EuroComply
Sign up
Official source map

DORA official sources

Primary DORA sources: official regulation text, ESMA and ESA guidance, ICT risk and third-party register references, and EuroComply checklists.

What official sources should SMEs cite for DORA?

The primary source for DORA is Regulation (EU) 2022/2554, supported by ESA and ESMA technical standards and guidance. Financial entities should retain evidence for ICT risk management, incident reporting, resilience testing, third-party risk management and ICT provider registers.

  • Chapter II: ICT risk management
  • Chapter III: Incident reporting
  • Chapter IV: Resilience testing
  • Chapter V: Third-party risk
Primary sourceRegulation (EU) 2022/2554
EuroComply source page/sources/dora
Last reviewed2026-05-11
Source: Regulation (EU) 2022/2554Reviewed:

Key references

ReferenceTopicWhy it matters
Chapter IIICT risk managementCore control framework.
Chapter IIIIncident reportingMajor incident reporting duties.
Chapter IVResilience testingTesting and TLPT where applicable.
Chapter VThird-party riskICT provider contract and register duties.

Use the source map with an action plan

Official sources answer what the law says. EuroComply guides turn those references into owners, deadlines, evidence and dashboard-ready actions.

EU AI Act official sourcesGDPR official sourcesNIS2 official sourcesData Act official sourcesPay Transparency Directive official sources