As of January 17, 2025, financial institutions operating in the EU—including banks—are required to comply with DORA, short for the Digital Operational Resilience Act (Regulation (EU) 2022/2554) The phrase “DORA compliance for banks” refers to the measures banks take to comply with DORA by managing ICT risks and remaining operational during disruptions.
What exactly is DORA, and why does it apply to banks?
DORA is an EU regulation created to ensure that financial organizations, along with their technology providers, can manage IT-related risks. It requires them to test the resilience of their systems, report all major incidents, and monitor third-party ICT providers for potential vulnerabilities. The goal is to keep financial services running without interruption, even when serious cybersecurity issues arise.
Banks are particularly affected by DORA because so many of their services rely heavily on digital technologies. These systems must be properly protected against cyberattacks, as an incident could directly affect both banks and their customers. For example, it could disrupt payment processing, prevent customers from accessing online banking, or even expose sensitive financial data. That’s why DORA calls on banks to put the appropriate security measures in place and respond effectively when such incidents occur.
Does DORA apply to banks outside the EU?
Yes, DORA can also apply to banks outside the EU, but only when they have a presence or carry out activities in the EU For example, a non-EU bank that provides services to EU customers may fall within DORA’s scope.
Similarly, US or UK banks with branches or subsidiaries in the EU need to make sure those entities comply with DORA even if the parent company’s domestic operations are not subject to it. In practice, this means a US bank’s EU branch may need to meet DORA requirements even though the bank’s operations in the US do not.
What organizations, other than banks, does DORA apply to?
Banks are just one of many types of organizations that must comply with DORA. As set out in Article 2, the regulation applies to a broad range of financial entities and ICT third-party service providers. These include:
- Investment firms
- Insurance and reinsurance companies
- Payment institutions
- Electronic money institutions
- Investment funds and asset managers
- Crypto-asset service providers
- Credit rating agencies
- Trading venues and central securities depositories
- ICT third-party service providers
What banks must do to meet DORA requirements
DORA is built around 5 core pillars and banks and other financial institutions are expected to address all of them.

The first one, ICT risk management means banks must have a board-approved framework to identify critical systems such as payment processing and core banking platforms, understand their vulnerabilities, and prepare recovery plans in case something goes wrong.
Then there’s ICT incident reporting and classification which requires banks to detect IT-related incidents, assess their severity, and report major ones to regulators within strict timeframes. For example, banks must submit an initial notification within 4 hours of classifying an incident as major.
The next two pillars cover a bank’s ability to withstand disruptions and manage risks that come from outside the organization. Digital operational resilience testing as the name suggests, is about regularly testing the defenses of a bank’s systems It involves everything from vulnerability scans to more advanced, scenario-based assessments. Banks identified by their competent authority based on factors such as financial-sector impact, financial stability, and ICT risk must also carry out threat-led penetration testing (TLPT), which simulates real-world attacks on live systems.
The fourth one is referred to as ICT third-party risk management It requires banks to monitor external technology providers assess how much risk they are taking on through any single provider, and include audit and exit rights in their contracts. This helps ensure that these providers continue to meet the bank’s security and resilience expectations throughout the relationship, rather than only at the time the contract is signed.
The final pillar, information and intelligence sharing is more collaborative. While it’s not mandatory, DORA encourages financial institutions to share information about cyber threats and incidents with each other That way, when one organization identifies a new type of attack, others can learn from it and take steps to protect themselves before they face a similar threat.
Key DORA compliance deadlines for banks
As mentioned earlier, DORA entered into force in January 2023 and has been applicable since January 17, 2025 so all in-scope banks must now operate in line with its requirements.
When it comes to the other deadlines, it’s worth highlighting incident reporting, as the timelines here are quite strict. Banks must submit the initial notification within 4 hours of classifying an ICT-related incident as major and, in any event, no later than 24 hours after becoming aware of the incident They then need to deliver an intermediate report within 72 hours of the initial notification, followed by the final report within a month.
Banks must also review their ICT risk management framework at least once a year, with additional reviews required after major incidents or significant operational changes. On top of that, banks also need to test systems supporting critical or important functions at least once a year. Banks identified by their competent authority for TLPT must also carry out threat-led penetration testing at least every 3 years although the authority can adjust this frequency.
What happens when banks fail to comply with DORA
Rather than just a warning, non-compliance with DORA can carry serious financial consequences. Although the exact penalties vary across EU member states in some cases, banks may face fines of up to €10 million or 10% of their annual turnover Regulators may also require banks to take corrective action and, where national law allows, hold members of the management body or other individuals accountable for a breach.
Beyond the financial penalties, banks could be subject to increased regulatory scrutiny and additional requirements to address any identified issues. Authorities may also release details of imposed penalties to the public which can damage the bank’s reputation
How banks can prepare for DORA
Banks should start working toward compliance by carrying out an honest gap analysis against DORA’s 5 pillars. This means looking at their current approach to risk management, incident response, testing, and vendor oversight, and comparing it with what DORA actually requires. If you want to quickly check where you stand, this DORA compliance checklist provides a practical way to assess your situation
As for the tools that can help organizations become DORA compliant, there are a few key ones to consider: ICT risk and asset management platforms, incident detection and reporting systems, resilience and penetration testing tools, and third-party risk management solutions, among others.