The Digital Operational Resilience Act has applied since 17 January 2025. Attention has moved from reading the rules to proving them: registers of information, incident reporting and oversight of critical ICT providers.
DORA requires financial entities to maintain a register of all contractual arrangements with ICT third-party service providers, in a standard format supervisors can collect.