The Digital Operational Resilience Act — Regulation (EU) 2022/2554, DORA — is the EU regulation that turns ICT risk management into a directly applicable legal obligation for the financial sector. It applies from 17 January 2025 to a wide span of financial entities — credit institutions, insurers, investment firms, payment institutions, crypto-asset service providers — and, unusually, reaches through them to the critical ICT third-party providers they depend on. Because it is a regulation rather than a directive, there is no national transposition step: the text applies as written, across every member state, under the supervision of the European Supervisory Authorities.
Why it matters
DORA says nothing about post-quantum algorithms and sets no PQC deadline — on timelines it effectively inherits the NIST deprecate-2030 / disallow-2035 schedule and, for organizations that also touch national-security work, CNSA 2.0's milestones. What it does do is make cryptography a named component of a legally required ICT risk-management framework. Article 9 requires protection and prevention measures, and the accompanying regulatory technical standard on the ICT risk-management framework — Commission Delegated Regulation (EU) 2024/1774 — is explicit: financial entities must maintain a policy on encryption and cryptographic controls, manage keys across their lifecycle, and provide for updating or replacing cryptographic technology as cryptanalysis develops. That last clause is the quantum hook. A quantum computer that breaks RSA and ECC is precisely a development in cryptanalysis, and an entity that cannot say where its quantum-vulnerable cryptography lives cannot show it is managing that risk.
What DORA requires
DORA is built on five pillars, and cryptography sits inside the first of them:
- ICT risk management (Arts. 5–16) — a documented framework covering identification, protection, detection, and recovery; this is where the encryption and cryptographic-controls policy, key management, and the expectation of a maintained asset view live.
- ICT-related incident management and reporting (Arts. 17–23) — classify incidents and report major ones to the competent authority on fixed timelines.
- Digital operational resilience testing (Arts. 24–27) — a proportionate testing programme, up to threat-led penetration testing (TLPT) for significant entities.
- ICT third-party risk management (Arts. 28–44) — contractual requirements, a register of information on ICT providers, and EU-level oversight of critical ICT third-party providers.
- Information sharing (Art. 45) — voluntary exchange of cyber threat intelligence between financial entities.
No PQC date of its own — the cryptanalysis clause does the work
Do not wait for DORA to name a post-quantum deadline; it never will. The obligation is indirect but real: the RTS requires your cryptographic-controls policy to track developments in cryptanalysis and update technology accordingly, which in practice imports the NIST and CNSA timelines into your DORA evidence. The defensible position is a cryptographic inventory, a quantum-risk assessment against it, and a transition plan aligned to those external dates — decided now, not after a supervisory finding.
How quantakrypto helps
We help you produce the cryptographic evidence the ICT risk-management pillar asks for — we do not make you DORA-compliant, and no tool can. Our audit maps explicitly onto the ISO 27001 / DORA / NIS2 control set: it produces the cryptographic inventory of where quantum-vulnerable algorithms live in your code, protocols, and dependencies, plus the risk-ranked assessment that shows your controls policy is tracking cryptanalysis rather than asserting it. Our migration engineering then delivers the documented transition plan aligned to the NIST timeline. If your governance anchor is a management-system standard, the same inventory serves ISO 27001 A.8.24; if you are also in NIS2 scope, it serves the Article 21 cryptography measure. Incident reporting, the register of information on ICT providers, and the resilience-testing programme are organizational obligations that remain yours — we cover the cryptography, not the whole regulation.
Frequently asked questions
Who does DORA apply to, and from when?
DORA applies from 17 January 2025 to EU financial entities across roughly twenty categories — including credit institutions, insurers and reinsurers, investment firms, payment and e-money institutions, and crypto-asset service providers — and extends EU-level oversight to critical ICT third-party providers serving them. As a regulation it is directly applicable in every member state, with no national transposition step.
Does DORA require post-quantum cryptography?
Not by name, and it sets no PQC deadline of its own. What it requires — via Article 9 and the RTS in Commission Delegated Regulation (EU) 2024/1774 — is a policy on encryption and cryptographic controls, full key-lifecycle management, and provisions to update or replace cryptographic technology based on developments in cryptanalysis. Quantum computing is exactly such a development, so in practice the obligation inherits the NIST IR 8547 and CNSA 2.0 timelines.
What evidence does a cryptographic inventory give under DORA?
The ICT risk-management framework requires you to identify and protect your ICT assets and to keep the cryptographic-controls policy current against cryptanalysis. A maintained inventory of where quantum-vulnerable cryptography lives, ranked by exposure, is the concrete artifact that shows both: it demonstrates you know what you run, and it is the baseline any credible transition plan and resilience-testing scope is built on.
Can a tool or an audit make us DORA-compliant?
No. DORA compliance spans incident reporting, third-party oversight including the register of information, resilience testing, and governance — organizational obligations no tool discharges. What a cryptographic audit produces is evidence for the ICT risk-management pillar: the inventory, the quantum-risk assessment, and the transition plan that let you answer a supervisor's questions about cryptography with artifacts instead of assertions.
Work with us on DORA
Related reading
References
- EUR-Lex: Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA) — the regulation itself; applies from 17 January 2025.
- EUR-Lex: Commission Delegated Regulation (EU) 2024/1774 — the RTS on the ICT risk-management framework, including the encryption, cryptographic-controls, and key-management requirements.
- EIOPA: Digital Operational Resilience Act (DORA) overview — ESA-level supervisory context and implementing measures.