DORA
Regulation (EU) 2022/2554 (DORA) has been applicable since 17 January 2025. It establishes a harmonised European framework for ICT risk management of financial entities and for EU-level oversight of ICT providers designated as critical.
Five pillars:
- ICT risk management: governance framework, policies, threat intelligence
- Incident reporting on major ICT-related incidents (Delegated Reg. (EU) 2025/295)
- Digital operational resilience testing (including selective TLPT, Delegated Reg. (EU) 2025/1190)
- ICT third-party risk management (Register of Information under Implementing Reg. (EU) 2025/302, Article 30 DORA contracting)
- Information sharing between entities
As of May 2026 the most active supervisory areas are:
- Register of Information: in Italy, the Bank of Italy has set the annual deadline at 15 March. Technical vademecum published April 2026. The 2025 horizontal analysis flagged vendor concentration, limited substitutability, supply chain complexity.
- Major incident notification timeline (Delegated Reg. (EU) 2025/301 Article 5): as soon as possible, within 4 hours of classification as major, and in any event within 24 hours from when the entity became aware; intermediate report 72 hours; final report within one month.
- Selective TLPT: the competent authority selects entities based on potential systemic impact, systemic character, ICT risk profile.
LX20 advises banks, investment firms, asset managers, e-money and payment institutions, market infrastructures and ICT providers on gap analysis, IT third-party contracts, incident reporting management, dialogue with the Bank of Italy, Register of Information preparation.
Related practices
Frequently asked questions
Does DORA apply directly to ICT providers?
No, only to ICT providers designated as critical by the European Supervisory Authorities (ESAs). All other providers are indirectly involved through the obligations imposed on the financial entities using them.
What is the Register of Information deadline in Italy?
The Bank of Italy has set the annual deadline at 15 March. A technical vademecum published April 2026 clarifies the most frequent compilation findings.
What is the major incident notification timeline?
Initial notification: as soon as possible, within 4 hours of classification as major, and in any event within 24 hours from when the entity became aware. Intermediate: 72 hours. Final: within one month.
What is a major ICT-related incident?
An incident that exceeds the quantitative and qualitative thresholds of Delegated Regulation (EU) 2025/295 in terms of customer impact, duration, persons affected and economic amount.
Must all entities perform TLPT?
No. TLPT is selective: Delegated Regulation (EU) 2025/1190 Article 2 identifies entities subject to TLPT based on potential systemic impact, systemic character of the entity, ICT risk profile. The competent authority selects.
Can I use internal testers for TLPT?
Yes, with stringent rules on independence, certification and separation from operational areas, under Delegated Regulation (EU) 2025/1190.
What does critical ICT provider mean?
A provider designated by the ESAs as critical based on systemic importance for EU financial stability, degree of dependency of financial entities, substitutability. Once designated, the provider is subject to direct EU oversight with a lead overseer (ESMA, EBA or EIOPA).
Are significant cyber threats subject to mandatory notification?
No. Significant cyber threats (Article 3(13) DORA) are subject only to voluntary notification, although encouraged by authorities as a sectoral intelligence tool.
How is IT third-party contracting managed?
Article 30 DORA sets minimum contractual content: services description, service level, data processing location, monitoring, exit, audit, subcontracting, segregation, termination. For critical services, enhanced requirements.
What changes for non-EU providers?
Non-EU ICT providers serving EU financial entities are subject to the same indirect contractual obligations. For non-EU critical providers, designation activates direct EU oversight with possible EU establishment requests.
EU Reg. 2022/2554, critical ICT providers, Register of Information, major ICT incident, TLPT Threat-Led Penetration Testing, Article 30 DORA, Bank of Italy, ESMA EBA EIOPA, digital operational resilience