Skip to main content
Link to Walkers homepage

Navigating DORA: Key compliance steps from 17 January 2025

Jan 16, 2025

Advisory
A sleek black pen with 'Walkers' branding lies atop a closed notebook, both featuring raised 'Walkers' logos.

key takeaways

  • DORA is now applicable, imposing requirements in respect of ICT risk management and digital operational resilience.

  • Firms should be preparing their register of information ready for sharing with the CBI in April.

  • Reporting major ICT-related incidents is now mandatory within specified timeframes.

The Digital Operational Resilience Act (DORA) applies to certain financial entities from today – 17th January 2025.

DORA aims to ensure that financial entities operating in the EU financial services industry can withstand, respond to and recover from all types of information and communication technology (ICT)-related disruptions and threats.
 
Starting today, national competent authorities (NCAs) such as the Central Bank of Ireland (CBI) will initiate their supervision of DORA. This includes conducting reviews to assess compliance along with gathering and verifying information requested by the European Supervisory Authorities (ESAs).
 
Following on from today's application date, the next significant deadline for firms is the submission of their register of information to their NCA who must submit this to the ESAs on 30 April 2025. Consequently, firms should be preparing their register of information ready for sharing in April. In its Industry Briefing on 6 November 2024, the CBI stated that it would seek to collect registers on the first week of April 2025.
 
Firms are also required to report major ICT-related incidents within specified timeframes on the determination of classifying an incident as major, and this was flagged as a key item for today's application date by the CBI.
 
Lastly, a number of firms will be designated by their NCA to conduct threat-led penetration testing. This designation will be communicated to the firms by their respective NCA. These firms must comply with additional advanced testing of their digital operational resilience.
 
In advance of the 17 January implementation date we have been assisting firms in reviewing their governance, ICT risk management, contractual and other arrangements for DORA readiness. Please reach out if you would like to discuss any of the above with our team.
Regulatory & ComplianceIreland

Authors

Niall Esler

Niall Esler

Partner/Ireland

T/+353 1 863 8517
M/+353 86 027 0344
E/Email Niall Esler
More articles from this author View profile
Shane Martin

Shane Martin

Partner/Ireland

T/+353 1 470 6673
M/+353 87 224 3486
E/Email Shane Martin
More articles from this author View profile
Laura Whitson

Laura Whitson

Associate/Ireland

T/+353 1 470 6615
E/Email Laura Whitson
More articles from this author View profile

Key contacts

Get in touch with our team

Niall Esler
Niall Esler

Niall Esler

Partner

Ireland

T

+353 1 863 8517

M

+353 86 027 0344

E

Email Niall Esler
View profile
Shane Martin
Shane Martin

Shane Martin

Partner

Ireland

T

+353 1 470 6673

M

+353 87 224 3486

E

Email Shane Martin
View profile
Laura Whitson
Laura Whitson

Laura Whitson

Associate

Ireland

T

+353 1 470 6615

E

Email Laura Whitson
View profile

Get the latest insights and expertise in your inbox 

Fluid ink image
Sign up
logo footer

Connect with us

FacebookFacebook
InstagramInstagram
LinkedInLinkedIn

Employee login

Self Service Password ResetWalkers AnywhereWalkers Sharefile
Legal notices/Cookies policy

All rights reserved - © 2025 Walkers Global