DORA : publication in the Official Journal of the EU

24/04/2023

The EU’s Digital Operational Resilience Act (DORA) regulation and directive were published in the Official Journal of the EU on 27 December 2022 and came into force on 17 January 2023. The DORA regulation comes into effect directly on 17 January 2025 and the DORA directive must be transposed into national law by EU member states by the same date.

This new regulatory framework includes two legislative acts:

  • The Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on Digital Operational Resilience (so-called DORA Regulation) which defines uniform requirements to strengthen and harmonize the management of risks related to information and communication technologies (ICT) and the security of networks and information systems at EU level.

  • The Directive (EU) 2022/2556 of the European Parliament and of the Council of 14 December 2022.  which amends existing directives such as CRD IV, PSD2, BRRD, Solvency 2, IORP2, MiFID 2, AIFM, ... in order to make them consistent with the new provisions of the DORA regulation.