Risk?

No. The export is a data-preparation aid: 4 of the 15 templates as plain CSV, with the disclosure in row 1 of every file. It is not xBRL-CSV, is not validated against the EBA taxonomy, and cannot be filed with the Central Bank of Ireland or any other competent authority.

Does DORA replace NIS2 for financial entities?

DORA is lex specialis for ICT risk in the financial sector, so where both could apply to the same subject matter, DORA's requirements take precedence. That is a legal question for your own advisers, not something a tool decides.

One assessment, every framework

The same answers produce your citations across every framework we cover at once, rather than one questionnaire per regulation.