DORA makes ICT third-party resilience a contractual and oversight responsibility for regulated financial entities

DORA moves technology resilience in financial services from good practice into contractual and supervisory obligation.

It requires regulated entities to know their critical technology dependencies, hold specific terms in supplier contracts, test their resilience and report incidents. The significant shift is that your supplier's resilience becomes something you are answerable for, rather than something you hope about.

Checked against the primary source.

More on Regulation and law