# DORA

EU rules on digital operational resilience in the financial sector

> DORA has applied since January 2025 and covers most firms supervised by the Swedish financial supervisory authority. This page covers what the regulation governs and how SBOM relates to the requirements.

Updated: 5 October 2026  
URL: https://sbom.se/en/regulations/dora

DORA (Digital Operational Resilience Act) is Regulation (EU) 2022/2554 on digital operational resilience in the financial sector. It has applied since January 2025 and applies directly in all member states. In Sweden it covers most firms supervised by Finansinspektionen, the financial supervisory authority.

## What DORA governs

The regulation has four main areas:

* **ICT risk management.** Firms must manage risks in information and communication technology (ICT).
* **Incident reporting.** ICT-related incidents must be reported.
* **Testing.** Digital operational resilience must be tested.
* **Third-party risk.** Risks at ICT suppliers must be managed.

Technical standards from the EU specify the requirements in more detail.

## DORA and SBOM

DORA does not mention SBOM. An SBOM is still used for several of the requirements:

* **Risk management.** To manage ICT risk, a firm needs to know which systems and components it has. An SBOM describes what a piece of software consists of, down to individual libraries.
* **Third-party risk.** An SBOM from the supplier shows what purchased software contains and makes it possible to monitor it against known vulnerabilities. SBOM requirements can be written into supplier contracts.
* **Incidents.** When a vulnerability in a component is being exploited, the SBOMs show which systems are affected.

## Suppliers to the financial sector

DORA also affects companies that are not supervised themselves. A software supplier to a bank or an insurer can expect questions about what the product contains, which vulnerabilities affect it and how long it is supported. [SBOM in software supply chains](https://sbom.se/en/guides/supply-chains) describes how SBOMs are shared between supplier and customer.

Suppliers that manufacture products with digital elements are also covered by the [Cyber Resilience Act (CRA)](https://sbom.se/en/cra/overview).

## References

- [Finansinspektionen: Om Dora](https://www.fi.se/sv/bank/it-risker-dora/om-dora/): The Swedish financial supervisory authority's overview of DORA (in Swedish).
- [EIOPA: Digital Operational Resilience Act (DORA)](https://www.eiopa.europa.eu/digital-operational-resilience-act-dora_en): The European Insurance and Occupational Pensions Authority's overview of DORA.
