01
ICT risk management framework
A documented framework covering identification, protection, detection, response and recovery — applied to the applications and systems that support critical functions.
Regulation (EU) 2022/2554
DORA requires financial entities and their ICT third-party providers to maintain a digital operational resilience framework: ICT risk management, incident handling and reporting, resilience testing, and structured management of third-party ICT risk. For software organizations this puts secure development, testing and dependency governance under financial supervision.
16 January 2023
Regulation entered into force
17 January 2025
Applies to financial entities and ICT providers
Primary source: Regulation (EU) 2022/2554 on EUR-Lex · Last reviewed 14 August 2026
Scope depends on your entity, sector and — for directives — national transposition. This page is informational, not legal advice.
We produce technical evidence and control narratives. We do not certify your compliance — that remains with you and your auditors.
01
A documented framework covering identification, protection, detection, response and recovery — applied to the applications and systems that support critical functions.
02
A testing programme proportionate to the entity, covering application security testing among other techniques, with findings tracked to closure.
03
Structured management of dependencies on ICT providers, including a register of information and contractual requirements — which cascades security expectations down the software supply chain.
04
Classification and reporting of ICT-related incidents on defined timelines, which requires detection capability in the systems that produce them.
Assess application security posture across the systems supporting critical or important functions
Establish an application security testing programme that satisfies resilience testing expectations
Build the dependency and third-party component view that ICT third-party risk management requires
Produce evidence packages that map engineering activity to the framework
Directly, if you qualify as an ICT third-party service provider to a financial entity — and in that case DORA's contractual and oversight requirements shape your obligations. Even where the direct application is limited, financial clients must impose specific requirements contractually, so the practical effect reaches your delivery process either way.
DORA requires a resilience testing programme proportionate to the entity's size, risk profile and role, using a range of techniques; advanced threat-led penetration testing applies to entities identified for it under the regulation. Application security testing is one component of the wider programme — check the requirements applicable to your entity against the text.
For financial entities, DORA generally operates as the sector-specific regime for ICT risk. Many groups nonetheless face both across different legal entities. We scope the applicable set per entity rather than assuming one answer for the whole group.
We link legal texts and standards directly. This page is informational and is not legal advice; obligations depend on your entity, sector and national transposition.
A scoped assessment maps your estate to the obligations that actually apply to your entity — and produces the evidence trail.