DORA

Digital Operational Resilience Act

ActiveOperational ResilienceEurope
European Union • Regulated by EBA / ESMA / EIOPA
📅
Effective Date
Jan 2023
Full Compliance
Jan 2025
🏛️
Regulator
EBA / ESMA / EIOPA
📊
Scope Areas
3

Overview

DORA establishes uniform requirements for ICT security in the EU financial sector. It impacts Open Banking by setting standards for API security, incident reporting, and third-party risk management.

Note: Full compliance required by January 2025. Impacts all TPPs and banks.

Applicable Countries

This regulation applies to all 27 EU Member States:

Scope & Coverage

This regulation covers the following areas and services:

ICT Risk ManagementIncident ReportingThird-Party Risk

Key Requirements

ICT risk management framework
Incident reporting
Digital resilience testing
Third-party risk oversight

Timeline

Effective Since
January 16, 2023
Full Compliance Deadline
January 17, 2025

Official Resources

Related Regulations

Other Europe regulations you might be interested in:

Need to integrate with Open Banking APIs?

Explore our directory of API aggregators and TPPs to accelerate your compliance.

Interested in more insights?

Banq builds data products and ecosystem solutions for bank and fintech providers.

Join our private beta