DORA
DORA (Regulation 2022/2554) is the EU law on ICT risk, incident reporting and resilience testing for the financial sector, applying since 2025.
DORA (the Digital Operational Resilience Act, Regulation 2022/2554) is the EU regulation on digital operational resilience for the financial sector - covering banks, insurers, investment firms, payment institutions and crypto-asset service providers. It entered into force in 2023 and has applied since 17 January 2025, setting requirements for ICT risk management, incident reporting, resilience testing (including threat-led penetration testing) and - notably - direct oversight of critical ICT third-party providers (CTPPs).
For financial entities DORA is lex specialis and takes precedence over NIS2, mainly for ICT risk management and incident reporting duties. It touches trust services indirectly: a QTSP serving banks is an ICT third party whose contracts and resilience evidence must meet DORA's outsourcing requirements.