ICT risk management and operational resilience for EU financial entities — in force since 17 January 2025.
DORA — Regulation (EU) 2022/2554 — is the EU's horizontal rulebook for the digital operational resilience of financial entities. It became applicable on 17 January 2025, after a two-year transition.
Banks, payment and e-money institutions, investment firms, crypto-asset service providers, central counterparties, central securities depositories, trading venues, fund managers, insurance and reinsurance undertakings, and crowdfunding service providers — among others. Critical ICT Third-Party Providers are also brought under direct EU oversight.
Bucephalus is treated as ICT for DORA purposes: hash-chained event logs, structured incident reporting, and the deployment models that allow a bank to keep critical operations inside its own trust boundary.