DORA

Regulation European Union · 2022

DORA is the EU regulation governing information and communication technology risk across the financial sector — banks, insurers, investment firms, payment institutions, crypto-asset providers and market infrastructure. It sets requirements for ICT risk management, incident classification and reporting, digital operational resilience testing, and the management of ICT third-party risk. Uniquely among the regimes in this catalog, it can designate a technology vendor a critical ICT third-party provider and supervise it directly, which is how it reaches companies that are not financial entities at all.

Sectoral regime. It binds the industries below; companies outside them generally fall outside it.

Countries

Where this binds. Each links to the providers apis.io has catalogued there.

Regions

Industries

Each links to that industry as a scored cohort — so the question "how ready is this sector for the regime that governs it?" becomes one you can actually look at.