The EU Digital Operational Resilience Act became applicable on 17 January 2025, establishing requirements for financial entities covering ICT risk management, incident reporting, resilience testing and — the distinctive part — the oversight of third-party technology providers.
It Regulates The Dependency, Not Just The Institution
The recurring finding of this database is that the party who loses the data is frequently not the party anyone regulates: Marquis at 25-0814, Chain IQ at 25-0613, the back-office administrator at 25-0801.
DORA is the first instrument in this corpus that addresses that directly. It requires financial entities to manage third-party ICT risk as a supervised obligation, and creates a route for critical providers themselves to fall under oversight — reaching the organisation the customer has never heard of.
It Also Regulates Availability, Which Almost Nothing Else Does
The word is "operational resilience", not "data protection". The concern is whether a financial entity can keep functioning through disruption.
This desk has argued repeatedly that availability is the unregulated, unmeasured half of the problem — at 26-0209, and again at 25-0708 where insurance claims turned out to be the only real measurement. DORA is a counter-example to that argument and the corpus should record it as one.
What It Does Not Reach
It applies to financial services in the EU. The distributor at 25-0606, the manufacturer at 25-0902, the school platform at 25-0105 and the law firms at 25-0910 all sit outside it.
The sector was chosen because financial stability is a public interest with an existing supervisory apparatus. The reasoning is sound and the effect is that the most demanding resilience regime in this corpus covers the sector already best resourced to meet it.
This is a regulatory file describing an instrument in force, built on published legal analysis listed below. We do not assess compliance outcomes. Corrections: corrections@forensicpost.com.