pqcstatus
Regulation & guidance

DORA — RTS on ICT risk management (Delegated Regulation (EU) 2024/1774): cryptography requirements and deadlines

EU regulation

Requires an encryption policy that can change cryptographic technology as cryptanalysis evolves, plus full key and certificate lifecycle management.

At a glance

TypeEU regulation
JurisdictionEU
Who it applies toEU financial entities (banks, insurers, investment firms, payment institutions...) and, indirectly, their critical ICT providers.

Cryptography requirements

ReferenceRequirementWhat a scan and inventory can evidence
Art. 6Encryption and cryptographic controls policy, including provisions for updating or changing cryptographic technology on the basis of developments in cryptanalysis.
  • Cryptography policy
  • Cryptographic inventory
  • PQC migration plan
Art. 7Cryptographic key management over the whole lifecycle, and a register of certificates for ICT assets supporting critical or important functions.
  • Key management
  • Certificates

Sources

  1. Commission Delegated Regulation (EU) 2024/1774 — DORA RTS on ICT risk management · European Union

Catalog version 2026-09-28. Every position links to its primary source; draft documents are labelled as such.

Frequently Asked Questions

Who must comply with DORA — RTS on ICT risk management (Delegated Regulation (EU) 2024/1774)?

EU financial entities (banks, insurers, investment firms, payment institutions...) and, indirectly, their critical ICT providers.

What does DORA — RTS on ICT risk management (Delegated Regulation (EU) 2024/1774) require for cryptography?

Art. 6: Encryption and cryptographic controls policy, including provisions for updating or changing cryptographic technology on the basis of developments in cryptanalysis. Art. 7: Cryptographic key management over the whole lifecycle, and a register of certificates for ICT assets supporting critical or important functions.