All terms
Topic: Recht & Aufsicht

What is DORA?

DORA (Digital Operational Resilience Act) is an EU regulation that has applied to financial entities in the EU since January 2025. It governs digital operational resilience — IT risk management, incident reporting, penetration testing and third-party risk — and complements national frameworks such as MaRisk and BAIT.

DORA rests on five pillars: ICT risk management, ICT incident management, resilience testing (TLPT), third-party risk management and information sharing on cyber threats.

For German institutions, DORA overlays existing MaRisk and BAIT requirements — which requirement prevails in a given case is one of the most frequent consulting topics for 2025/2026.

Related terms

Last updated: 2026-05-05