Germany

DE · DEU · Europe · Last verified 22 Sep 2026

5 regulators · 6 instruments · 6 obligations · 1 upcoming deadline

Germany — hero image

Regulation 2022

DORA — Digital Operational Resilience Act (Regulation (EU) 2022/2554)

Verordnung über die digitale operative Resilienz im Finanzsektor

Effective: 16 Jan 2023

Last amended: 17 Jan 2025

Plain-English summary

DORA (Digital Operational Resilience Act) is a supreme regulatory framework for Europe that has been put together to ensure that all financial institutions in the EU are able to withstand, respond to, and recover from any ICT disruptions and cyberattacks. The new regulation comes at a time when countries such as Germany had BAIT, whereas France had sector-specific national guidelines for ICT risk management in place. This new legislation serves to connect the dots between financial stability and digital security through its extraordinarily wide scope, which covers more than 22,000 entities in 20 different categories of finance, such as credit institutions, investment firms, CASPs, crowdfunding platforms, and, most importantly, critical third-party ICT service providers, including large cloud computing providers.

Who it applies to

Banking · Insurance · Capital Markets · Payments & Fintech

Topics

Cybersecurity & IT Risk Operational Risk & Outsourcing

Official source

Latest news

No related news yet. We publish updates as regulators act.

Browse all newsSubscribe for updates