What is DORA?
The Digital Operational Resilience Act (DORA) is an EU regulation that entered into force on 16 January 2023 and will apply as of 17 January 2025. The financial sector is increasingly dependent on technology and on tech companies to deliver financial services. This makes financial entities vulnerable to cyber-attacks or incidents.
When not managed properly, Information and Communications Technology (ICT) risks can lead to disruptions of financial services offered across borders. This, in turn, can impact other companies, sectors, and even the rest of the economy, which underlines the importance of the financial sector’s digital operational resilience.
Before DORA, financial institutions managed the main categories of operational risk mainly with the allocation of capital, but they did not manage all components of operational resilience. After DORA, they must also follow rules for the protection, detection, containment, recovery and repair capabilities against ICT-related incidents.
DORA is not the only regulation on the topic of operational resilience and has some common themes and overlaps with others. In the UK, the FCA, PRA and Bank of England issued policy statements on operational resilience in 2021 that came into effect in March 2022. They have also issued PRA Consultation paper 26/23 – FCA consultation paper 23/30 on critical third parties in December 2023.
Who does DORA apply to?
DORA applies to entities operating in the European Union. Specifically, it applies to the following 20 different types of financial entities.
(a) credit institutions
(b) payment institutions
(c) account information service providers
(d) electronic money institutions
(e) investment firms
(f) crypto-asset service providers
(g) central securities depositories
(h) central counterparties
(i) trading venues
(j) trade repositories
(k) managers of alternative investment funds
(l) management companies
(m) data reporting service providers
(n) insurance and reinsurance undertakings
(o) insurance intermediaries, reinsurance intermediaries and ancillary insurance intermediaries
(p) institutions for occupational retirement provision
(q) credit rating agencies
(r) administrators of critical benchmarks
(s) crowdfunding service providers
(t) securitisation repositories
(u) ICT third-party service providers.
Moreover, DORA also applies to ICT third-party service providers wherever located (even outside the EU) that provide services to any of the above-listed financial entities.
What are DORA’s requirements?
DORA explicitly refers to ICT risk and sets rules on ICT risk-management, incident reporting, operational resilience testing and ICT third-party risk monitoring. The requirements are contained in the DORA regulation itself as well as supporting technical standards. DORA requirements are fairly detailed and prescriptive, and can be themed across the following 6 pillars:
- ICT risk management – Implement a more robust and comprehensive ICT Risk Management framework, to support firms to mitigate their exposure to ICT failure.
- ICT incident reporting – Adopt standardised processes to classify, communicate (to regulators and clients), and report upon as part of a holistic incident management capability.
- ICT third-party risk management – Recontract for third-party ICT services, introducing clauses for stronger monitoring and oversight, and Service Level Agreements to better manage third party risk.
- Digital operational resilience testing – Implement and operate a comprehensive suite of tests, to continually ratify the digital resilience footing of the organisation.
- Information sharing – Exchange cyber threat information and intelligence with peers to improve the readiness and response capability.
- Oversight framework for critical ICT third-party providers
Timeline: when does DORA come into effect?
DORA entered into force on 16 January 2023 and will apply as of 17 January 2025.
The key milestones are summarised below:
- 16 January 2023: Entry into force of DORA
- 26 May – 23 June 2023: Public consultation on the call for advice on criticality criteria and fees
- 19 June – 11 Sept 2023: Public Consultation on the first batch of DORA policy mandates
- 30 September 2023: Call for advice on criticality criteria and fees
- 8 Dec 2023 – 4 Mar 2024: Public Consultation on the second batch of DORA policy mandates
- 17 January 2024: Delivery of First batch of policy products (technical standards)
- 17 July 2024: Delivery of the second batch of policy products (technical standards)
- 17 January 2025: Application of DORA
- From 2025: Start of the oversight activities for European Supervisory Authorities
Way forward and path to compliance
- Time is quickly running out and the scope of DORA is potentially huge.
- Conduct a scoping review to assess whether any of your entities are in scope because they fall within the definition of a European financial entity or act as ICT service providers to a financial entity which is itself in scope.
- For each in-scope entity, carry out a maturity assessment against the DORA requirements.
- Any gaps identified should then form the requirements for the DORA implementation or remediation project.
For more information, get in touch at Contact Xcina for Risk Consulting Solutions (xcinaconsulting.com)