DORA ICT Risk Management Framework 2026: Complete Guide for Financial Entities
Since 17 January 2025, every financial entity in the EU — from systemically important banks to small payment institutions — must maintain a documented ICT risk management framework under DORA. This isn't a checkbox exercise: Articles 6–16 of Regulation (EU) 2022/2554, together with three Delegated Regulations (RTS), specify exactly what policies, functions, tools and evidence the supervisors expect to find.
€5M
"Maximum fine for a financial entity that fails to maintain a compliant ICT risk management framework under DORA — or 10% of total annual worldwide turnover if higher."
— DORA Art. 50, Regulation (EU) 2022/2554
What is the DORA ICT risk management framework? The set of strategies, policies, procedures and tools that a financial entity must establish, implement and maintain to identify, classify, protect against, detect, respond to, recover from and learn from ICT-related incidents. DORA makes the management body (board of directors) directly accountable for approving and overseeing this framework (Art. 5).
The 5 components of the DORA ICT risk management framework
Governance and organisation (Art. 5–6)
The management body must approve the ICT risk strategy, allocate an appropriate ICT budget and ensure the ICT function has qualified staff. An internal control function (second line) and internal audit function (third line) must independently assess ICT risks. The CISO (or equivalent) reports directly to the management body at least annually.
ICT asset management (Art. 8)
A complete, up-to-date inventory of all hardware and software ICT assets is mandatory. Assets must be classified by criticality to business functions. The RTS on ICT risk management tools (Commission Delegated Regulation 2024/1774) specifies the minimum fields for the asset register and the review frequency (at least annually, or after any significant change).
Protection and prevention (Art. 9)
Minimum controls include: network segmentation, multi-factor authentication for privileged accounts, encryption of data in transit and at rest (AES-256 or equivalent), patch management with defined SLAs by criticality, and an information security management policy formally approved by the management body.
Detection (Art. 10)
Financial entities must implement mechanisms to promptly detect anomalous ICT activities — including activities at third-party access points. This typically requires a SIEM (Security Information and Event Management) system with defined alert thresholds and an on-call escalation process. The RTS requires documented baseline normal behaviour for critical systems.
Response, recovery and learning (Art. 11–13)
A documented Business Continuity Plan (BCP) and ICT Disaster Recovery Plan (DRP) with defined RPO and RTO targets are required. Plans must be tested annually (or after a major change). Post-incident reviews must be conducted for all major incidents and shared with the management body within 3 months.
The 3 RTS that detail DORA's ICT risk requirements
| RTS | Key requirements | In force |
|---|---|---|
| RTS on ICT risk management tools (2024/1774) | Asset register fields, patch SLAs, cryptography requirements, network security baseline | 17 Jan 2025 |
| RTS on simplified ICT risk framework (2024/1773) | Proportionate requirements for small/non-complex entities under Art. 16 DORA | 17 Jan 2025 |
| ITS on register of information (2024/2956) | Standardised templates for the ICT third-party register submitted to national supervisors | 30 Apr 2025 |