Regulation (EU) 2022/2554 — Digital Operational Resilience

DORA, for mutual insurers and insurance.

Since 17 January 2025, digital resilience is no longer a best practice: it is a directly applicable obligation, supervised by the ACPR. Here is the framework, the five pillars and the deadlines that structure compliance.

Applicable since
17 Jan. 2025Directly applicable, no transposition
Nature
EU RegulationTakes precedence over NIS2 for finance
Supervisor (FR)
ACPRInsurers, mutuals, provident funds
Pillars
5 domainsFrom ICT risk to info-sharing
Who is concerned

Health and provident mutual insurers are in scope

DORA applies to all insurance and reinsurance undertakings, mutual insurers, provident institutions and intermediaries supervised by the ACPR. Size does not remove you from scope: it only modulates the intensity of the obligations, through the proportionality principle set out in Article 4.

Fully subject

  • Health & provident mutuals, insurers, reinsurers
  • Provident institutions and occupational retirement funds
  • Intermediaries above the micro / SME thresholds
  • Register of information + major-incident reporting to the ACPR

Simplified regime or out of scope

  • Micro-entities: balance sheet ≤ €5M or ≤ 10 staff
  • Simplified ICT risk-management framework for the smallest entities
  • Micro / SME intermediaries: notification possible by simple e-mail
  • No consolidated register submission for solo intermediaries
Proportionality, not exemption. A small mutual is still required to demonstrate its ability to withstand an outage or a cyberattack without interrupting service. The simplified regime reduces the formalism, not the resilience objective.
The five pillars

What DORA requires, concretely

The regulation structures compliance around five domains. The first three concern internal organisation; the last two cover the ecosystem — providers and peers.

PILLAR 01

Governance & ICT risk management

A documented framework, approved by the management body, which remains accountable. Security policies, asset mapping, continuous detection, tested and updated BCP/DRP.

Management accountability
PILLAR 02

Major-incident reporting

Detect, classify then report to the ACPR any major ICT-related incident on a strict timeline — including an outage or failure with no cyber origin.

4h · 72h · 1 month
PILLAR 03

Resilience testing

A programme of regular tests (vulnerability, continuity, performance). Significant entities additionally run a TLPT — threat-led penetration test — at least every 3 years, under the TIBER-EU framework.

TLPT / 3 yrs if significant
PILLAR 04

ICT third-party risk

An up-to-date register of information, mandatory contractual clauses (Art. 30), due diligence before contracting, exit and reversibility strategies. European oversight of providers deemed critical.

Register + Art. 30 clauses
PILLAR 05

Sharing of cyber-threat information

On a voluntary basis, financial entities may exchange intelligence and indicators on threats and vulnerabilities, to strengthen the sector's collective defence.

Voluntary

The reporting countdown (Art. 19)

Calendar deadlines — nights and weekends included
Detection
Classification within 24h max of discovery
4H
Initial notification to the ACPR after a "major" classification
72H
Intermediate report as the situation evolves
1 MONTH
Final report after root-cause analysis
The ACPR takes a broad reading of the "major incident": a single severity criterion can be enough. Anticipate a high volume of reports, and pre-equip classification outside business hours.
The calendar

The deadlines that structure compliance

Beyond the entry-into-application date, two obligations recur continuously: incident reporting and the annual submission of the register of information.

17 JANUARY 2025

Entry into application

The ICT risk-management framework, the classification/notification procedures and a tested BCP must be operational. Directly applicable across the whole EU.

CONTINUOUS — SINCE 17/01/2025

Major-incident reporting ongoing

Each major incident triggers the 4h / 72h / 1 month sequence with the ACPR, through the dedicated portal. In the event of a personal-data breach, dual notification DORA + GDPR (CNIL, 72h).

BY 31 MARCH — EVERY YEAR

Register of information (RoI) submission annual

Lists all agreements with ICT service providers. Data as of 31 December N-1, submitted via OneGate (Banque de France). A LEI identifier is required.

2025 → 2026

Ramp-up of supervision

2025 focused on guidance and first targeted checks; 2026 marks the intensification of compliance audits by the ACPR.

In case of breach

Sanctions — but above all a continuity stake

The competent authorities have extensive powers. Beyond the fine, it is the ability to serve members and the reputation that are exposed.

€10M / 5%

Reported administrative-fine caps for the most serious breaches (the higher amount applies, as a % of annual turnover). A specific sanction regime applies to critical ICT providers.

  • Immediate corrective measures and compliance injunctions
  • Temporary suspension of activities in the event of critical failure
  • Order to terminate a contract with a non-compliant provider
  • Publication of the sanction — reputational "name & shame" effect
2Be-FFICIENT × DORA

Where 2Be-FFICIENT fits into the framework

DORA extends the perimeter well beyond cyber: an unavailable member area, a bug in claims processing or a slow subscription journey are ICT services whose availability must be monitored, tested and evidenced. That is exactly 2Be-FFICIENT's ground — without installing anything in your IT system. Here is how each capability maps to a requirement of the regulation.

An asset in a framework that scrutinises third-party dependency. DORA reinforces the oversight of ICT service providers (register, clauses, reversibility). 2Be-FFICIENT installs nothing in your information system and does not host your application data — one less point of vigilance in your supplier relationships.
Turning a resilience obligation into monitoring that lasts.
Talk with 2Be-FFICIENT →

Sources & reference texts

  • Regulation (EU) 2022/2554 — DORA (EUR-Lex)
  • Directive (EU) 2022/2556 — sectoral adaptations (incl. Solvency II)
  • Delegated Regulation (EU) 2024/1772 — incident-classification criteria
  • Implementing Regulation (EU) 2025/302 — reporting templates and procedures
  • ACPR — DORA FAQ & instruction no. 2025-I-12 (register of information)
  • AMF — DORA thematic dossier
  • EIOPA / ESAs — decision of 8 Nov. 2024 on register submission
  • TIBER-EU — reference framework for TLPT testing
Informative summary page, non-exhaustive and without the value of legal advice. Sanction thresholds and the interpretation of certain notions (major incident, significant entity) vary according to the implementing texts and the supervisor's positions. Refer to the text of the regulation, its technical standards (RTS/ITS) and the ACPR's publications for any compliance decision.
FR EN