Key Facts
Applicable since
17 January 2025
Irish regulator
Central Bank of Ireland
Regulation
(EU) 2022/2554
The Digital Operational Resilience Act has applied to financial entities across the EU since 17 January 2025. For Irish banks, insurers, investment firms, payment institutions, and a wide range of other financial entities, DORA compliance is not a future obligation. It is a current one. This checklist covers the core obligations and what the Central Bank of Ireland expects.
Who is in scope
DORA applies to more than twenty types of financial entity under Article 2. If you are regulated by the Central Bank of Ireland and provide financial services, you are almost certainly in scope.
Crypto-asset service providers
ICT risk management, Articles 5 to 16
The foundation of DORA compliance is a documented ICT risk management framework. Under Article 5 the management body carries direct responsibility for it. They must approve it, review it at least annually, and receive regular ICT risk reporting.
Article 5, governance
Management body approves the ICT risk framework and reviews it at least annually
Article 8, identification
All ICT assets and supported business functions identified and classified by criticality
Article 9, protection
Documented and enforced access control and security policies
Article 10, detection
Mechanisms to detect anomalous activity promptly, with defined alert thresholds
Article 11, response and recovery
ICT business continuity policy covering disruption and cyber incidents, tested periodically
Article 13, learning
Post-incident review feeding back into the framework, with staff awareness and training
Incident reporting, Articles 17 to 23
Article 18 sets out the criteria for classifying an incident as major. Where an incident meets them, Article 19 imposes a three-stage reporting obligation to the Central Bank of Ireland. The precise deadlines are set in the implementing technical standards, so they should be confirmed against the current text rather than assumed.
Stage 1
Initial notification
Promptly after the incident is classified as major
Stage 2
Intermediate report
Once regular activities are recovered, or sooner if there is material change
Stage 3
Final report
When root cause analysis is complete, with actual figures rather than estimates
The gap that shows up most often
The classification decision is the hard part rather than the report itself. Firms that have not written down how they decide whether an incident is major, and have never rehearsed the workflow, tend to lose the first hours of a live incident arguing about the threshold.
Third-party ICT risk, Articles 28 to 44
Third-party risk is one of the most resource-intensive areas of DORA. Under Article 30, contracts with ICT providers supporting critical or important functions must include specific mandatory provisions.
Full service description and service levels
Data location and processing details
Audit rights and regulator access
Incident notification timelines
Exit provisions and data portability
Sub-outsourcing conditions
Register of Information
The register of contractual arrangements with ICT third-party providers is maintained on an ongoing basis and submitted to the Central Bank of Ireland on request and through the annual collection exercise. Firms that treat it as a one-off submission tend to find it out of date the moment a contract changes.
A Morclear DORA Gap Assessment covers the applicable obligations across Articles 5 to 44, producing a scored report with RAG ratings and a prioritised remediation roadmap in two weeks for a fixed fee of €999.
Where does your organisation stand on DORA?
Book a free 30 minute scoping call with the Morclear team. We will go through your current DORA position and what needs to happen next.
Book a Scoping Call
No commitment required, and the first call is free.
Primary Regulatory Sources
Morclear resources are independently produced. They do not constitute legal, regulatory, financial, or professional advice.