How-to guide: DORA requirements for financial entities and ICT third-party service providers (EU)

Updated as of: 28 April 2025
This guide outlines the main compliance obligations under the Digital Operational Resilience Act, Regulation (EU) 2022/2554 (DORA). It sets out the key requirements for financial entities and information and communication technology (ICT) third-party service providers (who subject to their categorisation may be either directly or indirectly impacted). It is designed to assist legal and compliance teams, in-house counsel and private practitioners.