DORA

Mandatory · Financial

DORA compliance — operational resilience that survives a regulator inspection.

ICT risk management, operational resilience testing, and third-party oversight for EU financial entities and their critical ICT providers under the Digital Operational Resilience Act. Article 5 puts ultimate responsibility on the management body — personally.

Overview

Five pillars, written for the financial sector.

DORA — the Digital Operational Resilience Act, Regulation (EU) 2022/2554 — has been in force since January 2025. It is not a single obligation but a framework of five interconnected requirements designed to ensure every EU financial entity can withstand, respond to, and recover from ICT disruptions.

DORA demands a significantly higher level of documentation, testing rigour, and third-party oversight than previous EBA/EIOPA/ESMA guidelines — and supersedes them. For financial entities subject to DORA, NIS2 generally does not apply to financial services activities; DORA is the lex specialis for the sector.

Many DORA-covered entities deploy AI in core ICT operations — credit scoring, fraud detection, AML screening, customer-facing AI. These AI systems are typically Annex III high-risk under the EU AI Act, layering Article 26 deployer obligations on top of DORA ICT risk requirements. Our AI Governance & Security service applies the DORA sector overlay to AI estates, with ISO/IEC 42001 readiness built in.

Who DORA applies to

Three groups are in scope, with different oversight intensity.

  • EU financial entities (regardless of size)

    Banks, insurers, investment firms, payment institutions, e-money issuers, crypto-asset providers, fund managers — payment institutions are explicitly covered regardless of size.

  • Critical ICT third-party providers

    Designated by the European Supervisory Authorities and subject to direct EU oversight — significant cloud platforms, SaaS, payment processors, managed security providers.

  • Non-critical ICT providers serving financial entities

    Indirect DORA requirements through the contractual obligations their financial entity clients must impose under Article 30 (audit rights, incident notification, business continuity).

  • Micro-enterprise exemptions

    Micro-enterprises (fewer than 10 employees, under €2M turnover) may have member-state-defined exemptions from the more burdensome requirements such as TLPT.

The five pillars

What DORA requires in practice.

  1. 01Pillar 1

    ICT risk management framework

    A board-approved ICT risk management framework covering identification, protection, detection, response and recovery — with management responsibility throughout.

  2. 02Pillar 2

    ICT incident classification & reporting

    Mandatory reporting of major ICT incidents to the competent authority on a 4h / 72h / 1-month cadence, plus voluntary notification of significant cyber threats.

  3. 03Pillar 3

    Digital operational resilience testing

    Annual basic resilience testing for all entities; threat-led penetration testing (TLPT) every three years for significant entities, conducted by approved external test providers.

  4. 04Pillar 4

    ICT third-party risk management

    A complete Article 30 register of all ICT providers, mandatory contract provisions for critical providers (audit rights, exit plans, sub-processor controls), and ongoing oversight.

  5. 05Pillar 5

    Information sharing

    Voluntary participation in cyber threat intelligence and information-sharing arrangements between financial entities — reciprocal, structured exchange of indicators of compromise and threat intelligence.

Penalties & consequences

Daily-running fines and direct supervisory powers.

For financial entities, DORA penalties can reach 1% of average daily worldwide turnover per day of non-compliance following a binding supervisory instruction — for up to six months. For a financial entity with €50M annual turnover, a sustained 90-day non-compliance period can generate penalties exceeding €120,000.

Critical ICT third-party providers face up to €5M or 1% of average daily worldwide turnover — whichever is higher — and individual liability is possible for management. Non-financial penalties include binding instructions, public disclosure of violations, temporary prohibitions on offering services, and mandatory external audits at the entity's own cost.

  • Daily fine (financial entity)

    1%

    of average daily worldwide turnover, per day, up to six months.

  • Critical ICT provider fine

    €5M / 1%

    whichever is higher, of average daily worldwide turnover.

  • Major incident reporting

    4h · 72h · 1mo

    initial / intermediate / final — significantly faster than GDPR or NIS2.

Our approach

DORA compliance, scoped to your entity type.

What we deliver

  • Scoping assessment — confirms which DORA obligations apply to your entity type and supervisory authority
  • Five-pillar gap analysis with prioritised remediation plan
  • ICT risk management framework formalisation, board-approved
  • Incident classification framework with decision trees and pre-built notification templates for the 4h/72h/1mo cadence
  • Article 30 third-party register build — full inventory with criticality classification and audit rights
  • Critical ICT contract review against Article 30 mandatory provisions; remediation roadmap
  • Resilience testing program design — annual basic testing schedule and TLPT readiness for significant entities
  • Ongoing governance under our vCISO service

Typical timeline

Depends on baseline — existing EBA-aligned controls help.

  1. 3–6 months

    From an EBA-aligned or ISO 27001 baseline

    DORA-specific deltas: third-party register, Article 30 contract uplifts, 4-hour notification process, formalised ICT risk framework. ISO 27001 covers ~45–60% of DORA on its own.

  2. 9–12 months

    End-to-end including TLPT readiness

    Full implementation: framework, register, contracts, incident processes, basic testing, plus preparation for the first TLPT cycle (intelligence-led testing against live production systems).

Free tool

Where do you stand on DORA?

Run our free 8-minute readiness assessment and receive a personalised PDF report — your score, top gaps, and a 90-day roadmap. No slideware, no follow-up sequence.

Start the DORA assessment

About 8 minutes · Personalized PDF · No spam

FAQ

Common questions.

Does DORA apply to our ICT suppliers even if they are not financial entities?
Yes — directly to critical providers (with EU-level oversight), and indirectly to non-critical providers through the contractual obligations their financial entity clients must impose. Non-critical providers must accept Article 30 provisions: audit rights, incident notification, business continuity commitments, exit plans.
We already comply with EBA ICT guidelines — are we DORA compliant?
No. EBA Guidelines are a strong starting point but DORA goes significantly beyond them in three areas: mandatory threat-led penetration testing (TLPT) for significant entities every three years, the Article 30 third-party register with mandatory contract provisions, and the specific 4h/72h/1mo incident reporting cadence with quantitative classification thresholds.
What's the difference between basic and advanced (TLPT) resilience testing?
Basic testing is annual for all entities — vulnerability assessments, gap analyses, scenario-based tests, network and physical security reviews. TLPT (threat-led penetration testing) is required every three years for significant entities, conducted by approved external test providers using real threat intelligence against live production systems. TLPT results are shared with authorities; critical findings must be remediated within defined timelines.
How does DORA's incident reporting differ from GDPR and NIS2?
DORA requires an initial notification within 4 hours of classifying an incident as major — significantly faster than GDPR's 72-hour breach notification and NIS2's 24-hour early warning. DORA's classification uses quantitative impact thresholds. A single incident may trigger all three frameworks simultaneously; we design integrated incident processes that satisfy each timeline.
Does DORA apply if we are a small payment institution?
Yes. Payment institutions are explicitly covered by DORA regardless of size. Some member states grant exemptions to micro-enterprises (under 10 employees, under €2M turnover) from the most burdensome requirements like TLPT, but the core ICT risk management, incident reporting, and Article 30 obligations apply.
How long does DORA compliance take to implement?
3–6 months from an EBA-aligned or ISO 27001 baseline (closing DORA-specific gaps); 9–12 months end-to-end including TLPT readiness. DORA has been in force since January 2025 and supervisory inspections are underway, so this is no longer a planning exercise — most engagements run on tight client-driven deadlines.