Skip to main content
—
Framework library
Framework module · dora

Digital Operational Resilience Act

The EU digital-operational-resilience rulebook for financial entities, covering ICT risk, incidents, testing, information sharing, and third-party risk, plus an oversight framework for ICT providers designated critical.

Regulation (EU) 2022/2554 · European Commission — DORA implementing and delegated acts · published 2022-12-27

Standing today
Directory entry

00Answer

from the registry record
What is Digital Operational Resilience Act?
The EU digital-operational-resilience rulebook for financial entities, covering ICT risk, incidents, testing, information sharing, and third-party risk, plus an oversight framework for ICT providers designated critical.
Who does Digital Operational Resilience Act apply to?
Digital Operational Resilience Act applies to financial services, EU, per European Commission — DORA implementing and delegated acts.
What is the current version of Digital Operational Resilience Act?
The current edition is Regulation (EU) 2022/2554, issued by European Commission — DORA implementing and delegated acts and published 2022-12-27. Source: https://finance.ec.europa.eu/regulation-and-supervision/financial-services-legislation/implementing-and-delegated-acts/digital-operational-resilience-regulation_en.
What does an assessment under Digital Operational Resilience Act require?
No control catalog has been ingested for Digital Operational Resilience Act yet — the registry tracks it as roadmap (Modeled framework: we model the regime — control families and at least one crosswalk map on disk — but no source-pinned control catalog is ingested), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

Digital Operational Resilience Act is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

Freely published; obligations not modelled as a control catalog.

02Registry record

checked 2026-08-30
Registry status
Roadmap · modelledModeled framework: we model the regime — control families and at least one crosswalk map on disk — but no source-pinned control catalog is ingested.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
ICT risk management · Incident reporting · Resilience testing · Third-party risk · Information sharing
Applies to
financial services · EU
Verification
Primary — the issuing body's own page was read and states this version. checked 2026-08-30

03Version ledger

1 edition
Regulation (EU) 2022/2554Current edition2022-12-27

06Related frameworks

scored from registry facts
  1. Also applies to financial services · A licensed cybersecurity and risk-management framework used across healthcare and other sectors. HITRUST offers scoped assessment and certification programs through its authorized processes; registry tracking claims no certification.

  2. Shared Assessments SIG2026 annual release

    Also applies to financial services · The licensed Standardized Information Gathering questionnaire used for risk-based third-party due diligence across security, privacy, resilience, and operational domains. SIG responses are assessment inputs—not a certification, attestation, or independent assurance opinion.

  3. APRA CPS 2302026 determination (effective 2026-07-01)

    Also applies to financial services · Australia's cross-industry prudential standard for operational risk, continuity of critical operations, and material service-provider risk at APRA-regulated entities. It is a binding supervisory standard, not a certification.

  4. Also applies to financial services · The widely used internal-control framework for operations, reporting, and compliance, including internal control over financial reporting. It supplies evaluation criteria; it is not a certification and SOX does not create a fixed IT-control catalog.

Digital Operational Resilience Act | ControlFrame