Your ICT risk policy says “major incident” but your incident response plan says “significant disruption” — DORA defines these differently, and your competent authority can flag it on inspection. Manage DORA terms in Confluence with version control and proof of who approved each one.
Regulation (EU) 2022/2554 — the Digital Operational Resilience Act — establishes a comprehensive framework for ICT risk management across the EU financial sector. DORA has applied since January 17, 2025, meaning all in-scope financial entities must now comply.
DORA covers a broad range of financial entities:
Unlike a directive, DORA is a regulation — it applies directly in all EU member states without national transposition. The terminology it introduces is legally binding as written.
DORA introduces specific ICT risk management terminology that finance teams, IT teams, and third-party providers should govern consistently. When your ICT risk management framework uses different language than your incident reporting procedures — or your third-party contracts use different terms than your register of information — that can become a compliance gap your competent authority may flag on inspection.
Terms that consistently cause confusion under DORA:
The DORA terminology landscape, organized by the five pillars of the regulation:
| DORA Pillar | Terms | Examples |
|---|---|---|
| ICT Risk Management | 8 | ICT Risk, ICT System, ICT Asset, Digital Operational Resilience, Business Continuity Plan |
| Incident Reporting | 6 | ICT-Related Incident, Major ICT-Related Incident, Significant Cyber Threat, Root Cause Analysis |
| Resilience Testing | 5 | TLPT, Vulnerability Assessment, Scenario-Based Testing, Red Team Testing |
| Third-Party Risk | 6 | ICT Third-Party Service Provider, Critical Provider, Concentration Risk, Exit Strategy |
| Governance & Oversight | 5 | Management Body, Lead Overseer, Joint Examination Team, Information Sharing |
30 ICT risk, incident, testing, third-party, and governance terms. Submit your email and the packet is delivered to your inbox.
DORA covers 20 categories of financial entities (Article 2(1)(a)-(t)). If your organization falls into any of these categories, you must comply with DORA’s ICT risk management, incident reporting, resilience testing, and third-party risk requirements:
| Entity Type | DORA Relevance |
|---|---|
| Credit institutions (banks) | Full scope — ICT risk management, incident reporting, TLPT, third-party oversight |
| Insurance & reinsurance undertakings | Full scope — all five DORA pillars apply |
| Investment firms | Full scope — proportionality applies based on size and complexity |
| Crypto-asset service providers (CASPs) | Full scope — included in DORA via MiCA Art. 152 amendment (effective 30 December 2024) |
| Payment institutions | Full scope — including electronic money institutions |
| Credit rating agencies | Full scope — ICT risk management and incident reporting |
| Crowdfunding service providers | Full scope — authorized under Regulation (EU) 2020/1503 (ECSPR); in DORA scope per Art. 2(1)(p) |
| Central securities depositories | Full scope — critical market infrastructure |
| Trading venues & CCPs | Full scope — systemic importance triggers enhanced testing |
| ICT third-party service providers | Oversight framework — critical providers subject to Lead Overseer regime |
Stop managing ICT risk definitions in spreadsheets that don’t have audit trails. Install the DORA starter pack, review and approve your terms, then scan your documentation. Review our transparent app limitations for full details on what we do and don’t cover. Last verified: 2026-07-01.
Evaluate in Confluence Get Free PacketCompliance for Confluence — approved terms, page scanning, and audit evidence for regulated teams in Confluence
NIS2 Directive Terminology — network and information security terms for essential and important entities
SOC 2 Terminology Management — 40 Trust Services Criteria terms for InfoSec & GRC teams
Compliance Guide — what auditors check and how we help, mapped to real regulatory standards
ALCOA+ Documentation Principles — how every data integrity principle maps to terminology management
Glossary App Comparison — how Confluence glossary apps compare for compliance, QA, GRC, legal, security, and regulatory teams