Guide · DORA
DORA compliance: the five pillars and the articles behind each
DORA does not use the word "pillars"; that is industry shorthand for the areas Article 1 lists, grouped into five workstreams. They are ICT risk management, incident reporting, resilience testing, ICT third-party risk and information sharing, and all five have bound financial entities since 17 January 2025.
(a) financial entities that have in place contractual arrangements for the use of ICT services to run their business operations shall, at all times, remain fully responsible for compliance with, and the discharge of, all obligations under this Regulation and applicable financial services law.
The figure behind it
DORA has applied in full since 17 January 2025; basic resilience tests run at least yearly and threat-led penetration testing at least every 3 years for the entities identified for it. Source: Regulation (EU) 2022/2554, Articles 24(6), 26(1) and 64, EUR-Lex text as held by Rekvira (corpus of 2 September 2026)
DORA (the Digital Operational Resilience Act, Regulation (EU) 2022/2554) states its scope in Article 1 as a list, not as pillars. Industry guides group that list into five workstreams because one item, the contractual arrangements with ICT providers, is the operative detail behind another, third-party risk. Below is the Regulation's own breakdown with the article that carries each area, as Rekvira returned it on 24 September 2026.
What does Article 1 list?
"... this Regulation lays down uniform requirements concerning the security of network and information systems supporting the business processes of financial entities as follows: (a) requirements applicable to financial entities in relation to: (i) information and communication technology (ICT) risk management; (ii) reporting of major ICT-related incidents and notifying, on a voluntary basis, significant cyber threats to the competent authorities; (iii) reporting of major operational or security payment-related incidents ...; (iv) digital operational resilience testing; (v) information and intelligence sharing in relation to cyber threats and vulnerabilities; (vi) measures for the sound management of ICT third-party risk; (b) requirements in relation to the contractual arrangements concluded between ICT third-party service providers and financial entities" (Article 1(1))
How do the five pillars map to the Regulation?
| Pillar | Chapter and articles | The operative words | How often |
|---|---|---|---|
| ICT risk management | Chapter II, Articles 5 to 16 | The management body "shall define, approve, oversee and be responsible for the implementation of all arrangements related to the ICT risk management framework" (5(2)) | Continuous; reviewed periodically |
| Incident reporting | Chapter III, Articles 17 to 23 | "an initial notification", "an intermediate report", "a final report" (19(4)) | Per major incident |
| Resilience testing | Chapter IV, Articles 24 to 27 | "at least yearly, that appropriate tests are conducted on all ICT systems and applications supporting critical or important functions" (24(6)) | Yearly; TLPT at least every 3 years (26(1)) |
| ICT third-party risk | Chapter V, Articles 28 to 44 | "remain fully responsible for compliance" (28(1)); contract clauses in Article 30 | Per contract, plus a register kept up to date (28(3)) |
| Information sharing | Chapter VI, Article 45 | "may exchange amongst themselves cyber threat information and intelligence" (45(1)) | Voluntary |
read_unit on 24 September 2026. Chapter ranges follow the Regulation's structure.Who owns the risk management framework?
Not IT. Article 5(2) puts it on the management body, which must "bear the ultimate responsibility for managing the financial entity's ICT risk", set roles, approve the digital operational resilience strategy and the ICT business continuity policy, and approve the ICT internal audit plans. A framework that the board has never approved does not meet the Article, however good the controls are.
How are incidents reported?
Article 19(4) sets a three-step sequence for a major ICT-related incident: an initial notification, intermediate reports "as soon as the status of the original incident has changed significantly", and a final report "when the root cause analysis has been completed". The deadlines themselves are set in technical standards under Article 20, which the Regulation's own text does not contain.
How often must you test?
1 year
the longest gap between basic tests on systems supporting critical or important functions (Article 24(6))
3 years
the longest gap between threat-led penetration tests for identified entities (Article 26(1))
17 Jan 2025
the date DORA has applied from (Article 64)
read_unit on 24 September 2026.Microenterprises are outside the yearly test rule, and the competent authority may shorten or lengthen the three-year TLPT cycle "based on the risk profile of the financial entity" (Article 26(1)).
Why does third-party risk carry so much weight?
Because the responsibility does not move with the service. Article 28(1)(a) says a financial entity that uses ICT services under contract "shall, at all times, remain fully responsible for compliance with, and the discharge of, all obligations under this Regulation". Whatever the provider signs, the supervisor looks at you. That is why the contract clauses in Article 30 (service levels, locations, audit rights, exit strategies) and the register of information in Article 28(3) get a workstream of their own.
The recorded DORA third-party contract review shows what that looks like in practice: an assistant connected to Rekvira checks an illustrative cloud contract clause by clause against Articles 28 and 30, quoting each requirement.
When did DORA take effect?
On one date, with no phased schedule of the kind the AI Act uses: "It shall apply from 17 January 2025" (Article 64). All five workstreams above have been binding on financial entities since then.
Recorded run
The question:What does DORA require, area by area, and since when?
read_unit(regulation="dora", kind="paragraph", article="1", number="1")DORA's own list of what it regulates.
"information and communication technology (ICT) risk management" and "measures for the sound management of ICT third-party risk"
read_unit(regulation="dora", kind="paragraph", article="5", number="2")Who owns the ICT risk management framework.
"bear the ultimate responsibility for managing the financial entity"
read_unit(regulation="dora", kind="paragraph", article="19", number="4")The incident reporting sequence.
"an initial notification" and "a final report, when the root cause analysis has been completed"
read_unit(regulation="dora", kind="paragraph", article="24", number="6")How often the basic tests run.
"at least yearly, that appropriate tests are conducted on all ICT systems and applications supporting critical or important functions"
read_unit(regulation="dora", kind="paragraph", article="26", number="1")How often threat-led penetration testing runs.
"shall carry out at least every 3 years advanced testing by means of TLPT"
read_unit(regulation="dora", kind="paragraph", article="28", number="1")The general principle of third-party risk.
read_unit(regulation="dora", kind="paragraph", article="45", number="1")Information-sharing arrangements.
read_unit(regulation="dora", kind="article", number="64")The date DORA applies from.
"It shall apply from 17 January 2025."
verify_citation(regulation="dora", citation="Article 28(1)", quote="remain fully responsible for compliance with, and the discharge of, all obligations under this Regulation and applicable financial services law")Check the principle before quoting it.
Quote found for the Article 28(1) sentence quoted at the top of this page.
Real calls to Rekvira’s production server, captured 24 September 2026. Corpus as of 2 September 2026.
Limits
Rekvira holds the text of DORA itself, not the regulatory and implementing technical standards that set incident deadlines, classification criteria and the register templates, and not national guidance. Which entities are identified for TLPT, and whether your framework meets the Regulation, are decisions for your competent authority and your management body.
Do this in your assistant
Use Rekvira to map our DORA programme to the Regulation. Read Articles 1, 5, 19, 24, 26, 28
and 45. For each of the five workstreams give me the operative article, the exact words that
create the duty, and how often it recurs, each with its pinpoint.Paste this into Claude, ChatGPT, Cursor or any MCP client connected to https://mcp.rekvira.com/mcp. No account is needed to start.Install steps for each client
Start with the keyless trial.
No account, no API key, and free during the beta.
https://mcp.rekvira.com/mcp