Digital Operational Resilience Act (DORA)
Table of Contents
Chapter I – General provisions
Chapter II – ICT risk management
Chapter III – ICT-related incident management, classification and reporting
Chapter IV – Digital operational resilience testing
Chapter V – Managing of ICT third-party risk
Chapter VI – Information-sharing arrangements
Chapter VII – Competent authorities
Chapter VIII – Delegated acts
Chapter IX – Transitional and final provisions
Recitals (106)
Recital 26
(26) In addition, where no ICT testing is required, vulnerabilities remain undetected and result in exposing a financial entity to ICT risk and ultimately create a higher risk to the stability and integrity of the financial sector. Without Union intervention, digital operational resilience testing would continue to be inconsistent and would lack a system of mutual recognition of ICT testing results across different jurisdictions. In addition, as it is unlikely that other financial subsectors would adopt testing schemes on a meaningful scale, they would miss out on the potential benefits of a testing framework, in terms of revealing ICT vulnerabilities and risks, and testing defence capabilities and business continuity, which contributes to increasing the trust of customers, suppliers and business partners. To remedy those overlaps, divergences and gaps, it is necessary to lay down rules for a coordinated testing regime and thereby facilitate the mutual recognition of advanced testing for financial entities meeting the criteria set out in this Regulation.