← Back to the regulatory map
Act and regulation implementing an EU regulation Norway and the EU

The DORA Act and the DORA Regulations

Valid in Norway

Last peer-reviewed July 16, 2026

Brief overview

The DORA Act and the DORA Regulations entered into force on July 1, 2025. The act implements the EU regulation on digital operational resilience for the financial sector, the DORA Regulation, into Norwegian law. The regulations implement complementary technical rules.

DORA applies only to financial entities specified within the scope of the regulation, with explicit exemptions for certain types of enterprises and small businesses. The regulations set out detailed requirements for ICT risk management, management and reporting of major ICT incidents, digital operational resilience testing, and the monitoring of ICT third-party service providers.

The regulatory framework is not AI-specific. However, an AI service can still be an ICT service under DORA when it is provided digitally and used by a covered financial entity. If the service supports a critical or important function, this is of particular significance for risk assessments, contractual requirements, testing, incident management, and exit strategies.

The use of an external AI, cloud, or system provider does not transfer responsibility away from the financial entity. At the same time, regular ICT providers are not automatically subject to all DORA requirements directly. They are primarily affected through the financial entity's vendor management and contracts, unless the provider is designated as critical under DORA.

What regulates this

DORA regulates how financial entities must prevent, manage, and recover operations following ICT-related disruptions. The regulation consolidates requirements into five main areas: ICT risk management, incident management and reporting, digital operational resilience testing, ICT third-party risk management, and voluntary information sharing.

The DORA Act makes Regulation (EU) 2022/2554 applicable as Norwegian law with EEA adaptations. The DORA Regulations implement technical regulatory and implementation standards on, among other things, risk management, incident classification, reporting, information registers, subcontractors, and threat-led penetration testing.

The requirements must be applied proportionally based on the enterprise's size, risk profile, and operations. Nevertheless, the proportionality principle does not remove the absolute requirements that apply to the relevant type of enterprise.

Who is affected

Private sector

Why it has practical significance

Financial services rely heavily on digital systems and a limited number of key ICT third-party service providers. Operational disruptions, cyber attacks, data loss, or the failure of a provider can therefore impact customers, the market, and financial stability alike.

DORA places clear responsibility on the undertaking's management body and requires verifiable control of its own systems and the entire supply chain. The requirements also apply when the technology is delivered as a standardized cloud or AI service.

For AI-based solutions, it is particularly important to assess whether the service supports a critical or important function, what data and systems it has access to, which subcontractors are used, and how the enterprise can maintain or restore the service if the solution fails.

Key Requirements and Obligations

  • Determine whether the undertaking falls within the scope of DORA Article 2, and document the assessment of any exemptions or special rules.
  • The undertaking's governing body has overall responsibility for ICT risk and shall approve, monitor, and regularly review the ICT risk management framework.
  • The undertaking shall have a documented framework to identify, protect, detect, manage, recover from, and learn from ICT-related risks and incidents.
  • ICT systems, information values, data, critical functions, dependencies and suppliers must be identified and kept updated.
  • The undertaking shall have procedures to detect, manage, classify and report ICT-related incidents.
  • Serious ICT incidents must be reported to Finanstilsynet: an initial notification no later than four hours after classification and in any case no later than 24 hours after detection, the first status report no later than 72 hours after the initial notification, and the final report no later than one month after the latest status report.
  • The undertaking shall implement a risk-based program for testing digital operational resilience and follow up on identified vulnerabilities.
  • Enterprises designated by the supervisory authority shall conduct threat-led penetration testing in accordance with the specific TLPT rules.
  • ICT third-party risk must be included in the undertaking's overall ICT risk management; the undertaking retains responsibility even when services are provided by external or intra-group suppliers.
  • Before an ICT service agreement is entered into, the undertaking shall, among other things, assess risk, criticality, the supplier, concentration risk, and the possibility of an orderly exit.
  • ICT service agreements must include the contract provisions required by DORA, with additional requirements when the service supports a critical or important function.
  • The undertaking shall maintain and update an information register of contractual arrangements for the use of ICT services and make the register available or report it in accordance with regulatory requirements.

What the business may consider documenting

  • Conduct a precise scope analysis against DORA Article 2 and document which provisions and any simplified frameworks apply.
  • Map all ICT services and specifically assess whether AI, language, and cloud services are covered by the definition of an ICT service.
  • Classify which functions are critical or important, and document how loss or failure will impact customers, license requirements, and continuity.
  • Update the information registry when agreements, services, suppliers, or subcontractors change.
  • Review the ICT contracts against the requirements in DORA Article 30, including requirements for service levels, security, incident assistance, access and audit, regulatory cooperation, termination, and exit.
  • Assess the geographical location of data and processing, use of subcontractors, vendor concentration, and the possibility of moving or restoring the service.
  • Test preparedness, backup, recovery, and exit plans together with relevant vendors.
  • Establish an incident procedure that enables the classification of an incident and compliance with the four-hour, 24-hour, 72-hour, and one-month deadlines.
  • Ensure that the board of directors and relevant employees have sufficient knowledge and regular training on ICT risk and digital operational resilience.
  • Coordinate the DORA work with data privacy, AI regulations, and other financial regulatory requirements without merging different notification obligations or assessment themes.

Sources and Further Reading

The links point to external sources. Check the current text and status before using them in your own work.

The information is general information and not legal advice. The applicable requirements must be assessed based on the enterprise's sector, role, information, and specific use of technology.

Next step with ClearNord

Quality assure the language versions of the documentation

Do you have procedures, training materials, or supplier documentation in multiple languages? ClearNord can translate or quality-assure the language versions based on content approved by your subject matter experts. We agree on documents, languages, and deliveries in advance.

Get a quote for linguistic quality assurance