Overview
The Digital Operational Resilience Act (DORA, EU 2022/2554) applies to financial entities in the EU - including banks, payment institutions, investment firms, insurance companies, crypto-asset service providers, and their critical ICT third-party service providers. It has applied since January 2025. DORA introduces binding requirements for ICT risk management, incident classification and reporting, digital operational resilience testing, and third-party ICT risk - all with documentation and audit obligations that regulators can examine. The defining feature of DORA compliance is auditability: financial entities must demonstrate, with verifiable evidence, that their ICT systems were managed and monitored in accordance with the regulation. That evidence must hold up under adversarial scrutiny, including during incident investigations where the entity itself may be a subject of review.Article-Level Coverage
Chapter II - ICT Risk Management (Articles 5–14)
Article 17 - ICT-Related Incident Management
DORA Article 17 requires financial entities to establish and maintain an ICT-related incident management process. Key documentation requirements:Article 19 - Reporting of Major ICT-Related Incidents
DORA Article 19 requires financial entities to report major incidents to their competent authority. ROOTKey supports the evidence requirements at each reporting stage:Article 28 - General Principles on ICT Third-Party Risk
DORA Article 28 requires financial entities to manage the risks arising from ICT third-party service providers - including their software supply chains.
→ See also: Software Integrity use case
Compliance Summary
Applicable Entities
Request a DORA compliance review
We’ll map your DORA obligations to a ROOTKey implementation - including evidence package design for ECB, EBA, ESMA, or national competent authorities.
Regulatory audit trail use case
Full implementation guide for DORA-compliant audit trails and incident evidence management.

