Financial Services

DORA Regulation Terminology for Confluence

Your ICT risk policy says “major incident” but your incident response plan says “significant disruption” — DORA defines these differently, and your competent authority can flag it on inspection. Manage DORA terms in Confluence with version control and proof of who approved each one.

Compliance Glossary terms table in Confluence with Regulation Packs import, approval statuses, lifecycle state, and version history
Compliance Glossary for Confluence: version-controlled terms with approval statuses, lifecycle tracking, and one-click Regulation Packs import.

What Is DORA?

Regulation (EU) 2022/2554 — the Digital Operational Resilience Act — establishes a comprehensive framework for ICT risk management across the EU financial sector. DORA has applied since January 17, 2025, meaning all in-scope financial entities must now comply.

DORA covers a broad range of financial entities:

Unlike a directive, DORA is a regulation — it applies directly in all EU member states without national transposition. The terminology it introduces is legally binding as written.

The DORA Terminology Challenge

DORA introduces specific ICT risk management terminology that finance teams, IT teams, and third-party providers should govern consistently. When your ICT risk management framework uses different language than your incident reporting procedures — or your third-party contracts use different terms than your register of information — that can become a compliance gap your competent authority may flag on inspection.

Common compliance gap: Your ICT business continuity plan refers to “critical service providers” but your register of information lists “ICT third-party service providers” without the “critical” designation. Under DORA, “critical ICT third-party service provider” is a specific legal category with oversight implications — mixing terms creates regulatory exposure.

Terms that consistently cause confusion under DORA:

DORA Terminology — Five Pillars

The DORA terminology landscape, organized by the five pillars of the regulation:

ICT Risk Management (8 terms)

ICT Risk
ICT System
ICT Asset
Digital Operational Resilience
ICT Risk Management Framework
Information Security Policy
ICT Business Continuity Plan
ICT Response and Recovery Plan

Incident Reporting (6 terms)

ICT-Related Incident
Major ICT-Related Incident
Significant Cyber Threat
Incident Classification
Incident Notification
Root Cause Analysis

Digital Operational Resilience Testing (5 terms)

Digital Operational Resilience Testing
Threat-Led Penetration Testing (TLPT)
Vulnerability Assessment
Scenario-Based Testing
Red Team Testing

Third-Party Risk Management (6 terms)

ICT Third-Party Service Provider
Critical ICT Third-Party Service Provider
Subcontracting (Art. 30(2)(a) / RTS 2024/1773)
Concentration Risk
Exit Strategy
Register of Information

Governance & Oversight (5 terms)

Management Body
ICT Risk Management Function
Lead Overseer
Joint Examination Team
Information Sharing Arrangement
DORA PillarTermsExamples
ICT Risk Management8ICT Risk, ICT System, ICT Asset, Digital Operational Resilience, Business Continuity Plan
Incident Reporting6ICT-Related Incident, Major ICT-Related Incident, Significant Cyber Threat, Root Cause Analysis
Resilience Testing5TLPT, Vulnerability Assessment, Scenario-Based Testing, Red Team Testing
Third-Party Risk6ICT Third-Party Service Provider, Critical Provider, Concentration Risk, Exit Strategy
Governance & Oversight5Management Body, Lead Overseer, Joint Examination Team, Information Sharing

Free DORA Terminology Packet

30 ICT risk, incident, testing, third-party, and governance terms. Submit your email and the packet is delivered to your inbox.

Who Does DORA Apply To?

DORA covers 20 categories of financial entities (Article 2(1)(a)-(t)). If your organization falls into any of these categories, you must comply with DORA’s ICT risk management, incident reporting, resilience testing, and third-party risk requirements:

Entity TypeDORA Relevance
Credit institutions (banks)Full scope — ICT risk management, incident reporting, TLPT, third-party oversight
Insurance & reinsurance undertakingsFull scope — all five DORA pillars apply
Investment firmsFull scope — proportionality applies based on size and complexity
Crypto-asset service providers (CASPs)Full scope — included in DORA via MiCA Art. 152 amendment (effective 30 December 2024)
Payment institutionsFull scope — including electronic money institutions
Credit rating agenciesFull scope — ICT risk management and incident reporting
Crowdfunding service providersFull scope — authorized under Regulation (EU) 2020/1503 (ECSPR); in DORA scope per Art. 2(1)(p)
Central securities depositoriesFull scope — critical market infrastructure
Trading venues & CCPsFull scope — systemic importance triggers enhanced testing
ICT third-party service providersOversight framework — critical providers subject to Lead Overseer regime

DORA-Ready Terminology Management

Stop managing ICT risk definitions in spreadsheets that don’t have audit trails. Install the DORA starter pack, review and approve your terms, then scan your documentation. Review our transparent app limitations for full details on what we do and don’t cover. Last verified: 2026-07-01.

Evaluate in Confluence Get Free Packet

Sources

Related Compliance Resources

Compliance for Confluence — approved terms, page scanning, and audit evidence for regulated teams in Confluence

NIS2 Directive Terminology — network and information security terms for essential and important entities

SOC 2 Terminology Management — 40 Trust Services Criteria terms for InfoSec & GRC teams

Compliance Guide — what auditors check and how we help, mapped to real regulatory standards

ALCOA+ Documentation Principles — how every data integrity principle maps to terminology management

Glossary App Comparison — how Confluence glossary apps compare for compliance, QA, GRC, legal, security, and regulatory teams