DORA compliance — operational resilience that survives a regulator inspection.
ICT risk management, operational resilience testing, and third-party oversight for EU financial entities and their critical ICT providers under the Digital Operational Resilience Act. Article 5 puts ultimate responsibility on the management body — personally.
Overview
Five pillars, written for the financial sector.
DORA — the Digital Operational Resilience Act, Regulation (EU) 2022/2554 — has been in force since January 2025. It is not a single obligation but a framework of five interconnected requirements designed to ensure every EU financial entity can withstand, respond to, and recover from ICT disruptions.
DORA demands a significantly higher level of documentation, testing rigour, and third-party oversight than previous EBA/EIOPA/ESMA guidelines — and supersedes them. For financial entities subject to DORA, NIS2 generally does not apply to financial services activities; DORA is the lex specialis for the sector.
Many DORA-covered entities deploy AI in core ICT operations — credit scoring, fraud detection, AML screening, customer-facing AI. These AI systems are typically Annex III high-risk under the EU AI Act, layering Article 26 deployer obligations on top of DORA ICT risk requirements. Our AI Governance & Security service applies the DORA sector overlay to AI estates, with ISO/IEC 42001 readiness built in.
Who DORA applies to
Three groups are in scope, with different oversight intensity.
EU financial entities (regardless of size)
Banks, insurers, investment firms, payment institutions, e-money issuers, crypto-asset providers, fund managers — payment institutions are explicitly covered regardless of size.
Critical ICT third-party providers
Designated by the European Supervisory Authorities and subject to direct EU oversight — significant cloud platforms, SaaS, payment processors, managed security providers.
Non-critical ICT providers serving financial entities
Indirect DORA requirements through the contractual obligations their financial entity clients must impose under Article 30 (audit rights, incident notification, business continuity).
Micro-enterprise exemptions
Micro-enterprises (fewer than 10 employees, under €2M turnover) may have member-state-defined exemptions from the more burdensome requirements such as TLPT.
The five pillars
What DORA requires in practice.
- 01Pillar 1
ICT risk management framework
A board-approved ICT risk management framework covering identification, protection, detection, response and recovery — with management responsibility throughout.
- 02Pillar 2
ICT incident classification & reporting
Mandatory reporting of major ICT incidents to the competent authority on a 4h / 72h / 1-month cadence, plus voluntary notification of significant cyber threats.
- 03Pillar 3
Digital operational resilience testing
Annual basic resilience testing for all entities; threat-led penetration testing (TLPT) every three years for significant entities, conducted by approved external test providers.
- 04Pillar 4
ICT third-party risk management
A complete Article 30 register of all ICT providers, mandatory contract provisions for critical providers (audit rights, exit plans, sub-processor controls), and ongoing oversight.
- 05Pillar 5
Information sharing
Voluntary participation in cyber threat intelligence and information-sharing arrangements between financial entities — reciprocal, structured exchange of indicators of compromise and threat intelligence.
Penalties & consequences
Daily-running fines and direct supervisory powers.
For financial entities, DORA penalties can reach 1% of average daily worldwide turnover per day of non-compliance following a binding supervisory instruction — for up to six months. For a financial entity with €50M annual turnover, a sustained 90-day non-compliance period can generate penalties exceeding €120,000.
Critical ICT third-party providers face up to €5M or 1% of average daily worldwide turnover — whichever is higher — and individual liability is possible for management. Non-financial penalties include binding instructions, public disclosure of violations, temporary prohibitions on offering services, and mandatory external audits at the entity's own cost.
Daily fine (financial entity)
1%
of average daily worldwide turnover, per day, up to six months.
Critical ICT provider fine
€5M / 1%
whichever is higher, of average daily worldwide turnover.
Major incident reporting
4h · 72h · 1mo
initial / intermediate / final — significantly faster than GDPR or NIS2.
Our approach
DORA compliance, scoped to your entity type.
What we deliver
- Scoping assessment — confirms which DORA obligations apply to your entity type and supervisory authority
- Five-pillar gap analysis with prioritised remediation plan
- ICT risk management framework formalisation, board-approved
- Incident classification framework with decision trees and pre-built notification templates for the 4h/72h/1mo cadence
- Article 30 third-party register build — full inventory with criticality classification and audit rights
- Critical ICT contract review against Article 30 mandatory provisions; remediation roadmap
- Resilience testing program design — annual basic testing schedule and TLPT readiness for significant entities
- Ongoing governance under our vCISO service
Typical timeline
Depends on baseline — existing EBA-aligned controls help.
3–6 months
From an EBA-aligned or ISO 27001 baseline
DORA-specific deltas: third-party register, Article 30 contract uplifts, 4-hour notification process, formalised ICT risk framework. ISO 27001 covers ~45–60% of DORA on its own.
9–12 months
End-to-end including TLPT readiness
Full implementation: framework, register, contracts, incident processes, basic testing, plus preparation for the first TLPT cycle (intelligence-led testing against live production systems).
Free tool
Where do you stand on DORA?
Run our free 8-minute readiness assessment and receive a personalised PDF report — your score, top gaps, and a 90-day roadmap. No slideware, no follow-up sequence.
Start the DORA assessmentFAQ