Digital resilience · IT governance · Compliance

DORA: digital resilience, a governance issue

Applicable from January 2025, the European DORA regulation imposes a single IT resilience framework on the financial sector. Directly applicable in Luxembourg, it makes the management of digital risk — including among service providers — a responsibility that extends all the way up to the board of directors and management.

Category: IT & DORA Reading time: 6 minutes Regulation (EU) 2022/2554 17 January 2025 — Application

Financial activities now rely almost entirely on computer systems and external providers: hosting, software, cloud services. A failure or cyberattack at one of them can interrupt an entire business. Until recently, the rules governing this risk were scattered. DORA (Digital Operational Resilience Act) addresses this through a single framework — and makes it a governance issue, not just a technical matter.

5 pillars Structure
CSSF Authority in Luxembourg

The framework at a glance

DORA is EU Regulation 2022/2554. Like any European regulation, it applies directly, without national transposition, and uniformly throughout the Union. In Luxembourg, the Commission de Surveillance du Secteur Financier (CSSF) ensures its monitoring. It concerns a wide range of entities — banks, investment firms, fund managers, insurers, crypto-asset service providers — as well as their IT service providers. A proportionality principle eases the obligations for smaller structures.

The regulations are organised around five pillars:

  • IT risk management ;
  • the detection and notification of major incidents; ;
  • resilience tests, extending to advanced penetration testing for the most significant entities; ;
  • management of IT vendor risk ;
  • threat intelligence sharing.

DORA complements the broader NIS2 Directive by providing the financial sector with a specific and more demanding framework.

What DORA changes in practice

  • Responsibility at the top. The IT risk management framework is the responsibility of the management body, which must approve it, understand it and oversee its implementation.
  • A register of IT service providers. Each entity shall keep a register of its agreements with information and communication technology (ICT) third-party service providers and make it available to its competent authority upon request.
  • Enhanced contracts. IT contracts, especially for critical functions, must provide for audit and access rights, security requirements, incident notification and exit strategies.
  • Monitoring of critical service providers. IT service providers deemed critical for the sector are designated at European level and placed under the direct supervision of the European Supervisory Authorities (EBA for banking, ESMA for markets, EIOPA for insurance).
Practical consequence: Resilience does not stop at the walls of the entity. It now encompasses the entire IT supply chain, which the board must be able to assess.

Points to note

  • Concentration risk depending on a small number of providers, often the same major cloud players, creates a collective vulnerability.
  • Exit strategies — being able to change service provider, or bring activities back in-house, without any disruption to business.
  • The quality of the register and documentation — often underestimated, it determines the ability to respond to the supervisor.
  • Proportionality is not an exemption — the smallest structures have reduced obligations, not none.

The main stages of the calendar

  • 14th December 2022 — adoption of the regulations.
  • 16 January 2023 — commencement date.
  • 2024-2025 — gradual adoption of regulatory technical standards (RTS) and implementing technical standards (ITS).
  • 17 January 2025 - full and proper application.
  • 2025 - designation of critical ICT third-party service providers and the establishment of their European oversight.
  • Every year, around 30 April — forwarding of the IT agreements register to the competent authority.

How to prepare?

  • map IT service providers and the functions they support; ;
  • compile and keep up to date the register of agreements, with a view to annual transmission; ;
  • review the contractual clauses (audit, security, notification, exit) of critical contracts; ;
  • set up a major incident detection and notification system; ;
  • define and execute a resilience testing plan tailored to the entity's profile; ;
  • ensure that the governing body is informed and actively oversees the system.

Actions to be tailored to the profile, size and business model of each organisation.

Locate your DORA setup and reinforce it.

ARCAD carries out IT and DORA audits — audit rights, resilience, management of IT service providers — tailored to the CSSF framework.

Schedule an exchange →

Official sources

  1. Regulation (EU) 2022/2554 (DORA) — EUR-Lex
  2. CSSF - «ICT and cyber-risk: for DORA entities»
  3. Technical standards of application (delegated regulations), notably (EU) 2024/1773, (EU) 2025/295 and (EU) 2025/420 — EUR-Lex.

Scope of the article: review verified on 12 August 2026. Technical standards and regulatory decisions published after this date must be verified separately.