If you are working in Fintech security or compliance right now, your browser history probably resembles a crime scene, with numerous PDF downloads and EUR-Lex tabs.
We are now deep into the operational phase of DORA (Digital Operational Resilience Act). The “preparation” phase is over; the “execution” phase is here. But DORA isn’t just one PDF. It’s a sprawling ecosystem of Level 1 legislation, Level 2 Technical Standards (RTS/ITS), and Level 3 Guidelines.
As a CISO helping financial entities and fintechs navigate this, I realised we all needed a single source of truth, not just a dump of links, but a structured library organised by operational pillar and context.
Below is the complete inventory of the 27 DORA documents defining the framework as of January 2026.
The General Framework (3 Docs)
The foundation. Before you implement the controls, you need to understand the mandate.
The core legislative act establishing the digital operational resilience framework for the EU financial sector.
Modifies existing financial directives to ensure consistency with DORA requirements.
A living supervisory Q&A tool on DORA that is updated periodically.
ICT Risk Management (2 Docs)
Mandatory technical standards for the ICT risk management framework and simplified requirements.
Explanatory report providing the regulatory rationale behind the ICT Risk Management RTS and the simplified framework.
Incident Management & Reporting (7 Docs)
Specific criteria used to determine if an ICT incident or cyber threat is classified as “major”.
Final report explaining the incident classification criteria and thresholds for major incidents and significant cyber threats.
Mandatory details and strict time limits are required when reporting major incidents and significant cyber threats to authorities.
Official standard forms, templates, and procedures used for filing incident reports and cyber threat notifications.
Final report explaining reporting triggers and timelines for major ICT incident notifications and how they map to the RTS/ITS requirements and templates.
Guidelines on estimating aggregated annual costs and losses caused by major ICT-related incidents.
Joint ESAs report evaluating the feasibility, options, and implications of further centralising major ICT incident reporting under DORA.
Operational Resilience Testing (3 Docs)
Rules for advanced security testing (TLPT), including scope, methodology, and assessor criteria.
Final report explaining the rationale, scope, methodology, and expectations underpinning the TLPT RTS.
Eurosystem framework and guidance for threat intelligence-based ethical red teaming, updated to support consistent TLPT under DORA.
ICT Third-Party Risk / TPRM (6 Docs)
Description: Regulatory technical standards specifying the detailed content of the policy for contractual arrangements on ICT services supporting critical or important functions.
Official data structure and templates for the mandatory register of ICT service contracts (Register of Information).
Final report explaining the design and completion guidance for the Register of Information templates.
Specific rules for assessing and monitoring ICT services that involve subcontracting chains.
Opinion responding to the European Commission’s changes to the draft ITS on the Registers of Information, including implications for data quality and identifiers.
Non-binding ECB guide describing supervisory expectations and recommended good practices for banks outsourcing cloud services.
The Oversight Framework (6 Docs)
How the EU supervises Critical Third-Party Providers (CTPPs).
Note: The first wave of CTPP designations landed in Nov 2025, meaning oversight audits are now imminent for major cloud providers.Delegated act setting out the quantitative and qualitative criteria for designating ICT providers as critical for the EU financial sector.
Published list of designated critical ICT third-party providers subject to EU-level oversight.
Delegated act determining how oversight fees are calculated and paid by designated critical ICT third-party providers.
Ensures uniform conditions for how authorities conduct oversight activities, including audits and inspections, over CTPPs.
Details the composition, tasks, and working arrangements of the Joint Examination Teams responsible for supervising critical providers.
Guidelines on cooperation and information exchange between ESAs and competent authorities for DORA oversight activities.
Why This Library Matters Now (And How to Use It)
We are past the theoretical stage. Deadlines are active, and supervision is ramping up.
If you’re auditing your incident response plan, you need RTS 2025/301.
If you’re calculating last quarter’s losses, you need the Cost and Loss Guidelines.
If you’re preparing for your first TLPT, you need RTS 2025/1190.
How to use this library:
Bookmark this page. Save it as your DORA home base.
Map it to your roadmap. Identify the key documents for your next audit or reporting cycle.
Share with your team. Ensure Legal, Procurement, and Tech Leads work from the same source.



