B.BlockAxis⌕ Search
Menu

DORA and digital operational resilience

DORA is the EU framework for digital operational resilience in the financial sector, applicable from 17 January 2025.

IntermediateContent revised · 13.09.20263 min reading · allow 5–10 more minutes for the workshopBlockAxis

Your learning plan

Turn resilience requirements into testable operations

By the end, explain the diagram in your own words, solve the case and justify the correction.

Prerequisites : Security, scaling and governance

Level 2 · Intermediate →

Reading path · 24 / 35 · Intermediate

Key takeaway

DORA is the EU framework for digital operational resilience in the financial sector, applicable from 17 January 2025.

The essentials

DORA is the EU framework for digital operational resilience in the financial sector, applicable from 17 January 2025. It covers ICT risk management, incident reporting, resilience testing and third-party risk requirements for entities within its scope, including specified crypto-asset firms.

How it works

Its purpose is broader than cybersecurity prevention. Organisations need to withstand, respond to and recover from disruption. Map important services to systems and providers, establish recovery objectives, maintain incident classification processes and manage contractual and concentration risks. A backup is useful only if restoration works.

What to watch

For a custody service, examine the signing platform, cloud infrastructure, blockchain-node access and internal ledgers together. An outage in one dependency can interrupt withdrawals even when the blockchain is functioning. Determine the exact entity’s scope and applicable technical requirements before treating a general control checklist as compliance evidence.

Understand the details

Operational resilience concerns maintaining and restoring critical services through ICT disruption. An assessment begins with the functions the organization must deliver, then maps applications, infrastructure, people and external dependencies supporting them. A blockchain’s continued production of blocks does not mean a firm’s own withdrawal, reconciliation or customer service remains available.

Boundaries and common mistakes

Document incident detection, decision responsibility, communication and recovery evidence. Third-party reliance should include concentration and exit considerations, not just a service-level promise. Applicability and specific reporting duties depend on the regulated entity and relevant rules, so a generic checklist cannot substitute for that assessment.

The mechanism at a glance

  1. Critical service
  2. Dependency map
  3. Incident and recovery test
  4. Evidence of restored service
Turn resilience requirements into testable operations. Conceptual map: read these four landmarks together with the explanation above.
Applied workshop · work at your own pace

Apply the lesson to a case

A firm uses one cloud provider for its wallet policy service, monitoring and backups. Simulate a regional outage. List the critical functions affected and the evidence needed before declaring recovery complete.

Why is restoring the website alone insufficient?

Choose one answer.

Prepare a correction note

Describe the passage and the proposed correction. This creates a local note for you to share; it sends nothing. Do not include personal or confidential information.