Article content
In briefShow moreShow lessDORA started applying in the EU on 17 January 2025.
- DORA started applying in the EU on 17 January 2025.
- DORA combines technical, operational and contractual controls.
- DORA applied in the EU from 17 January 2025. Norwegian application still depended on EEA incorporation and Norwegian implementation at the publication date.
What happened
DORA started applying in the EU on 17 January 2025. Financial entities in scope needed comprehensive ICT risk management, major-incident reporting, resilience testing and registers of ICT third-party contracts.
DORA combines technical, operational and contractual controls. The supplier register also helps reveal concentration risk, weak exit options and critical dependencies.
Legal status in Norway
DORA applied in the EU from 17 January 2025. Norwegian application still depended on EEA incorporation and Norwegian implementation at the publication date.
What the sources clarify
DORA also moved supplier governance from a general contract exercise to an operational register of ICT agreements. Financial entities needed to identify services supporting critical functions, concentration risk and whether exit or migration was workable. Incident classification and resilience tests had to connect to the same map. When a cloud service fails, knowing the contract owner is insufficient; the entity needs an escalation route, technical logs, recovery objectives and an approved fallback. Norwegian groups operating in the EU also had to separate duties applying to EU entities from the legal status of Norwegian entities.
Boards and senior management need more than an annual vendor list. They should see which critical processes share the same cloud provider or subcontractor, which exit tests have been completed and whether fallback capacity can actually be activated. Exercises and incidents should update the register so contractual records, technical reality and reporting do not drift apart.
Practical implications
Management should select a small set of verifiable measures: the share of critical contracts with tested exit, time to classify and report incidents, and open resilience-test findings. Measures should connect to particular services and vendors because group averages can hide a single critical dependency.
Sources
European Banking Authority: “EBA repeals PSD2 incident-reporting guidelines as DORA applies,” 17 January 2025.
EUR-Lex: “Regulation (EU) 2022/2554 — DORA,” 27 December 2022.
For discussion
Which control should we verify first?

