Fingerprint & verify any document — free, no upload Try it now →

DORA · Regulation (EU) 2022/2554

Verifiable evidence for the Digital Operational Resilience Act

DORA makes financial entities responsible for ICT resilience — and for the records that prove it: incident reports, resilience tests, the register of ICT third parties. A log you keep yourself is easy to doubt. LedgerProof turns each of those records into a tamper-evident, independently verifiable, cryptographically anchored receipt — evidence a supervisor can check without trusting you or any vendor.

Applies now · since 17 Jan 2025 5 pillars Reg (EU) 2022/2554 Hash-only · GDPR-clean

What DORA is. The Digital Operational Resilience Act — Regulation (EU) 2022/2554 — is the EU's single rulebook for the financial sector's resilience to ICT (technology) disruption. Adopted on 14 December 2022, it entered into force on 16 January 2023 and has applied since 17 January 2025. It reaches a broad range of financial entities — from banks, payment and e-money institutions to investment firms, insurers, trading venues and crypto-asset service providers — and, through an EU oversight framework run by the three European Supervisory Authorities, their critical ICT third-party providers. A companion directive, Directive (EU) 2022/2556, aligns the older financial-sector directives with it.

Why evidence is the hard part. DORA does not just ask you to do the right things — it expects you to be able to show them to a competent authority, often under time pressure. The weak point is almost always the record: an internal log your organisation wrote itself can be edited after the fact, so it proves little to a third party. Verifiable evidence has to be independently checkable and tamper-evident — anyone can confirm a record existed in exactly that form at that time, without trusting you. That is precisely what LedgerProof produces.

The five pillars — and where verifiable evidence helps

DORA is built on five areas. Each one leaves a paper trail a supervisor may later scrutinise — and each is a place a cryptographically anchored receipt makes that trail provable.

1

ICT risk management

Chapter II · Art. 6

DORA asks for: A documented ICT risk-management framework, with policies, and records of ICT assets and logs, as part of the firm's overall risk management.

LedgerProof: Anchor each version of your framework and key policies, so you can prove which version was in force on any given date.

2

Incident management & reporting

Chapter III · Art. 19

DORA asks for: Detect and classify ICT-related incidents, and report a major one to your competent authority in three stages: an initial notification, an intermediate report, and a final report.

LedgerProof: Anchor the incident record and each report the moment it is filed — timestamped — so what you reported, and when, is provable later.

3

Digital operational resilience testing

Chapter IV · Art. 26

DORA asks for: A testing programme, and — for identified entities — threat-led penetration testing (TLPT) at least every three years.

LedgerProof: Anchor test scopes, results and remediation records as fixed, independently checkable artifacts an assessor can trust.

4

ICT third-party risk & the register

Chapter V · Art. 28

DORA asks for: Maintain a register of information on every contractual arrangement for ICT services, kept updated and reported to authorities at least yearly.

LedgerProof: Anchor a dated snapshot of each register submission, so the exact version you reported is fixed and verifiable after the fact.

5

Information sharing

Chapter VI · Art. 45

DORA asks for: Voluntary arrangements to exchange cyber-threat information and intelligence among financial entities.

LedgerProof: Anchor the provenance of shared intelligence, so recipients can independently verify its origin and that it has not been altered.

DORA's reporting clock

Time limits for a major ICT-related incident — Commission Delegated Regulation (EU) 2025/301.

4h
Initial notification
Within 4 hours of classifying the incident as major — and no later than 24 hours from becoming aware of it.
72h
Intermediate report
At the latest within 72 hours of the initial notification.
1 mo
Final report
No later than one month after the intermediate report, once root-cause analysis is complete.

A LedgerProof receipt fixes the exact content and time of each report as you file it. “We reported on time” stops being something you assert and becomes something you can prove.

The DORA source stack

The authoritative material, ranked by how cleanly it can be fingerprinted and cryptographically anchored. Every URL was verified.

The law

  1. The Act itself. Official Journal L 333, 27 December 2022; CELEX 32022R2554.
    eur-lex.europa.eu/eli/reg/2022/2554/oj/eng
  2. Legal status, ELI and every related act for the regulation.
    eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022R2554
  3. Plain-language overview of scope, application date and the five areas.
    eur-lex.europa.eu/EN/legal-content/summary/digital-operational-resilience-for-the-financial-sector.html
  4. Amends eight financial-sector directives to align them with DORA.
    eur-lex.europa.eu/eli/dir/2022/2556/oj/eng

The technical standards (RTS / ITS)

  1. Adopted 13 Mar 2024. Criteria for classifying ICT-related incidents and cyber threats; materiality thresholds.
    eur-lex.europa.eu/eli/reg_del/2024/1772/oj
  2. Adopted 13 Mar 2024. Content of the policy on ICT services supporting critical or important functions.
    eur-lex.europa.eu/eli/reg_del/2024/1773/oj
  3. Adopted 13 Mar 2024. ICT risk-management tools, methods and processes, and the simplified framework.
    eur-lex.europa.eu/eli/reg_del/2024/1774/oj
  4. Adopted 29 Nov 2024. Standard templates for the register of information.
    eur-lex.europa.eu/eli/reg_impl/2024/2956/oj
  5. Adopted 23 Oct 2024. Content and time limits of major-incident reports and cyber-threat notifications.
    eur-lex.europa.eu/eli/reg_del/2025/301/oj
  6. Adopted 23 Oct 2024. Forms, templates and procedures for reporting major ICT-related incidents.
    eur-lex.europa.eu/eli/reg_impl/2025/302/oj
  7. Adopted 24 Mar 2025. Assessing the subcontracting of ICT services supporting critical or important functions.
    eur-lex.europa.eu/eli/reg_del/2025/532/oj
  8. Adopted 13 Feb 2025. Threat-led penetration testing (TLPT).
    eur-lex.europa.eu/eli/reg_del/2025/1190/oj

The regulators

  1. The Commission's implementing & delegated-acts hub for DORA.
    finance.ec.europa.eu/regulation-and-supervision/financial-services-legislation/implementing-and-delegated-acts/digital-operational-resilience-regulation_en
  2. The EU securities-markets authority's DORA hub.
    www.esma.europa.eu/esmas-activities/digital-finance-and-innovation/digital-operational-resilience-act-dora
  3. The EU insurance & occupational-pensions authority's DORA hub.
    www.eiopa.europa.eu/digital-operational-resilience-act-dora_en
  4. The EU banking authority's hub for oversight of critical ICT third-party providers.
    www.eba.europa.eu/activities/direct-supervision-and-oversight/digital-operational-resilience-act

A Anchor directly — a stable Official-Journal PDF at a permanent URL.   B Anchor a snapshot — a living regulator page that changes over time.

Frequently asked

When did DORA start to apply?

DORA — Regulation (EU) 2022/2554 — entered into force on 16 January 2023 and has applied since 17 January 2025. Its evidence expectations are live now, not upcoming.

Does LedgerProof make my firm DORA-compliant?

No tool can. LedgerProof produces independently verifiable evidence that a record — an incident report, a test result, a register submission — existed, unaltered, at a specific time. Whether that satisfies a DORA obligation is a determination your auditor, competent authority, or counsel makes.

Which DORA records are worth anchoring?

The ones a supervisor may later scrutinise: major-incident reports and their timing, resilience-test and TLPT results, the versions of your ICT risk-management framework, and each submission of the register of information.

Do I have to put sensitive records on a public chain?

No. LedgerProof is hash-only: it anchors the SHA-256 fingerprint of a record, never the record itself. The document never leaves your systems, which keeps the approach GDPR-clean and confidentiality-safe.

Can a receipt still be verified years later?

Yes. Receipts keep verifying against the public chain independently of LedgerProof — anyone can confirm a record existed in a given form at a given time, with no vendor dependency.

Related reading

LedgerProof produces independently verifiable evidence, not a verdict — it does not make any firm “DORA-compliant.” Whether anchored evidence satisfies a given obligation is a determination your auditor, competent authority, or counsel makes. Authoritative text always remains the version on EUR-Lex / the Official Journal. Proofs are tamper-evident, not tamper-proof. Not legal advice.