Skip to main content
IAMRoadmapIAMRoadmap
Back to Compliance
Financial Compliance

DORA

Digital Operational Resilience Act (Regulation (EU) 2022/2554)

European Union
Effective: January 17, 2025

Overview

The Digital Operational Resilience Act sets uniform requirements for the security of network and information systems in the EU financial sector, covering ICT risk management, reporting of major ICT-related incidents, digital operational resilience testing, management of ICT third-party risk, and an oversight framework for critical ICT third-party service providers. It entered into force on 16 January 2023 and has applied since 17 January 2025. It applies to 20 types of financial entities and to ICT third-party service providers, and as a regulation it is directly applicable in all Member States. The detailed identity management and access control rules are in Commission Delegated Regulation (EU) 2024/1774, which supplements DORA.

IAM Requirements

Access Policies and Strong Authentication (Article 9)

  • Limit physical and logical access to information and ICT assets to what is required for legitimate and approved functions and activities (Article 9(4)(c))
  • Establish policies, procedures and controls that address access rights and ensure their sound administration (Article 9(4)(c))
  • Implement policies and protocols for strong authentication mechanisms, based on relevant standards and dedicated control systems (Article 9(4)(d))
  • Protect cryptographic keys, with encryption based on approved data classification and ICT risk assessment (Article 9(4)(d))

Identity Management (Delegated Regulation (EU) 2024/1774, Article 20)

  • Assign a unique identity and user account to each staff member, and to staff of ICT third-party service providers, who access the entity's information and ICT assets
  • Run a lifecycle process covering creation, change, review and update, temporary deactivation and termination of all accounts
  • Keep records of all identity assignments
  • Deploy automated solutions for identity lifecycle management where feasible and appropriate

Access Control (Delegated Regulation (EU) 2024/1774, Article 21)

  • Assign access rights on need-to-know, need-to-use and least privilege principles, including for remote and emergency access
  • Segregate duties to prevent combinations of access rights that could be used to circumvent controls
  • Limit generic and shared accounts so that users are identifiable for their actions at all times
  • Review access rights at least once a year, and at least every six months for ICT systems supporting critical or important functions
  • Withdraw access rights without undue delay when employment ends or access is no longer necessary
  • Use strong authentication for remote access, privileged access, and access to ICT assets that support critical or important functions or are publicly accessible
  • Grant privileged, emergency and administrator access on a need-to-use or ad-hoc basis, using dedicated administration accounts where possible

Governance and Third Parties

  • The management body defines, approves, oversees and is responsible for the ICT risk management framework and bears ultimate responsibility for ICT risk (Article 5)
  • Major ICT-related incidents are reported to the relevant competent authority (Article 19)
  • Critical ICT third-party service providers are overseen by a Lead Overseer (Article 35)

Compliance Checklist

1
Confirm which legal entities fall within DORA's scope
2
Have the management body approve the ICT risk management framework
3
Document an identity management policy and an access control policy
4
Give every employee and third-party user a unique identity and account
5
Automate joiner, mover and leaver processes where feasible
6
Apply need-to-know, need-to-use and least privilege to all access rights
7
Define segregation-of-duties rules and check for conflicting access
8
Review access rights at least yearly, and every six months for critical or important functions
9
Require strong authentication for remote, privileged and critical-system access
10
Use dedicated administrator accounts and manage privileged access on a need-to-use basis
11
Reduce generic and shared accounts and log their use
12
Keep records of identity assignments and access decisions for supervisors

Penalties for Non-Compliance

Member States set the administrative penalties and remedial measures for financial entities (Article 50). For critical ICT third-party service providers, the Lead Overseer can impose a periodic penalty payment of up to 1% of average daily worldwide turnover, applied daily for no more than six months (Article 35).

Quick Facts

Region
European Union
Effective Date
January 17, 2025
Enforcing Body
National financial competent authorities; the European Supervisory Authorities (EBA, EIOPA, ESMA) oversee critical ICT third-party service providers

Related Certifications

Related Regulations & Frameworks