Digital Operational Resilience Act
The EU digital-operational-resilience rulebook for financial entities, covering ICT risk, incidents, testing, information sharing, and third-party risk, plus an oversight framework for ICT providers designated critical.
Regulation (EU) 2022/2554 · European Commission — DORA implementing and delegated acts · published 2022-12-27
00Answer
01Standing
Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.
Digital Operational Resilience Act is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.
Freely published; obligations not modelled as a control catalog.
02Registry record
- Registry status
- Roadmap · modelledModeled framework: we model the regime — control families and at least one crosswalk map on disk — but no source-pinned control catalog is ingested.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- ICT risk management · Incident reporting · Resilience testing · Third-party risk · Information sharing
- Applies to
- financial services · EU
- Verification
- Primary — the issuing body's own page was read and states this version. checked 2026-08-30
03Version ledger
| Regulation (EU) 2022/2554 | Current edition | 2022-12-27 |
06Related frameworks
- HITRUST CSFv11.8.0
Also applies to financial services · A licensed cybersecurity and risk-management framework used across healthcare and other sectors. HITRUST offers scoped assessment and certification programs through its authorized processes; registry tracking claims no certification.
- Shared Assessments SIG2026 annual release
Also applies to financial services · The licensed Standardized Information Gathering questionnaire used for risk-based third-party due diligence across security, privacy, resilience, and operational domains. SIG responses are assessment inputs—not a certification, attestation, or independent assurance opinion.
- APRA CPS 2302026 determination (effective 2026-07-01)
Also applies to financial services · Australia's cross-industry prudential standard for operational risk, continuity of critical operations, and material service-provider risk at APRA-regulated entities. It is a binding supervisory standard, not a certification.
Also applies to financial services · The widely used internal-control framework for operations, reporting, and compliance, including internal control over financial reporting. It supplies evaluation criteria; it is not a certification and SOX does not create a fixed IT-control catalog.