Regulation

EU DORA

EU DORA — Digital Operational Resilience Act

6 requirements · 5 connected unified controls

Open EU DORA in the map
Version
Regulation (EU) 2022/2554
Published
2022-12-27
Effective
2025-01-17
Amendments
none

Requirements and control mappings

“Full” and “Partial” describe the catalog mapping to a unified control. A partial mapping includes the remaining requirement. These mappings do not establish an organization’s implementation or certification.

EU DORA (Digital Operational Resilience Act)

RequirementUnified control and mapping
DORA-Ch2ICT risk management framework (Art 5-16)
UC-BCDR-02 — Establish and govern an ICT operational resilience frameworkPartial

Remaining requirement: detailed protection, backup, and recovery capabilities implemented via companion controls

DORA-Art17-23ICT-related incident management, classification and reporting
UC-BCDR-06 — Resolve operational incidents and eliminate root causesPartial

Remaining requirement: major-incident report clocks: initial 24h, intermediate 72h, final 1 month

DORA-Art24-27Digital operational resilience testing (incl. threat-led penetration testing)
UC-BCDR-10 — Test recovery capabilities and train contingency personnelPartial

Remaining requirement: vulnerability assessments and the Art 25 security-testing catalogue satisfied by companion controls; TLPT regime specifics - three-yearly cadence, authority-approved scope, independent/certified testers (Arts 26-27), and tester independence (Art 24(4)) - require dedicated controls

DORA-Art28-44Managing of ICT third-party risk
UC-TPRM-01 — Operate a third-party security risk management programPartial

Remaining requirement: DORA-specific regulator obligations (register of information format, competent-authority/Lead Overseer interactions) beyond the general third-party program

DORA-Art45Information and intelligence sharing arrangements
DORA-Art5Governance and organisation (management body responsibility)