DORA
Digital Operational Resilience Act (Regulation (EU) 2022/2554)
Overview
The Digital Operational Resilience Act sets uniform requirements for the security of network and information systems in the EU financial sector, covering ICT risk management, reporting of major ICT-related incidents, digital operational resilience testing, management of ICT third-party risk, and an oversight framework for critical ICT third-party service providers. It entered into force on 16 January 2023 and has applied since 17 January 2025. It applies to 20 types of financial entities and to ICT third-party service providers, and as a regulation it is directly applicable in all Member States. The detailed identity management and access control rules are in Commission Delegated Regulation (EU) 2024/1774, which supplements DORA.
IAM Requirements
Access Policies and Strong Authentication (Article 9)
- Limit physical and logical access to information and ICT assets to what is required for legitimate and approved functions and activities (Article 9(4)(c))
- Establish policies, procedures and controls that address access rights and ensure their sound administration (Article 9(4)(c))
- Implement policies and protocols for strong authentication mechanisms, based on relevant standards and dedicated control systems (Article 9(4)(d))
- Protect cryptographic keys, with encryption based on approved data classification and ICT risk assessment (Article 9(4)(d))
Identity Management (Delegated Regulation (EU) 2024/1774, Article 20)
- Assign a unique identity and user account to each staff member, and to staff of ICT third-party service providers, who access the entity's information and ICT assets
- Run a lifecycle process covering creation, change, review and update, temporary deactivation and termination of all accounts
- Keep records of all identity assignments
- Deploy automated solutions for identity lifecycle management where feasible and appropriate
Access Control (Delegated Regulation (EU) 2024/1774, Article 21)
- Assign access rights on need-to-know, need-to-use and least privilege principles, including for remote and emergency access
- Segregate duties to prevent combinations of access rights that could be used to circumvent controls
- Limit generic and shared accounts so that users are identifiable for their actions at all times
- Review access rights at least once a year, and at least every six months for ICT systems supporting critical or important functions
- Withdraw access rights without undue delay when employment ends or access is no longer necessary
- Use strong authentication for remote access, privileged access, and access to ICT assets that support critical or important functions or are publicly accessible
- Grant privileged, emergency and administrator access on a need-to-use or ad-hoc basis, using dedicated administration accounts where possible
Governance and Third Parties
- The management body defines, approves, oversees and is responsible for the ICT risk management framework and bears ultimate responsibility for ICT risk (Article 5)
- Major ICT-related incidents are reported to the relevant competent authority (Article 19)
- Critical ICT third-party service providers are overseen by a Lead Overseer (Article 35)
Compliance Checklist
Penalties for Non-Compliance
Member States set the administrative penalties and remedial measures for financial entities (Article 50). For critical ICT third-party service providers, the Lead Overseer can impose a periodic penalty payment of up to 1% of average daily worldwide turnover, applied daily for no more than six months (Article 35).
Quick Facts
- Region
- European Union
- Effective Date
- January 17, 2025
- Enforcing Body
- National financial competent authorities; the European Supervisory Authorities (EBA, EIOPA, ESMA) oversee critical ICT third-party service providers