DORA regulation: compliance software for UK firms with EU exposure
DORA, the EU's Digital Operational Resilience Act, has applied since 17 January 2025. It does not bind UK-only firms directly, but it reaches UK financial entities with EU subsidiaries or branches, and UK firms that provide ICT services to EU financial entities. STREAM® by Acuity helps in-scope firms evidence DORA's ICT risk, third-party oversight and incident obligations, including the cyber risk and control evidence behind the Register of Information.
Does DORA apply to a UK firm?
Not automatically. DORA is an EU regulation. A purely domestic UK firm with no EU nexus is regulated instead by the FCA and PRA operational resilience regime (FCA PS21/3 and PRA SS1/21), not by DORA. But two things pull a UK firm into DORA's scope:
An EU subsidiary or branch
You have an EU subsidiary or branch that is itself a regulated financial entity.
ICT provider to EU entities
You act as an ICT third-party provider to EU financial entities, including an intra-group UK IT function serving an EU subsidiary. Your EU clients must build DORA's contract terms (Article 30) into their agreements with you, so the obligations reach you through the contract.
If either is true, DORA follows you home. If neither is, your obligations sit with the FCA/PRA regime, and STREAM® supports that too. New UK rules on operational incident and third-party reporting (PRA SS1/26 and FCA PS26/2) take effect on 18 March 2027.
What is DORA, and when did it take effect?
DORA (Regulation (EU) 2022/2554) creates one binding standard for how EU financial entities manage ICT risk. It entered into force on 16 January 2023 and has applied since 17 January 2025, following a two-year transition. It rests on five pillars: ICT risk management, incident reporting, digital operational resilience testing, ICT third-party risk, and information sharing. The detail is in the regulatory and implementing technical standards (RTS and ITS) made under it, including the RTS on incident reporting and the ITS templates for the Register of Information.
DORA compliance checklist
Six things every in-scope firm needs to be able to show a supervisor:
ICT risk management framework: Documented, approved by the management body and reviewed at least once a year.
Incident classification and reporting: ICT incidents classified against the RTS criteria, and major incidents reported on the deadlines below.
Resilience testing: A testing programme covering critical ICT systems, with threat-led penetration testing where the authority requires it.
ICT third-party risk: A third-party strategy, a complete Register of Information and the Article 30 terms in every ICT contract.
Information sharing: Optional arrangements to exchange cyber threat intelligence with other financial entities.
Management body accountability: The board holds final responsibility for ICT risk and must be able to evidence it.
DORA incident reporting timelines
Under Commission Delegated Regulation (EU) 2025/301, a major ICT-related incident is reported in three stages:
Initial notification. Within 4 hours of classifying the incident as major, and no later than 24 hours after becoming aware of it.
Intermediate report. Within 72 hours of the initial notification.
Final report. Within one month of the latest intermediate report.
STREAM® helps you assess incidents against the classification criteria and assemble the evidence each report needs. Your team submits the reports.
The Register of Information: DORA's hardest requirement
Under Article 28(3), every in-scope financial entity must maintain a Register of Information: a complete, structured record of every contractual arrangement with every ICT third-party provider, held at entity, sub-consolidated and consolidated levels, using the templates in Implementing Regulation (EU) 2024/2956. Supervisors can ask for the full register at any time, and it is the first place teams come unstuck.
How STREAM® helps you evidence DORA
STREAM® by Acuity gives in-scope firms one place to build and maintain the evidence DORA demands, rather than a spreadsheet per obligation.
Register of Information evidence
Hold the cyber risk assessment, tiering and control evidence for each ICT third-party provider, so the data behind your Register of Information is complete and current. STREAM® is not positioned as the tool that produces the ESA reporting templates.
ICT third-party risk
Assess and continuously monitor cyber risk across your ICT vendor population, with tiering and control evidence, via the Vendor Management Hub.
Incident readiness
Assess incidents against the DORA classification criteria and assemble the evidence each major-incident report requires, ready for your team to submit.
Control monitoring
Map controls once and evidence them against DORA and your other frameworks together, so continuous compliance replaces the annual scramble.
What's at stake
DORA gives supervisors real teeth. For financial entities, EU member states set the administrative penalties and remedial measures (Article 50). For critical ICT third-party providers, the Lead Overseer can impose periodic penalty payments of up to 1% of average daily worldwide turnover (Article 35(8)). Beyond the fine, the exposure is board-level: DORA places ICT and third-party resilience squarely within management-body accountability, and a failed Register is a documented, dated finding. STREAM® exists to make that accountability defensible: evidence you can put in front of a supervisor, produced continuously rather than reconstructed under deadline.
See how STREAM® evidences DORA
Book a walkthrough with our team and see the evidence behind your Register of Information, ICT third-party risk and incident evidence in one platform.
Book a walkthroughRelated solution
Third-Party Risk Management
How STREAM® and the Vendor Management Hub help you assess and continuously monitor cyber risk across your ICT vendor population.
Explore third-party risk management →Frequently asked questions about DORA
Common questions on DORA scope, the Register of Information, and how STREAM® helps.