{"id":48828,"date":"2026-06-08T14:29:37","date_gmt":"2026-06-08T11:29:37","guid":{"rendered":"https:\/\/trueconf.com/blog\/?p=48828"},"modified":"2026-08-31T18:01:59","modified_gmt":"2026-08-31T15:01:59","slug":"dora-regulation","status":"publish","type":"post","link":"https:\/\/trueconf.com/blog\/reviews-comparisons\/dora-regulation","title":{"rendered":"Digital Operational Resilience Act (DORA) Explained 2026"},"content":{"rendered":"<p class=\"primary-medium-text ui-mb-sm-1\"><em>The Digital Operational Resilience Act (DORA)<\/em>, Regulation (EU) 2022\/2554, establishes EU-wide requirements for the digital operational resilience of financial entities. It covers ICT risk management, major ICT-related incident reporting, resilience testing, ICT third-party risk, and voluntary information sharing, with additional oversight applying to designated critical ICT third-party service providers.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">DORA has applied since 17 January 2025. As an EU regulation, it is directly applicable across Member States, while supervision and sanctions are carried out by the competent authorities identified under DORA and relevant national frameworks.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">DORA places responsibility for the ICT risk-management framework on the management body of the financial entity, making digital operational resilience a governance responsibility rather than an IT-only issue.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\"><a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/secure-communication-platform-for-enterprises\" target=\"_blank\" rel=\"noopener\">Communication infrastructure<\/a> can form part of this framework when it supports financial services, incident response, or critical or important functions.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\"><a href=\"https:\/\/eur-lex.europa.eu\/eli\/reg\/2022\/2554\/oj\/eng\" target=\"_blank\" rel=\"noopener noreferrer\">Article 14 of DORA<\/a> requires financial entities to maintain crisis communication plans for responsible disclosure of major ICT-related incidents or vulnerabilities to clients, counterparts, and the public as appropriate. Communication channels used for crisis coordination should therefore be assessed within the institution&#8217;s ICT risk and continuity planning.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">DORA does not automatically classify every communication platform as critical infrastructure. The applicable controls depend on how the platform is used, whether it supports a critical or important function, and whether it is provided under a contractual arrangement with an ICT third-party service provider.<\/p>\n<h3 class=\"h5--main h5--thick black-text ui-mb-xs-3 ui-mt-md-1\">Key Takeaways at a Glance<\/h3>\n<table style=\"overflow-x: auto; display: block;\">\n<tbody>\n<tr>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Question<\/strong><\/p>\n<\/th>\n<th style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Direct answer<\/strong><\/p>\n<\/th>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>What DORA is?<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Regulation (EU) 2022\/2554, a directly applicable EU law requiring financial entities to manage ICT risk, report major ICT-related incidents, test resilience, and manage ICT third-party risk; it also establishes an oversight framework for designated critical ICT third-party service providers<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>When it entered into force and became applicable?<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Entered into force 16 January 2023, fully applicable across the EU since 17 January 2025<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Who does DORA apply to?<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">The financial entities listed in Article 2, including banks, insurers, investment firms, payment institutions, electronic money institutions, and certain crypto-asset market participants. ICT third-party service relationships are governed through separate DORA third-party risk requirements<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Five core areas commonly used to summarize DORA<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">ICT risk management, ICT incident management and reporting, digital operational resilience testing, ICT third-party risk management, and information sharing arrangements<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Current implementation and oversight status<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">DORA has applied since 17 January 2025. The ESAs published the first list of designated Critical ICT Third-Party Providers on 18 November 2025 and the oversight framework is operational<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Why communications infrastructure matters here?<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/enterprise-meeting-software\" target=\"_blank\" rel=\"noopener\">Video conferencing and messaging platforms<\/a> should be included in DORA scoping when they are used as ICT services by a financial entity. Enhanced requirements apply where an ICT service supports a critical or important function<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2 class=\"h4--main h4--thick black-text ui-mb-xs-3 ui-mt-md-1\">Understanding DORA&#8217;s Regulatory Architecture and Jurisdictional Reach<\/h2>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-46576 size-full\" title=\"Data security\" src=\"https:\/\/trueconf.com\/blog\/wp-content\/uploads\/2026\/06\/oauth.svg\" alt=\"Data security\" width=\"515\" height=\"380\" \/ loading=\"lazy\"><\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">Unlike a directive, DORA does not require transposition into national law to become applicable. Its core requirements apply directly across the EU, although national competent authorities remain responsible for supervision and Member States provide the applicable national rules for penalties and remedial measures where DORA requires them.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">The regulation is intended to harmonize ICT risk-management and digital operational resilience requirements across the EU financial sector.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\"><b>DORA&#8217;s scope encompasses an extensive range of financial entities, including:<\/b><\/p>\n<div class=\"accent-note ui-mb-sm-1\">\n<ul class=\"ui-list ui-list--medium\" style=\"margin-bottom: 18px;\">\n<li class=\"ui-list__item ui-list__item--disc\">Credit institutions authorized under the Capital Requirements Directive<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Insurance and reinsurance undertakings operating within Solvency II frameworks<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Investment firms regulated by MiFID II<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Payment institutions governed by PSD2<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Electronic money institutions<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Crypto-asset service providers and issuers of asset-referenced tokens operating under the Markets in Crypto-Assets regulation<\/li>\n<\/ul>\n<\/div>\n<p class=\"primary-medium-text ui-mb-sm-1\">DORA also establishes a Union-level oversight framework for ICT third-party service providers that the European Supervisory Authorities designate as critical under Article 31.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\"><b>ICT third-party services used by financial entities can include:<\/b><\/p>\n<div class=\"accent-note ui-mb-sm-1\">\n<ul class=\"ui-list ui-list--medium\" style=\"margin-bottom: 18px;\">\n<li class=\"ui-list__item ui-list__item--disc\">Major cloud infrastructure providers<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Managed security service organizations<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Software vendors delivering core banking or trading systems<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Communication and collaboration services used by financial entities, depending on the contractual arrangement and role of the service<\/li>\n<\/ul>\n<\/div>\n<p class=\"primary-medium-text ui-mb-sm-1\">The regulation establishes an oversight framework in which national competent authorities supervise financial entities and the European Supervisory Authorities directly oversee ICT third-party service providers designated as critical under Article 31.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">Communication platform vendors serving financial entities may face contractual requirements imposed under DORA by their financial-sector customers. Vendors designated as Critical ICT Third-Party Providers are additionally subject to direct ESA oversight. The exact obligations depend on the service relationship and whether the service supports a critical or important function.<\/p>\n<div class=\"accent-note accent-note--special accent-note--line ui-mb-sm-1\">\n<p class=\"primary-medium-text ui-mb-xs-3\"><em><b>Insight 1.<\/b><\/em><\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\"><em>Communication and collaboration tools should not be excluded from DORA scoping merely because they are categorized internally as productivity applications. If they are provided as ICT services under a contractual arrangement, they should be assessed within the institution&#8217;s ICT third-party risk framework.<\/em><\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\"><em>Article 28 requires financial entities to maintain a Register of Information for contractual arrangements on the use of ICT services provided by ICT third-party service providers. Whether a communication platform supports a critical or important function affects the depth of additional contractual and risk-management requirements, but the Register is not limited only to critical services.<\/em><\/p>\n<\/div>\n<h2 class=\"h4--main h4--thick black-text ui-mb-xs-3 ui-mt-md-1\">Five Core Areas Commonly Used to Summarize DORA<\/h2>\n<p class=\"primary-medium-text ui-mb-sm-1\">DORA is commonly summarized through five core operational areas. This editorial structure helps explain how the regulation affects ICT governance, incident reporting, resilience testing, third-party risk, and information sharing, including the use of communication and collaboration tools.<\/p>\n<table style=\"overflow-x: auto; display: block;\">\n<tbody>\n<tr>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Pillar<\/strong><\/p>\n<\/th>\n<th style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>What it requires<\/strong><\/p>\n<\/th>\n<th style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Implications for communication platforms<\/strong><\/p>\n<\/th>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>ICT risk management<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">A governance framework covering identification, protection, detection, response, and recovery for ICT risk, with the management body responsible for defining, approving, overseeing, and implementing the framework<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/unified-communication-platform\" target=\"_blank\" rel=\"noopener\">Communication platforms<\/a> within scope should be assessed against the institution&#8217;s ICT risk-management framework, with controls proportionate to their role, risks, and the functions they support<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>ICT incident management and reporting<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Classification and reporting of major ICT-related incidents according to DORA and the applicable <a href=\"https:\/\/eur-lex.europa.eu\/eli\/reg_del\/2025\/301\/oj\/eng\" target=\"_blank\" rel=\"noopener noreferrer\">classification criteria<\/a> and <a href=\"https:\/\/eur-lex.europa.eu\/eli\/reg_impl\/2025\/302\/oj\/eng\" target=\"_blank\" rel=\"noopener noreferrer\">reporting requirements<\/a><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">An outage or breach affecting a communication platform may become reportable if it meets DORA&#8217;s criteria for a major ICT-related incident; crisis communication planning should also account for loss of the primary channel<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Digital operational resilience testing<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">A risk-based resilience testing programme; certain financial entities identified under Article 26 must perform Threat-Led Penetration Testing (TLPT) at least every three years, with the competent authority able to adjust the frequency<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">If a communication platform underlies a critical or important function, it may fall within the systems and ICT services considered for the relevant resilience testing or TLPT scope<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>ICT third-party risk management<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">A Register of Information for contractual arrangements on ICT services, baseline contractual clauses for ICT services, enhanced requirements for services supporting critical or important functions, and exit strategies where Article 28 requires them<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">This pillar can apply to <a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/nis2-compliance\" target=\"_blank\" rel=\"noopener\">video conferencing and messaging services<\/a> when they are supplied to a financial entity as ICT services; enhanced requirements depend on the criticality of the supported function<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Information sharing<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Voluntary arrangements between financial entities to share cyber threat intelligence, indicators of compromise, and lessons learned from incidents<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Where threat intelligence is exchanged through <a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/how-to-build-an-instant-messaging-app\" target=\"_blank\" rel=\"noopener\">communication tools<\/a>, the institution should apply confidentiality and access controls appropriate to the sensitivity of the information shared<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<div class=\"accent-note ui-mb-sm-1\">\n<p class=\"primary-medium-text\">\n<h2 class=\"h4--main h4--thick black-text ui-mb-xs-3 ui-mt-md-1\">ICT Third Party Risk Management and the Register of Information<\/h2>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-46644 size-full\" title=\"Third-party risk management\" src=\"https:\/\/trueconf.com\/blog\/wp-content\/uploads\/2026\/06\/secure-enter-1.svg\" alt=\"Third-party risk management\" width=\"561\" height=\"335\" \/ loading=\"lazy\"><\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">ICT third-party risk management is a major part of DORA. <a href=\"https:\/\/eur-lex.europa.eu\/eli\/reg\/2022\/2554\/oj\/eng\" target=\"_blank\" rel=\"noopener noreferrer\">Article 28 of DORA<\/a> requires financial entities to maintain a Register of Information covering contractual arrangements on the use of ICT services provided by ICT third-party service providers. The detailed templates are set by <a href=\"https:\/\/eur-lex.europa.eu\/eli\/reg_impl\/2024\/2956\/oj\/eng\" target=\"_blank\" rel=\"noopener noreferrer\">Commission Implementing Regulation (EU) 2024\/2956<\/a> and capture information about the financial entity, provider, contractual arrangement, service, locations, and whether the supported function is critical or important.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">The European Supervisory Authorities use Register of Information data as part of the designation process for Critical ICT Third-Party Providers. On <a href=\"https:\/\/www.esma.europa.eu\/press-news\/esma-news\/european-supervisory-authorities-designate-critical-ict-third-party-providers\" target=\"_blank\" rel=\"noopener noreferrer\">18 November 2025, the ESAs published the first list of designated CTPPs<\/a> after assessing providers against the criteria in Article 31 and the related delegated regulation, including systemic impact, support for critical or important functions, and substitutability.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">Designated CTPPs are subject to direct oversight by a Lead Overseer within the ESA framework, including examinations, information requests, recommendations, and follow-up activities provided for by DORA.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">Article 30 sets baseline contractual requirements for ICT services and additional clauses where the service supports a critical or important function, including detailed service levels, reporting obligations, security and contingency requirements, audit and access rights, and transition provisions. Separately, Article 28 requires documented <a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/nis2-requirements\" target=\"_blank\" rel=\"noopener\">exit strategies<\/a> for ICT services supporting critical or important functions so that contractual arrangements can be exited without undue disruption.<\/p>\n<\/p>\n<\/div>\n<div class=\"accent-note accent-note--special accent-note--line ui-mb-sm-1\">\n<p class=\"primary-medium-text ui-mb-xs-3\"><em><b>Insight 2.<\/b><\/em><\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\"><em>CTPP designation is based on DORA&#8217;s Article 31 criteria, including systemic impact, the importance of the functions supported, and substitutability. Broad use across the financial sector can therefore contribute to the concentration and systemic-dependency considerations assessed by the ESAs, but designation is not based on market success alone.<\/em><\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\"><em>Self-hosting can reduce dependence on vendor-operated shared cloud infrastructure and therefore reduce one form of concentration risk. It does not automatically eliminate ICT third-party risk: software licensing, support, updates, maintenance, integrations, and other contracted services may still create relevant third-party dependencies that need to be assessed under DORA.<\/em><\/p>\n<\/div>\n<h2 class=\"h4--main h4--thick black-text ui-mb-xs-3 ui-mt-md-1\">DORA in 2026: Implementation and Oversight<\/h2>\n<p class=\"primary-medium-text ui-mb-sm-1\">DORA has been applicable since 17 January 2025. By 2026, the regulatory framework includes the operational Register of Information process, adopted technical standards and implementing acts, and an active <a href=\"https:\/\/www.esma.europa.eu\/dora-oversight\" target=\"_blank\" rel=\"noopener noreferrer\">ESA oversight framework for designated Critical ICT Third-Party Providers<\/a>. The <a href=\"https:\/\/www.esma.europa.eu\/press-news\/esma-news\/european-supervisory-authorities-designate-critical-ict-third-party-providers\" target=\"_blank\" rel=\"noopener noreferrer\">first CTPP list was published on 18 November 2025<\/a>, and the ESAs have stated that oversight examinations and related activities will follow under the Lead Overseer framework.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">For financial entities, competent authorities have the supervisory, investigatory, sanctioning, and remedial powers set out in <a href=\"https:\/\/eur-lex.europa.eu\/eli\/reg\/2022\/2554\/oj\/eng\" target=\"_blank\" rel=\"noopener noreferrer\">Article 50<\/a>. DORA does not establish one uniform EU-wide maximum administrative fine for financial entities; Member States provide the applicable penalty rules. Separate periodic penalty-payment provisions apply to Critical ICT Third-Party Providers in the context of ESA oversight. Financial entities should therefore be able to evidence how ICT services are recorded, risk-assessed, contracted, tested, and monitored in accordance with the requirements applicable to the specific service and supported function.<\/p>\n<div class=\"accent-note ui-mb-sm-1\">\n<h2 class=\"h4--main h4--thick black-text ui-mb-xs-3 ui-mt-md-1\">Five Steps to DORA Compliance for Communication and Collaboration Tools<\/h2>\n<p class=\"primary-medium-text ui-mb-sm-1\">A practical review of communication and collaboration tools can follow the sequence below, while the institution&#8217;s full DORA programme should address all applicable requirements across the regulation.<\/p>\n<ol class=\"ui-list ui-list--medium\" style=\"margin-bottom: 18px; margin-left: 20px;\">\n<li class=\"ui-list__item\"><b>Inventory every <a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/class-collaboration-tool\" target=\"_blank\" rel=\"noopener\">communication and collaboration tool<\/a> actually in use<\/b>, including tools adopted informally by individual desks or departments outside a formal procurement process, since an unlisted tool is an unlisted risk regardless of how it was acquired.<\/li>\n<li class=\"ui-list__item\"><b>Determine how each tool is used and whether it supports a critical or important function<\/b>, using the institution&#8217;s DORA classification process rather than assuming that data sensitivity alone determines criticality.<\/li>\n<li class=\"ui-list__item\"><b>Populate the Register of Information for relevant contractual ICT-service arrangements<\/b> using the required templates and data fields. Where the service supports a critical or important function, apply the additional risk-management, contractual, and exit-planning requirements.<\/li>\n<li class=\"ui-list__item\"><b>Build and rehearse an incident response and alternate communication plan<\/b> that assumes the primary communication platform itself is the thing that has failed, not just a system it happens to report on.<\/li>\n<li class=\"ui-list__item\"><b>Include relevant communication services in <a href=\"https:\/\/trueconf.com\/blog\/wiki\/video-resolution\" target=\"_blank\" rel=\"noopener\">resilience testing<\/a><\/b> where they support the functions being tested. For entities identified under Article 26, TLPT must cover several or all critical or important functions and the relevant underlying ICT systems and services, with a baseline frequency of at least every three years that the competent authority may adjust.<\/li>\n<\/ol>\n<\/div>\n<h2 class=\"h4--main h4--thick black-text ui-mb-xs-3 ui-mt-md-1\">How On-Premises Communication Infrastructure Can Affect DORA Risk?<\/h2>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-46482\" title=\"On-premises deployment\" src=\"https:\/\/trueconf.com\/blog\/wp-content\/uploads\/2026\/02\/secure-shield.svg\" alt=\"On-premises deployment\" width=\"396\" height=\"324\" \/ loading=\"lazy\"><\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">A financial institution running video conferencing and messaging on <a href=\"https:\/\/trueconf.com\/docs\/main\/\" target=\"_blank\" rel=\"noopener\">TrueConf Server<\/a> on infrastructure it operates directly has a different dependency model from an institution using a vendor-operated shared cloud service. This can reduce reliance on external hosting, but it does not remove the need to assess any ICT services obtained from the software vendor or other providers.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">Self-hosting may simplify some data-location, hosting, and subprocessor dependencies because communication data can remain on infrastructure controlled by the institution. However, an on-premises software deployment can still involve contractual ICT services such as licensing, support, maintenance, updates, or integrations.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">Those arrangements should be assessed for Register of Information and third-party risk requirements based on their actual scope. Exit-strategy obligations also depend on whether an ICT service supports a critical or important function and on the contractual relationship involved.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">An on-premises deployment can give the institution direct access to its own platform logs and infrastructure during an incident, which may support investigation and continuity planning. TrueConf Server can also operate without a persistent internet connection, allowing an organization to design an internal communication path that does not depend on public internet availability.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">Whether a particular incident is reportable still depends on DORA&#8217;s major-incident classification criteria.<\/p>\n<div class=\"accent-note accent-note--special accent-note--line ui-mb-sm-1\">\n<p class=\"primary-medium-text ui-mb-xs-3\"><em><b>Insight 3.<\/b><\/em><\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\"><em>DORA requires financial entities to plan how they can exit ICT-service arrangements supporting critical or important functions without undue disruption. For a self-hosted deployment, the transition risk may differ from that of a vendor-operated cloud service because hosting and data custody can remain under the institution&#8217;s control.<\/em><\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\"><em>Self-hosting can reduce exposure to shared-cloud concentration and give the institution more control over hosting and data location. It does not by itself remove software-vendor dependencies or DORA obligations associated with contracted ICT services. The relevant risk posture should therefore be assessed from the actual architecture, contracts, support model, integrations, and functions supported.<\/em><\/p>\n<\/div>\n<div class=\"accent-note ui-mb-sm-1\">\n<h2 class=\"h4--main h4--thick black-text ui-mb-xs-3 ui-mt-md-1\">Conclusion: DORA and Resilient Communication Planning<\/h2>\n<p class=\"primary-medium-text ui-mb-sm-1\">DORA requires financial entities to treat ICT resilience as an ongoing governance, risk-management, testing, incident-management, and third-party-risk discipline.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">Communication systems are relevant when they form part of the ICT environment used to support financial services, incident response, or critical or important functions. Their treatment under DORA depends on the role they play, the architecture in which they operate, and the contractual ICT-service relationships involved.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">For financial institutions evaluating communication platforms, the practical questions are therefore whether the service can be inventoried and governed, how incidents can be investigated and communicated, how continuity is maintained, what third-party dependencies exist, and how the platform fits into the institution&#8217;s resilience-testing and exit-planning framework.<\/p>\n<\/div>\n<div style=\"background: #00B3CD; border-radius: 12px; padding: 24px;\">\n<h2 class=\"h4--main h4--thick white-text center-text ui-mb-xs-3\">Empower your video conferencing experience with TrueConf!<\/h2>\n<div class=\"button-group-container button-group-container--center\"><a class=\"primary-smallest-text to-page to-page--rarr white-icon white-text\" role=\"link\" href=\"https:\/\/trueconf.com\/products\/server\/video-conferencing-server.html\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Learn more<\/a><\/div>\n<\/div>\n<section id=\"faq\">\n<h2 class=\"h3--main h3--thick black-text ui-mb-md-1\">FAQ<\/h2>\n<div class=\"faq__container ui-mb-md-1\">\n<div class=\"faq__item\">\n<p class=\"faq__question h4--main h4--thick black-text hyphens--auto margin--not\">What is the DORA (Digital Operational Resilience Act) Regulation?<\/p>\n<div class=\"faq__answer\">\n<p class=\"primary-medium-text margin--not\">DORA (Digital Operational Resilience Act), Regulation (EU) 2022\/2554, establishes EU-wide digital operational resilience requirements for financial entities. It has applied since 17 January 2025 and covers ICT risk management, major ICT-related incident reporting, resilience testing, ICT third-party risk management, and voluntary information sharing. Communication platforms may fall within these processes depending on how they are used and whether they are supplied as ICT services.<\/p>\n<\/div>\n<\/div>\n<div class=\"faq__item\">\n<p class=\"faq__question h4--main h4--thick black-text hyphens--auto margin--not\">When did DORA become applicable across the European Union?<\/p>\n<div class=\"faq__answer\">\n<p class=\"primary-medium-text margin--not\">DORA has applied across the EU since 17 January 2025. National competent authorities supervise financial entities under the framework established by DORA, while the ESAs operate the oversight framework for designated Critical ICT Third-Party Providers. The first CTPP list was published on 18 November 2025.<\/p>\n<\/div>\n<\/div>\n<div class=\"faq__item\">\n<p class=\"faq__question h4--main h4--thick black-text hyphens--auto margin--not\">What distinguishes DORA from previous regulatory initiatives?<\/p>\n<div class=\"faq__answer\">\n<p class=\"primary-medium-text margin--not\">DORA gives the management body responsibility for the financial entity&#8217;s ICT risk-management framework and introduces a Union-wide oversight framework for ICT third-party service providers designated as critical. A self-hosted architecture can reduce dependence on vendor-operated cloud infrastructure, but it does not automatically remove software-vendor or other ICT third-party relationships.<\/p>\n<\/div>\n<\/div>\n<div class=\"faq__item\">\n<p class=\"faq__question h4--main h4--thick black-text hyphens--auto margin--not\">Why does secure communication infrastructure matter under DORA?<\/p>\n<div class=\"faq__answer\">\n<p class=\"primary-medium-text margin--not\">Article 14 requires financial entities to maintain crisis communication plans for major ICT-related incidents or vulnerabilities. Communication platforms used for incident response or critical or important functions should therefore be included in relevant ICT risk, continuity, and testing decisions. A platform capable of operating without a persistent internet connection can support architectures designed to maintain internal communications during loss of public connectivity.<\/p>\n<\/div>\n<\/div>\n<div class=\"faq__item\">\n<p class=\"faq__question h4--main h4--thick black-text hyphens--auto margin--not\">Why is it important that DORA is a regulation rather than a directive?<\/p>\n<div class=\"faq__answer\">\n<p class=\"primary-medium-text margin--not\">Because DORA is an EU regulation, its core requirements apply directly without national transposition. Supervision and penalties can still involve national competent authorities and national legal frameworks, so implementation and enforcement should be assessed in the relevant jurisdiction.<\/p>\n<\/div>\n<\/div>\n<div class=\"faq__item\">\n<p class=\"faq__question h4--main h4--thick black-text hyphens--auto margin--not\">Which entities does DORA cover?<\/p>\n<div class=\"faq__answer\">\n<p class=\"primary-medium-text margin--not\">DORA covers the financial entities listed in Article 2, including credit institutions, insurance and reinsurance undertakings, investment firms, payment institutions, electronic money institutions, and certain crypto-asset market participants. Communication platforms used by those entities should be assessed according to their role in the ICT environment and any relevant ICT-service contractual arrangement.<\/p>\n<\/div>\n<\/div>\n<div class=\"faq__item\">\n<p class=\"faq__question h4--main h4--thick black-text hyphens--auto margin--not\">Does DORA extend oversight to third-party ICT service providers?<\/p>\n<div class=\"faq__answer\">\n<p class=\"primary-medium-text margin--not\">Yes. DORA establishes an oversight framework for ICT third-party service providers designated as critical under Article 31. A provider of <a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/unified-communication-platform\" target=\"_blank\" rel=\"noopener\">communication or collaboration services<\/a> could fall within that framework if it meets the designation criteria. Self-hosting can reduce reliance on shared vendor-operated infrastructure, but contracted software, support, maintenance, updates, or integrations may still constitute relevant ICT third-party dependencies.<\/p>\n<\/div>\n<\/div>\n<div class=\"faq__item\">\n<p class=\"faq__question h4--main h4--thick black-text hyphens--auto margin--not\">What is the Register of Information, and does it apply to video conferencing platforms?<\/p>\n<div class=\"faq__answer\">\n<p class=\"primary-medium-text margin--not\">The Register of Information is the structured record financial entities maintain for contractual arrangements on the use of ICT services provided by ICT third-party service providers. A video conferencing or messaging service can belong in the register when it is obtained through such an arrangement. Whether the service supports a critical or important function affects additional DORA requirements. An on-premises deployment should be assessed based on the actual licensing, support, maintenance, update, integration, and hosting arrangements rather than assumed to be outside the register.<\/p>\n<\/div>\n<\/div>\n<div class=\"faq__item\">\n<p class=\"faq__question h4--main h4--thick black-text hyphens--auto margin--not\">What happens if a communications vendor is designated a Critical ICT Third-Party Provider?<\/p>\n<div class=\"faq__answer\">\n<p class=\"primary-medium-text margin--not\">A vendor designated as a Critical ICT Third-Party Provider becomes subject to the DORA oversight framework led by the relevant European Supervisory Authority, including examinations, information requests, recommendations, and follow-up. A self-hosted architecture can reduce dependence on a shared vendor-operated cloud service, but any remaining contracted ICT services should still be included in the institution&#8217;s third-party risk assessment.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/section>\n<div class=\"accent-note accent-note--special ui-mb-sm-1\">\n<p class=\"primary-medium-text\"><strong><i>About the Author<\/i><\/strong><br \/>\n<i>Diana Shtapova is a product specialist and technology writer with three years of experience in the unified communications industry. At TrueConf, she leverages her deep product expertise to create clear and practical content on video conferencing platforms, collaboration tools, and enterprise communication solutions. With a strong background in product research and user-focused content development, Diana helps professionals and businesses understand core product features, adopt new technologies, and unlock the full potential of modern.<\/i><\/p>\n<p><a class=\"primary-small-text to-page to-page--rarr cyan-icon\" role=\"link\" href=\"https:\/\/www.facebook.com\/shtapovadiana\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\"><i>Connect with Diana on Facebook<\/i><\/a><\/p>\n<\/div>\n<p><script type=\"application\/ld+json\">\n{\n  \"@context\": \"https:\/\/schema.org\",\n  \"@type\": \"BlogPosting\",\n  \"headline\": \"DORA Regulation: What It Means for Secure Communications\",\n  \"description\": \"A guide to Regulation (EU) 2022\/2554 (DORA), including ICT risk management, incident reporting, resilience testing, ICT third-party risk, the Register of Information, CTPP oversight, and implications for communication platforms.\",\n  \"url\": \"https:\/\/trueconf.com\/blog\/reviews-comparisons\/dora-regulation\",\n  \"mainEntityOfPage\": {\n    \"@type\": \"WebPage\",\n    \"@id\": \"https:\/\/trueconf.com\/blog\/reviews-comparisons\/dora-regulation\"\n  },\n  \"dateModified\": \"2026-08-31\",\n  \"inLanguage\": \"en\",\n  \"author\": {\n    \"@type\": \"Person\",\n    \"name\": \"Diana Shtapova\"\n  },\n  \"publisher\": {\n    \"@type\": \"Organization\",\n    \"name\": \"TrueConf\",\n    \"url\": \"https:\/\/trueconf.com\"\n  },\n  \"citation\": [\n    \"https:\/\/eur-lex.europa.eu\/eli\/reg\/2022\/2554\/oj\/eng\",\n    \"https:\/\/eur-lex.europa.eu\/eli\/reg_impl\/2024\/2956\/oj\/eng\",\n    \"https:\/\/www.esma.europa.eu\/dora-oversight\",\n    \"https:\/\/www.esma.europa.eu\/press-news\/esma-news\/european-supervisory-authorities-designate-critical-ict-third-party-providers\",\n    \"https:\/\/eur-lex.europa.eu\/eli\/reg_del\/2025\/301\/oj\/eng\",\n    \"https:\/\/eur-lex.europa.eu\/eli\/reg_impl\/2025\/302\/oj\/eng\"\n  ],\n  \"about\": [\n    {\n      \"@type\": \"Thing\",\n      \"name\": \"Digital Operational Resilience Act\"\n    },\n    {\n      \"@type\": \"Thing\",\n      \"name\": \"ICT risk management\"\n    },\n    {\n      \"@type\": \"Thing\",\n      \"name\": \"Digital operational resilience testing\"\n    },\n    {\n      \"@type\": \"Thing\",\n      \"name\": \"ICT third-party risk management\"\n    },\n    {\n      \"@type\": \"Thing\",\n      \"name\": \"Critical ICT Third-Party Provider\"\n    },\n    {\n      \"@type\": \"Thing\",\n      \"name\": \"Register of Information\"\n    }\n  ]\n}\n<\/script><br \/>\n<script type=\"application\/ld+json\">\n{\n  \"@context\": \"https:\/\/schema.org\",\n  \"@type\": \"FAQPage\",\n  \"mainEntity\": [\n    {\n      \"@type\": \"Question\",\n      \"name\": \"What is the DORA (Digital Operational Resilience Act) Regulation?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"DORA (Digital Operational Resilience Act), Regulation (EU) 2022\/2554, establishes EU-wide digital operational resilience requirements for financial entities. It has applied since 17 January 2025 and covers ICT risk management, major ICT-related incident reporting, resilience testing, ICT third-party risk management, and voluntary information sharing. Communication platforms may fall within these processes depending on how they are used and whether they are supplied as ICT services.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"When did DORA become applicable across the European Union?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"DORA has applied across the EU since 17 January 2025. National competent authorities supervise financial entities under the framework established by DORA, while the ESAs operate the oversight framework for designated Critical ICT Third-Party Providers. The first CTPP list was published on 18 November 2025.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"What distinguishes DORA from previous regulatory initiatives?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"DORA gives the management body responsibility for the financial entity's ICT risk-management framework and introduces a Union-wide oversight framework for ICT third-party service providers designated as critical. A self-hosted architecture can reduce dependence on vendor-operated cloud infrastructure, but it does not automatically remove software-vendor or other ICT third-party relationships.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"Why does secure communication infrastructure matter under DORA?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"Article 14 requires financial entities to maintain crisis communication plans for major ICT-related incidents or vulnerabilities. Communication platforms used for incident response or critical or important functions should therefore be included in relevant ICT risk, continuity, and testing decisions. A platform capable of operating without a persistent internet connection can support architectures designed to maintain internal communications during loss of public connectivity.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"Why is it important that DORA is a regulation rather than a directive?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"Because DORA is an EU regulation, its core requirements apply directly without national transposition. Supervision and penalties can still involve national competent authorities and national legal frameworks, so implementation and enforcement should be assessed in the relevant jurisdiction.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"Which entities does DORA cover?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"DORA covers the financial entities listed in Article 2, including credit institutions, insurance and reinsurance undertakings, investment firms, payment institutions, electronic money institutions, and certain crypto-asset market participants. Communication platforms used by those entities should be assessed according to their role in the ICT environment and any relevant ICT-service contractual arrangement.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"Does DORA extend oversight to third-party ICT service providers?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"Yes. DORA establishes an oversight framework for ICT third-party service providers designated as critical under Article 31. A provider of communication or collaboration services could fall within that framework if it meets the designation criteria. Self-hosting can reduce reliance on shared vendor-operated infrastructure, but contracted software, support, maintenance, updates, or integrations may still constitute relevant ICT third-party dependencies.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"What is the Register of Information, and does it apply to video conferencing platforms?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"The Register of Information is the structured record financial entities maintain for contractual arrangements on the use of ICT services provided by ICT third-party service providers. A video conferencing or messaging service can belong in the register when it is obtained through such an arrangement. Whether the service supports a critical or important function affects additional DORA requirements. An on-premises deployment should be assessed based on the actual licensing, support, maintenance, update, integration, and hosting arrangements rather than assumed to be outside the register.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"What happens if a communications vendor is designated a Critical ICT Third-Party Provider?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"A vendor designated as a Critical ICT Third-Party Provider becomes subject to the DORA oversight framework led by the relevant European Supervisory Authority, including examinations, information requests, recommendations, and follow-up. A self-hosted architecture can reduce dependence on a shared vendor-operated cloud service, but any remaining contracted ICT services should still be included in the institution's third-party risk assessment.\"\n      }\n    }\n  ]\n}\n<\/script><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Digital Operational Resilience Act (DORA), Regulation (EU) 2022\/2554, establishes EU-wide requirements for the digital operational resilience of financial entities. It covers ICT risk management, major ICT-related incident reporting, resilience testing, ICT third-party risk, and voluntary information sharing, with additional oversight applying to designated critical ICT third-party service providers. DORA has applied since 17 January [&hellip;]<\/p>\n","protected":false},"author":78,"featured_media":49326,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[32],"tags":[386,393],"class_list":["post-48828","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-reviews-comparisons","tag-security","tag-unified-communications","wpautop"],"_links":{"self":[{"href":"https:\/\/trueconf.com/blog\/wp-json\/wp\/v2\/posts\/48828","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/trueconf.com/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/trueconf.com/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/trueconf.com/blog\/wp-json\/wp\/v2\/users\/78"}],"replies":[{"embeddable":true,"href":"https:\/\/trueconf.com/blog\/wp-json\/wp\/v2\/comments?post=48828"}],"version-history":[{"count":26,"href":"https:\/\/trueconf.com/blog\/wp-json\/wp\/v2\/posts\/48828\/revisions"}],"predecessor-version":[{"id":49327,"href":"https:\/\/trueconf.com/blog\/wp-json\/wp\/v2\/posts\/48828\/revisions\/49327"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/trueconf.com/blog\/wp-json\/wp\/v2\/media\/49326"}],"wp:attachment":[{"href":"https:\/\/trueconf.com/blog\/wp-json\/wp\/v2\/media?parent=48828"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/trueconf.com/blog\/wp-json\/wp\/v2\/categories?post=48828"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/trueconf.com/blog\/wp-json\/wp\/v2\/tags?post=48828"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}