DORA compliance means meeting the requirements set out in the Digital Operational Resilience Act (DORA). This law (Regulation (EU) 2022/2554) requires financial organizations to manage information and communication technology (ICT) risk, report major ICT-related incidents, test their operational resilience, and manage risks from technology suppliers.
Digital Operational Resilience Act (DORA) entered into force on January 16, 2023, and has been applied since January 17, 2025. For financial entities within its scope, DORA compliance requires ongoing ICT risk management, incident reporting, resilience testing, and oversight of ICT third-party providers. Compliance continues after the initial implementation, with regular reviews, tests, reporting duties, and supplier assessments.
Understanding DORA and when it came into effect
Banks, insurers, investment firms, and other financial organizations depend on software, cloud platforms, data centers, telecommunications services, etc. If a payment system goes down (whether from a data-center outage or a ransomware attack), regulated services can stop working, and both customers and other financial institutions can be affected.
Before DORA, EU and national requirements for financial-sector ICT risk were inconsistent. For example, the regulatory reforms following the 2008 financial crisis focused mainly on financial resilience. Meanwhile, ICT risk received less attention and was addressed unevenly across financial sectors and Member States.
To address these gaps, the European Commission proposed DORA on September 24, 2020 as part of its Digital Finance Package. The regulation introduced common EU requirements for ICT risk management, incident reporting, resilience testing, and ICT third-party risk.
Who needs to comply with DORA?
Article 2 of DORA lists 20 categories of financial entities covered by the regulation. The scope is determined by an organization’s legal status and financial authorizations. The general type of services it offers does not decide this.
Covered financial entities include:
- Credit institutions, payment institutions, account information service providers, and electronic money institutions.
- Investment firms, alternative investment fund managers, and UCITS management companies.
- Central securities depositories, central counterparties, trading venues, trade repositories, data reporting service providers, credit rating agencies, administrators of critical benchmarks, and securitization repositories.
- Insurance and reinsurance undertakings, insurance and reinsurance intermediaries, ancillary insurance intermediaries, and institutions for occupational retirement provision.
- Crypto-asset service providers, issuers of asset-referenced tokens, and crowdfunding service providers.
ICT third-party service providers form a separate category under Article 2. Under DORA, financial entities carry most of the obligations for managing suppliers, including due diligence, contract requirements, monitoring, and exit planning. ICT providers designated as critical also are subject to direct oversight by the European Supervisory Authorities.

Article 2 contains several exclusions. These include certain sub-threshold alternative investment fund managers, insurance and reinsurance undertakings covered by the exclusion in Article 4 of Solvency II, and occupational pension institutions that operate schemes with no more than 15 members.
Insurance, reinsurance, and ancillary insurance intermediaries are also excluded if they qualify as microenterprises or small or medium-sized enterprises under DORA’s definitions. Other financial sectors do not receive the same general exclusion for small and medium-sized enterprises. An organization’s size can affect which proportionality rules, simplified requirements, or exemptions apply, but many small financial entities still fall within DORA’s scope.
How DORA applies outside the EU
DORA can affect organizations based outside the EU.
A European Commission Q&A published through EIOPA states that DORA applies to EU branches of third-country credit institutions, as well as to EU branches of third-country insurance and reinsurance undertakings.
An EU financial entity must also apply DORA across the same legal entity, including branches located outside the EU. A non-EU subsidiary incorporated as a separate legal entity needs its own scope assessment, because DORA determines scope at the legal-entity level.
If a non-EU technology provider serves an EU financial entity, it may be asked to accept contract terms covering incident support, audit rights, data access, subcontracting, service continuity, and exit assistance. These requirements come from the financial entity’s own obligations under DORA.
Direct EU oversight applies when the European Banking Authority (EBA) EIOPA and ESMA designate the provider as a critical ICT third-party service provider. A designated provider established outside the EU must set up an EU subsidiary within 12 months of its designation.
The 5 pillars of DORA
EU supervisory materials group DORA’s operational requirements into 5 main areas. The oversight of critical information and communications technology providers is covered separately.
1. ICT risk management
Each financial entity must operate a documented framework to identify, assess, control, and monitor ICT risk. This framework must cover systems, information assets, business functions, dependencies, protective controls, detection, incident response recovery, and lessons learned after incidents.
2. ICT incident management and reporting
Organizations must detect, record, classify, manage, and investigate ICT incidents. Major ICT-related incidents must be reported to the relevant financial authority within set deadlines.
Financial entities may also voluntarily notify competent authorities about a significant cyber threat DORA uses the legal term for a threat that could affect the organization, its customers, or the financial sector.
3. Digital operational resilience testing
Covered entities must maintain a risk-based testing program for their ICT systems and controls. Tests may include vulnerability assessments, network security assessments, scenario-based tests, end-to-end tests, and penetration tests.
Selected financial entities must also conduct threat-led penetration testing (TLPT) under the criteria and methods specified in Commission Delegated Regulation (EU) 2025/1190
4. ICT third-party risk management
Financial entities must assess technology suppliers before entering contracts and monitor them throughout the relationship. They must also maintain records of ICT arrangements, include required contract clauses, assess concentration risk, and prepare exit strategies for ICT services supporting critical or important functions.
5. Information and intelligence sharing
DORA allows financial entities to join trusted arrangements for exchanging cyber-threat information and intelligence. Participation is voluntary and must protect confidentiality, personal data, and sensitive business information.
Alongside these 5 areas, the EBA, EIOPA, and ESMA oversee ICT providers designated as critical. Their powers include requesting information, conducting investigations and inspections, issuing recommendations, and imposing penalty payments when a provider fails to cooperate.
Key DORA compliance requirements
Each of the 5 areas comes with specific duties. A covered organization must:
- Make the management body responsible for the ICT risk management framework. Its members must maintain enough knowledge to understand ICT risk and receive relevant training. Using a cloud platform or managed service provider does not transfer this responsibility.
- Maintain a documented ICT risk management framework covering identification, protection, detection, response, recovery, backup, crisis communication, and post-incident review.
- Review the framework at least once a year. Microenterprises may conduct the review periodically instead of annually.
- Maintain current inventories of ICT-supported business functions including functions classified as critical or important, and the assets and dependencies that support them.
- Operate and test ICT business continuity, backup, restoration, and recovery procedures.
- Maintain an incident management process that detects, classifies, escalates, reports, and reviews ICT incidents.
- Inform clients immediately when a major ICT-related incident affects their financial interests.
- Conduct supplier due diligence before signing ICT contracts and continue monitoring providers after the contract begins.
- Maintain the Register of Information covering contractual arrangements for ICT services supplied by ICT third-party service providers.
- Use the templates set out in Commission Implementing Regulation (EU) 2024/2956 for the Register of Information.
- Include required contract terms covering service descriptions, service levels, data and service locations, data recovery, incident assistance, audit and access rights, subcontracting, termination, and exit support.
- Assess concentration risk and maintain exit strategies for ICT services supporting critical or important functions.
- Test ICT systems and applications supporting critical or important functions at least annually, except where a microenterprise exemption applies.
- Conduct TLPT when selected by the competent authority, normally at least once every 3 years unless the authority sets a different frequency.
The DORA regulation, together with the delegated and implementing acts on ESMA’s DORA policy page define these requirements.
DORA deadlines and timeline
DORA was established through a defined legislative process and includes compliance duties that recur over time.
Date | DORA milestone |
|---|---|
September 24, 2020 | The European Commission proposed DORA within the Digital Finance Package. |
December 14, 2022 | Regulation (EU) 2022/2554 was signed by the presidents of the European Parliament and the Council. |
December 27, 2022 | |
January 16, 2023 | DORA entered into force. |
January 17, 2025 | DORA became applicable. |
November 18, 2025 | |
July 14, 2026 | Austria’s Financial Market Authority announced a legally final €42,000 DORA sanction against Western Union International Bank for late incident reports. |
Compliance also includes duties that repeat on a regular basis:
- Review the ICT risk management framework at least annually, or periodically for microenterprises.
- Test systems and applications supporting critical or important functions at least annually, except where a microenterprise exemption applies.
- Conduct TLPT at least every 3 years when selected, subject to adjustment by the competent authority.
- Keep the Register of Information current.
- Review ICT contracts, supplier dependencies, and exit strategies when services or risks change.
- Meet incident-reporting deadlines whenever an incident is classified as major.
DORA vs. GDPR
DORA addresses the operational resilience of financial services and ICT systems. The General Data Protection Regulation (GDPR) protects personal data and the rights of individuals. The same event can trigger duties under both laws.
Area | DORA | GDPR |
|---|---|---|
Main purpose | Operational resilience of financial services and ICT systems | Protection of personal data and privacy rights |
Main scope | Listed financial entities and relevant ICT providers | Any organization that processes personal data |
Report trigger | A major ICT-related incident meeting DORA thresholds | A personal data breach with risk to individuals |
Personal data needed? | No | Yes |
Main authority | Financial-sector competent authority | Data protection authority |
Initial deadline | 4 hours after major classification, generally within 24 hours of awareness | Within 72 hours of awareness |
A service outage may require a DORA report even when no personal data is affected. A personal data disclosure may require a GDPR notification without meeting DORA’s major-incident thresholds.
When an event meets both tests, the organization may need to notify its financial supervisor and its data protection authority through separate processes. European Commission guidance on personal data breaches explains the GDPR notification test and deadline. DORA leaves GDPR breach duties in place.
DORA vs. NIS2
DORA is a regulation that applies directly in EU Member States. The NIS2 Directive requires implementation through national law and covers essential and important entities across 18 sectors.
Area | DORA | NIS2 |
|---|---|---|
Legal form | Regulation, applies directly | Directive, needs national law |
Scope | Financial entities and their ICT providers | Essential and important entities across 18 sectors |
Role for finance | Sector-specific law (lex specialis) | General baseline |
Incident timeline | 4-hour classification, 24-hour awareness limit, 72-hour intermediate, 1-month final | 24-hour early warning, 72-hour notification, 1-month final |
For financial entities covered by both laws, DORA is treated as a sector-specific Union legal act under Article 4 of NIS2. European Commission guidance on the relationship between DORA and NIS2 states that DORA’s requirements apply to ICT risk management, ICT incident management and reporting, operational resilience testing, information sharing, and ICT third-party risk for those financial entities.
NIS2 can still apply separately to:
- A non-financial subsidiary that falls within a NIS2 sector.
- A cloud, data-center, managed service, or other ICT provider that qualifies under NIS2 in its own right.
- National cybersecurity strategies, crisis-management structures, and cooperation between authorities.
The European Commission’s NIS2 guidance confirms the 24-hour early warning, 72-hour incident notification, and 1-month final report structure.
How to prepare for DORA compliance
The following steps can help an organization within scope build or assess its DORA program:
- Confirm the scope for each legal entity based on authorization type and the relevant Article 2 category.
- Document any exclusion and the legal provision that supports it.
- Give the management body documented responsibility for the ICT risk management framework.
- Map critical or important functions and their dependencies, including applications, infrastructure, data, suppliers, subcontractors, and recovery requirements.
- Assess gaps against the DORA regulation and the applicable delegated and implementing acts.
- Create an incident decision process that records the time of awareness, classification criteria, classification decision, and reporting deadlines.
- Test whether the organization can prepare an initial notification within 4 hours after classifying an incident as major.
- Review supplier records and contracts for missing DORA terms.
- Complete and validate the Register of Information against procurement, finance, architecture, security, and contract records.
- Set a resilience-testing schedule based on system and business-function risk.
- Test backups, restoration, crisis communications, supplier outages, and exit strategies.
- Keep evidence such as management decisions, risk assessments, incident logs, test results, contract reviews, remediation records, and audit reports ready for supervision.

Conclusion
DORA requires covered financial entities to run an ongoing program for ICT risk management, major-incident reporting, resilience testing, and supplier-risk management. Its scope covers 20 categories of financial entities.
ICT providers may also face DORA requirements through customer contracts. Providers designated as critical are subject to direct EU oversight. DORA can also affect third-country branches, non-EU branches of EU financial entities, and non-EU providers serving the EU financial sector.
The requirements have applied since January 17, 2025. Financial entities remain responsible for compliance when they depend on cloud platforms, managed service providers, software vendors, or other outside technology providers.
FAQ
Does DORA apply to organizations outside the EU?
Yes, in several cases. EU branches of third-country banks and insurers are covered. An EU financial entity must apply DORA across its non-EU branches. A non-EU technology provider serving an EU financial entity faces DORA-related contract and incident duties, and direct EU oversight if designated as critical.
What types of ICT incidents must be reported?
Only major ICT-related incidents. An incident is major when it affects a critical or important function and meets DORA’s materiality thresholds, such as large client impact, downtime over 2 hours, spread across 2 or more EU countries, or losses over €100,000. Routine outages and failed logins do not qualify.
What happens if you fail to comply with DORA?
Each EU country sets penalties that must be effective, proportionate, and dissuasive, so amounts vary by country and sector. Authorities can investigate, inspect, order corrective measures, publish sanctions, and fine responsible individuals. In July 2026, Austria’s FMA fined a bank €42,000 for repeated late incident reports.