DORA
DORA (Digital Operational Resilience Act) is a European Union regulation establishing uniform requirements for digital operational resilience in the financial sector. The regulation imposes obligations regarding ICT risk management, incident reporting, and resilience testing.
What is DORA?
DORA Definition
DORA (Digital Operational Resilience Act) is Regulation (EU) 2022/2554 of the European Parliament and of the Council, establishing uniform requirements for digital operational resilience for financial sector entities. The regulation entered into force on January 16, 2023, with full application from January 17, 2025.
Purpose of DORA
DORA aims to:
- Harmonize ICT security requirements across the EU
- Strengthen financial sector resilience against cyber threats
- Unify approaches to ICT risk management
- Increase oversight of ICT service providers
- Improve ICT-related incident reporting
Who Does DORA Apply To?
Financial Entities
- Banks and credit institutions
- Investment firms
- Payment institutions
- Insurance companies
- Investment funds
- Exchanges and clearing houses
- Rating agencies
- Fintech and crypto-asset service providers
ICT Service Providers
- Cloud computing providers
- Data centers
- Software companies
- Managed Security Service Providers (MSSP)
Main Pillars of DORA
1. ICT Risk Management
- Comprehensive ICT risk management strategy and policy
- Identify, protect, detect, respond, and recover
- Management body responsibility for ICT security
- Regular reviews and updates
2. ICT Incident Reporting
- Incident classification according to DORA criteria
- Obligation to report major incidents to supervisory authorities
- Reporting deadlines: initial (24h), intermediate (72h), final (1 month)
- EU central reporting platform
3. Digital Resilience Testing
- Regular ICT security testing
- Threat-Led Penetration Testing (TLPT) for significant entities
- Scenario testing and crisis exercises
- Independent validation of results
4. Third-Party Risk Management
- ICT provider due diligence
- DORA-compliant contractual clauses
- Provider monitoring and auditing
- Exit strategies and contingency plans
5. Threat Information Sharing
- Cyber threat information sharing mechanisms
- Collaboration between financial entities
- Participation in sectoral initiatives (ISAC)
Key DORA Requirements
For Management Bodies
- Direct responsibility for ICT risk management
- Approval of security policies and strategies
- Regular training and knowledge updates
- Oversight of resilience program implementation
For Organizations
- Dedicated ICT risk management function
- Process and procedure documentation
- Business continuity testing (BCP/DR)
- ICT asset and supplier inventory
For ICT Providers
- Meeting security requirements
- Client audit rights
- Incident reporting
- Continuity plans and exit strategy
Threat-Led Penetration Testing (TLPT)
DORA introduces TLPT requirements for significant entities:
- Tests based on realistic threat scenarios
- Conducted by certified testers
- TIBER-EU framework as standard
- Frequency: at least once every 3 years
- Scope: critical functions and systems
Sanctions for Non-Compliance
Member States determine sanctions, which may include:
- Administrative penalties
- Public warnings
- Orders to cease practices
- License revocation
Implementation Timeline
| Date | Event |
|---|---|
| 16.01.2023 | DORA entry into force |
| 17.01.2024 | RTS and ITS (delegated acts) |
| 17.01.2025 | Full DORA application |
| 17.01.2025 | First TLPT deadline |
How to Prepare for DORA?
Step 1: Gap Analysis
- Compare current practices with DORA requirements
- Identify areas requiring improvement
- Prioritize actions
Step 2: Update Risk Management Framework
- Review ICT policies and procedures
- Adjust organizational structure
- Strengthen supplier management
Step 3: Testing Program
- Implement regular security testing
- Prepare for TLPT
- Document results and remediation actions
Step 4: Incident Reporting
- Classification and reporting processes
- Integration with monitoring systems
- Team training
DORA and Other Regulations
DORA complements and is consistent with:
- NIS2 - Network and Information Security Directive
- GDPR - personal data protection
- PSD2 - payment services
- MiCA - Markets in Crypto-Assets
DORA is a groundbreaking regulation that raises the bar for cybersecurity in the EU financial sector, requiring a comprehensive approach to digital resilience.
Explore our services
Frequently asked questions
+ What is DORA in simple terms?
DORA (Digital Operational Resilience Act) is the EU regulation (Regulation 2022/2554) that requires every financial entity in the European Union to demonstrate digital operational resilience — the ability to operate, recover from and report on ICT (information and communication technology) incidents. It applies from 17 January 2025 to ~22,000 entities including banks, insurers, investment firms, crypto-asset providers, payment institutions, and the third-party ICT providers that serve them. DORA harmonises previously fragmented rules across EU countries and adds direct oversight of critical ICT third-party providers (CTPPs) by European supervisory authorities.
+ Who must comply with DORA?
DORA applies to virtually every regulated financial entity in the EU and the third parties they rely on: banks, building societies, payment institutions, e-money institutions, investment firms, crypto-asset service providers (under MiCA), insurance and reinsurance companies, insurance intermediaries, fund managers (UCITS, AIFM), pension funds, trading venues, central counterparties, central securities depositories, credit rating agencies, crowdfunding platforms, and account information service providers. Critical ICT third-party providers (CTPPs) — typically large cloud providers and SaaS vendors serving the financial sector — fall under direct supervision by the ESAs (European Banking Authority, ESMA, EIOPA).
+ What are DORA audit firms and what do they do?
DORA audit firms are specialised consultancies that assess a financial entity's compliance with the regulation. Two main scopes: (1) DORA readiness audit — gap analysis against the five DORA pillars, recommended remediation roadmap, deliverables for the board and supervisors, (2) DORA compliance audit — formal independent verification, often required for ongoing regulatory reporting. Tier-1 firms include Big Four (KPMG, PwC, EY, Deloitte) for large banks, mid-tier (BDO, Grant Thornton, Mazars) for mid-size institutions, and specialist cybersecurity firms (incl. nFlo) for technical pillars (TLPT, ICT risk management, incident response). Cost: €40K-300K depending on entity size and scope, plus annual surveillance reviews.
+ What are the 5 pillars of DORA?
DORA structures requirements into five pillars: (1) ICT Risk Management — governance, risk framework, asset inventory, vulnerability management, security architecture (Articles 5-15), (2) ICT Incident Management — classification, response, three-stage reporting (initial 4-72h, intermediate weekly, final 1 month) to competent authority (Articles 17-23), (3) Digital Operational Resilience Testing — annual technical tests, plus Threat-Led Penetration Testing (TLPT) every 3 years for significant entities (Articles 24-27), (4) ICT Third-Party Risk — register of all ICT contracts, due diligence, exit plans, register reporting to authorities (Articles 28-44), (5) Information Sharing — voluntary participation in cyber threat intelligence networks (Article 45).
+ What are DORA deadlines and penalties?
Deadlines: DORA entered into force on 16 January 2023 with full application from **17 January 2025**. Initial register-of-information reporting was due 30 April 2025. Threat-Led Penetration Testing (TLPT) cycles begin in 2026 for significant entities. Penalties: up to **1% of daily turnover** for each day of non-compliance (per Article 65), with caps depending on entity size. National competent authorities can also impose periodic penalty payments. The European Supervisory Authorities can directly fine Critical ICT Third-Party Providers up to 1% of average daily worldwide turnover. Reputational damage and customer/partner loss often exceed direct fines.
+ DORA vs NIS2 — what is the difference?
Both regulate cybersecurity and operational resilience but for different sectors with different focus: NIS2 — applies horizontally across sectors (energy, transport, health, water, digital infrastructure, public administration) with general cybersecurity requirements; DORA — applies vertically only to the financial sector but with much deeper requirements specific to ICT operational resilience, including TLPT and direct CTPP supervision. Where they overlap, **DORA takes precedence** for financial entities (lex specialis). A bank classified as essential under NIS2 follows DORA for its ICT requirements. Multinational financial groups need to map both regimes plus equivalents in non-EU jurisdictions (UK PRA, Swiss FINMA, US OCC).
+ How to prepare for a DORA audit?
Six-step preparation, typically 6-9 months: (1) Gap analysis against the five DORA pillars + register of information requirements (4-6 weeks), (2) Roadmap with prioritised remediation aligned with the entity's classification (microenterprise vs significant entity), (3) Document everything — DORA is heavily documentation-driven (ICT policies, risk framework, incident response plan, BC/DR plans, third-party register), (4) Tabletop exercises and TLPT preparation (for significant entities), (5) Vendor and third-party register completion — usually the longest task (3-6 months), (6) Internal audit dry-run before the external audit. Common pitfalls: incomplete vendor register, missing exit plans, weak TLPT scope, untested incident classification.