Skip to main content

What is DORA compliance?

DORA compliance refers to adhering to the EU’s Digital Operational Resilience Act (Regulation (EU) 2022/2554), a regulatory framework that requires organizations to detect and report cyber incidents, test their digital resilience, and monitor third-party technology providers. DORA entered into force in January 2023 and has applied since January 17, 2025 It’s now a key part of the EU’s approach to making sure financial organizations are prepared to defend against cyber threats.

Who must comply with DORA?

DORA applies to around 20 types of financial entities across the European Union, with some of the most notable being:

  • Banks and credit institutions DORA applies to banks because they rely heavily on digital systems for essential services such as payments, online banking, and transaction processing.
  • Insurance and reinsurance companies These organizations use technology to manage policies, process claims, store customer data, and handle other essential operations. That’s why DORA requires them to respond to and recover from disruptions related to Information and Communications Technology (ICT).
  • Investment firms DORA helps ensure that the systems investment firms use for trading, managing portfolios, processing transactions, and communicating with clients remain secure and available.
  • Crypto-asset service providers (CASPs) DORA also covers certain crypto-asset firms as they increasingly rely on digital platforms to process transactions and manage customer assets.

Apart from these organizations, DORA also applies to ICT third-party providers that support financial institutions with essential ICT services, such as cloud computing, data analytics, software, and other technology infrastructure.

However, only providers formally designated as critical ICT third-party providers by the European Supervisory Authorities (ESAs) under Article 31 are subject to the EU’s direct Oversight Framework. Other ICT providers are affected indirectly through the contractual requirements that financial entities must impose on their ICT third-party service providers under Article 30.

The 5 pillars of DORA compliance

Visual depicting 5 pillars of DORA compliance

DORA sets clear expectations across 5 key areas, though the exact requirements scale with an organization’s size, risk profile, and activities. Here’s what those areas are:

ICT risk management

This is the foundation that everything else builds on. It involves identifying the technology and systems an organization relies on, assessing the associated risks, and developing a clear plan for what to do when something goes wrong.

That response plan, however, cannot simply be something people know informally or a note buried in an outdated policy document. Instead, organizations need an official ICT risk management framework that is reviewed at least once a year. It should include a list of all critical systems, make clear who is responsible for them, and be updated whenever there is a significant change in the IT environment, such as when a new vendor is brought on.

ICT incident reporting and classification

When an incident occurs, DORA requires financial organizations to classify it by its severity based on factors such as who was affected, how long the disruption lasted, and how critical the affected service is. Incidents that meet the threshold for “major” must be reported to regulators.

The DORA reporting requirements also set specific timelines for notifying regulators about major ICT-related incidents. Financial entities must submit an initial notification within 24 hours of becoming aware of an incident and within four hours of classifying it as major. This is followed by more detailed intermediate and final reports as the situation develops.

Digital operational resilience testing

A resilience plan is only useful if it’s actually been tested. That’s why organizations need to regularly assess the effectiveness of their defenses under DORA. Assessments may include everything from basic vulnerability scans to advanced simulations designed to test how well security measures perform under pressure

Certain financial entities may also need to carry out threat-led penetration testing (TLPT) on a regular basis These tests help identify and address weaknesses in a controlled environment before they can cause problems during a real incident. Under DORA, competent authorities decide which entities must perform TLPT, based on factors like their impact, financial stability concerns, and ICT risk profile.

ICT third-party risk management

Most financial organizations rely on external providers for cloud services, software, and IT support, which is why DORA treats the risks from these providers as part of the organization’s overall ICT risk. As a result, financial institutions need to keep track of their ICT vendors and clearly document the services each one provides

Contracts with these providers also need to include specific terms, such as audit rights and clear exit options. Companies should also assess the potential impact of a key provider going down and how much it could affect their operations.

Information and intelligence sharing

The final part asks financial entities to share information about cyber threats and incidents with each other While this isn’t mandatory, it can certainly help financial institutions identify and respond to threats faster by learning from experiences across the sector.

Though it’s less formal than the other 4, this part reflects one of DORA’s main ideas, which is that the financial sector is more resilient when organizations work together to respond to threats rather than tackle them on their own.

What are DORA’s regulatory technical standards (RTS)?

DORA is a high-level regulation, so it doesn’t cover every technical detail itself. That’s why regulatory technical standards (RTS) play an important role. These detailed rules are drafted by the European Supervisory Authorities (ESAs) and adopted by the European Commission as delegated regulations. They explain how financial entities should meet requirements such as ICT risk management, incident classification, and third-party contract terms.

DORA compliance checklist

Use this checklist to get a clearer view of where your organization stands against the DORA requirements. Go through each row, mark what’s already in place, and identify gaps that need to be addressed.

Checklist item

What to check

In place?

Scope assessment and gap analysis

Confirm whether your organization falls under DORA, identify your entity category, and assess gaps across all 5 pillars.

Yes / No

Governance & board oversight

Verify that senior management has approved the ICT risk framework and that accountability clearly sits with the board, not just IT.

Yes / No

ICT asset inventory

Maintain an up-to-date inventory of all ICT systems and their dependencies, so you know which ones support critical functions.

Yes / No

Risk-management framework

Confirm that your ICT risk framework is in place, covers the full risk lifecycle, and is reviewed at least annually.

Yes / No

Incident response & reporting process

Verify that you have a tested process for detecting, classifying, and escalating ICT incidents, with clear timelines for notifying regulators.

Yes / No

Resilience testing schedule

Review your testing calendar to cover vulnerability scans, scenario tests, and, where needed, threat-led penetration testing.

Yes / No

Register of information & contract review

Keep your ICT vendor register up to date and make sure contracts include key requirements, like audit rights and exit strategies.

Yes / No

Continuous monitoring

Confirm there’s an ongoing process to monitor ICT risk, vendor performance, and emerging threats.

Yes / No

DORA compliance timeline and key deadlines

As we mentioned at the beginning, the EU’s Digital Operational Resilience Act has been in force since January 17, 2025 which means it now applies to financial organizations across the EU that fall within its scope.

There are also a few important deadlines for financial entities to keep in mind. Organizations need to review their ICT risk management framework at least once a year and regularly test their ICT systems and applications. Certain organizations must undergo threat-led penetration testing (TLPT) at least every 3 years, though authorities may change this frequency.

When a major ICT incident occurs, there are also tight deadlines for notifying regulators The initial notification is due within 4 hours of classifying the incident as major, and no later than 24 hours after becoming aware of it, whichever comes first You then have 72 hours to submit an intermediate report, followed by a final report within one month.

Penalties for non-compliance

Financial entities that don’t meet DORA requirements can face significant fines, but exact penalties vary from one EU member state to another Some allow fines of up to 10% of annual turnover or €10 million while others have different limits. In some countries, individuals responsible for a breach can also be subject to personal fines.

Critical ICT third-party (CTPPS) providers fall under a separate enforcement framework. The Lead Overseer, a regulator responsible for directly supervising each critical provider, can impose periodic penalty payments of up to 1% of the provider’s average daily worldwide turnover for each day of non-compliance, for up to 6months.