RegTech

DORA ICT Risk Management Framework 2026: Complete Guide for Financial Entities

Gerard Maymó
June 17, 2026
14 min read

DORA ICT Risk Management Framework 2026: Complete Guide for Financial Entities

Since 17 January 2025, every financial entity in the EU — from systemically important banks to small payment institutions — must maintain a documented ICT risk management framework under DORA. This isn't a checkbox exercise: Articles 6–16 of Regulation (EU) 2022/2554, together with three Delegated Regulations (RTS), specify exactly what policies, functions, tools and evidence the supervisors expect to find.

€5M

"Maximum fine for a financial entity that fails to maintain a compliant ICT risk management framework under DORA — or 10% of total annual worldwide turnover if higher."

— DORA Art. 50, Regulation (EU) 2022/2554

What is the DORA ICT risk management framework? The set of strategies, policies, procedures and tools that a financial entity must establish, implement and maintain to identify, classify, protect against, detect, respond to, recover from and learn from ICT-related incidents. DORA makes the management body (board of directors) directly accountable for approving and overseeing this framework (Art. 5).

The 5 components of the DORA ICT risk management framework

1

Governance and organisation (Art. 5–6)

The management body must approve the ICT risk strategy, allocate an appropriate ICT budget and ensure the ICT function has qualified staff. An internal control function (second line) and internal audit function (third line) must independently assess ICT risks. The CISO (or equivalent) reports directly to the management body at least annually.

2

ICT asset management (Art. 8)

A complete, up-to-date inventory of all hardware and software ICT assets is mandatory. Assets must be classified by criticality to business functions. The RTS on ICT risk management tools (Commission Delegated Regulation 2024/1774) specifies the minimum fields for the asset register and the review frequency (at least annually, or after any significant change).

3

Protection and prevention (Art. 9)

Minimum controls include: network segmentation, multi-factor authentication for privileged accounts, encryption of data in transit and at rest (AES-256 or equivalent), patch management with defined SLAs by criticality, and an information security management policy formally approved by the management body.

4

Detection (Art. 10)

Financial entities must implement mechanisms to promptly detect anomalous ICT activities — including activities at third-party access points. This typically requires a SIEM (Security Information and Event Management) system with defined alert thresholds and an on-call escalation process. The RTS requires documented baseline normal behaviour for critical systems.

5

Response, recovery and learning (Art. 11–13)

A documented Business Continuity Plan (BCP) and ICT Disaster Recovery Plan (DRP) with defined RPO and RTO targets are required. Plans must be tested annually (or after a major change). Post-incident reviews must be conducted for all major incidents and shared with the management body within 3 months.

The 3 RTS that detail DORA's ICT risk requirements

RTS Key requirements In force
RTS on ICT risk management tools (2024/1774)Asset register fields, patch SLAs, cryptography requirements, network security baseline17 Jan 2025
RTS on simplified ICT risk framework (2024/1773)Proportionate requirements for small/non-complex entities under Art. 16 DORA17 Jan 2025
ITS on register of information (2024/2956)Standardised templates for the ICT third-party register submitted to national supervisors30 Apr 2025

5 common gaps found in DORA ICT framework reviews

!

Asset register not formally approved by management body

Many entities maintain an IT asset list in a spreadsheet but lack documented management body approval and a defined review cycle.

!

BCP/DRP not tested in the last 12 months

DORA Art. 11 requires annual testing of response and recovery capabilities. Tabletop exercises count, but must be documented with outcomes and remediation actions.

!

SaaS providers missing from the ICT third-party register

Cloud tools used by business units (CRM, HR, communication platforms) are often overlooked. Under DORA, any third-party ICT service that supports a business function must be in the register.

!

No documented cryptography policy

The RTS on ICT risk management tools requires a formal cryptography and key management policy. Many entities rely on vendor defaults without documenting the standards applied.

!

CISO report to board not documented

DORA Art. 5.4 requires the ICT risk function to report at least once a year to the management body. This report — with its agenda, minutes and action points — is a key piece of audit evidence.

How IgeraRegtech automates DORA ICT risk documentation

// Real query from a compliance team

❓ "Does DORA require us to classify ICT assets by criticality, and what fields must the register contain?"

✅ "Yes. DORA Art. 8.1 requires financial entities to maintain an up-to-date register of all ICT assets. Commission Delegated Regulation 2024/1774 (RTS on ICT risk management tools), Art. 4, specifies that the register must include at minimum: asset identifier, asset type (hardware/software), business function(s) supported, criticality classification (critical/important/other), owner, location, support contract and end-of-life date. Review frequency: at least annually and after any significant infrastructure change."

⏱ 2 seconds · 📄 DORA Art. 8.1 + CDR 2024/1774 Art. 4 · 🚫 0 hallucinations

Audit-ready DORA documentation in 48 hours

IgeraRegtech generates your ICT risk framework documentation — policies, asset register template, BCP/DRP outline, management body report — pre-filled with your entity details and compliant with the latest RTS.

Start free DORA gap analysis

Published: June 2026 · Sources: Regulation (EU) 2022/2554 (DORA); Commission Delegated Regulation 2024/1774 (RTS on ICT risk management tools); Commission Delegated Regulation 2024/1773 (RTS simplified framework); Commission Implementing Regulation 2024/2956 (ITS register of information); EBA/ESMA/EIOPA Joint Guidelines on ICT and security risk management 2024 · Author: Gerard Maymó, CEO Igera Solutions · IgeraRegtech

#DORA ICT risk management#DORA Articles 6-16#DORA RTS ICT risk#DORA governance financial entities#ICT risk framework DORA#DORA compliance guide 2026#DORA audit evidence#DORA implementation guide

COMPARTIR

Comparte el conocimiento con tu red