Skip to main content

DORA penalties for noncompliance and how to avoid them

What are DORA fines?

DORA fines refer to the administrative and financial penalties imposed for violations of the Digital Operational Resilience Act (Regulation (EU) 2022/2554)—an EU regulation that requires financial institutions and ICT service providers to effectively manage cyber threats Applicable since January 17, 2025 DORA aims to improve the operational resilience of organizations operating within the financial sector.

An explanatory infographic that explain what DORA fines are.

While the specific penalties differ across EU member states, in some cases, financial entities can be fined even up to €10 million or 10% of their annual turnover At the same time, critical ICT third-party providers may face penalties of up to 1% of their average daily worldwide turnover for each day of noncompliance.

Examples of DORA noncompliance fines

There’s no single EU-wide fine for being noncompliant with DORA. Article 50 simply requires each member state to have “effective, proportionate, and dissuasive” administrative penalties, but leaves the actual fine limits to national law This means enforcement can look quite different depending on where a given financial entity is regulated.

That national discretion results in significant gaps in maximum fines. A few examples illustrate the range:

  • Finland. Administrative fines capped at €100,000.
  • Czech Republic. Fines capped at around €2 million.
  • Germany. Fines of up to €5 million.
  • Netherlands. Fines of up to €5 million.
  • Norway*. Fines of up to NOK 50 million (roughly €4.3 million).
  • Ireland. Fines of up to €10 million.

As mentioned, the amounts above represent the maximum fines permitted by law, rather than the actual fines imposed, meaning that the penalties may be significantly lower.

Specific examples of fines are relatively scarce, as enforcement actions are not always publicly announced. One of the most recent publicly reported cases was in Austria, where the FMA imposed a €42,000 fine on Western Union International Bank GmbH on July 14, 2026, for repeated breaches of DORA’s incident-reporting obligations.

It’s also worth noting that Article 51 gives authorities the power to impose financial penalties alongside other measures, such as corrective action plans or, in more serious cases, restrictions on service provision.

On top of these fines, Article 52 allows, but doesn’t require EU member states to introduce criminal penalties for the most serious violations. In countries that have taken this approach, criminal liability applies to individuals involved Depending on the national rules, this can mean criminal fines or, in more serious cases, even prison sentences for those responsible for breaches.

*Norway is not an EU member state; it applies DORA through its incorporation into the EEA Agreement.

Which companies must comply with DORA?

DORA applies to a wide range of financial entities operating in the EU. Here are some of the most notable examples:

  • Banks and credit institutions
  • Payment institutions
  • Electronic money institutions
  • Investment firms
  • Crypto-asset service providers (CASPs)
  • Insurance and reinsurance companies
  • Insurance and reinsurance intermediaries
  • Asset managers and management companies
  • Central securities depositories (CSDs)
  • Central counterparties (CCPs)
  • Trading venues

Beyond financial organizations, DORA also introduces requirements for ICT third-party service providers that support the financial sector, with additional oversight applying to providers designated as critical

DORA fines vs. GDPR penalties

The two frameworks are built around fundamentally different penalty structures. GDPR sets a fixed, EU-wide ceiling fines of up to €20 million or 4% of a company’s total annual worldwide turnover for the most serious infringements, with a lower tier capped at €10 million or 2% for less severe breaches; the greater of the fixed amount or the percentage applies.

DORA, on the other hand, leaves the actual amounts to national law, meaning there is no single DORA-wide cap.

The two regulations also differ in scope and enforcement. GDPR applies globally to organizations processing the personal data of EU residents and is enforced by national data protection authorities.

In contrast, DORA applies specifically to financial entities and ICT third-party providers operating in the EU and is enforced by the EU’s financial regulators.

DORA penalties for critical ICT third-party providers

Critical third-party ICT providers are treated differently from financial entities under DORA. They’re overseen directly by the European Supervisory Authorities rather than individual national regulators. A Lead Overseer is appointed to supervise each critical provider and address compliance issues within the framework.

Article 35 states that a critical ICT provider that fails to comply with a measure imposed by the Lead Overseer can face periodic penalty payments of up to 1% of its average daily worldwide turnover for each day of continued noncompliance for up to 6 months.

The Lead Overseer can also take other measures, including recommending that financial entities terminate or refrain from entering into contracts with the particular provider

Individual and management liability

DORA does hold individuals accountable for noncompliance, not just the organization. Under Article 5 the management body is ultimately responsible for managing ICT risk, including approving and overseeing the ICT risk management framework. This means that when something goes wrong, regulators can examine whether specific board members or executives failed to meet their responsibilities

Those found responsible can face administrative fines separate from any penalties imposed on the firm itself with the applicable maximum varying depending on the member state. In Ireland, for example, individuals may face fines of up to €1 million as well as temporary restrictions or a complete ban on holding management positions.

In some countries, the consequences can be even more severe, with criminal penalties for the most serious violations These penalties may range from criminal fines to prison sentences.

DORA enforcement actions and how penalties are applied

Authorities usually start with inspections and remediation orders. Fines are generally reserved for cases where identified issues remain unresolved, or where the breaches are more serious or repeated.

To enable the supervision, Article 50 allows authorities to get access to and copy any relevant documents, conduct on-site inspections (including interviews with staff), require corrective measures within a set deadline, and, where necessary, restrict or suspend specific business activities until the issue has been resolved.

When a fine is warranted, authorities set the final amount based on factors such as the severity and duration of the breach, whether it was intentional or negligent, the firm’s financial position, and whether it cooperated with the investigation or tried to conceal the problem The company will then be given a deadline for paying the fine, based on the applicable national rules.

How to avoid DORA regulation fines

DORA has been in full effect since January 17, 2025 with authorities across the EU now supervising the roughly 22,000 financial entities and ICT providers within its scope. However, a McKinsey survey found that only around one-third of financial institutions feel confident about meeting the full range of requirements

The best way for an organization to become compliant and avoid DORA penalties is to focus on each of the so-called 5 key pillars of DORA Here’s what those pillars are and how to address them:

  1. ICT risk management Develop a board-approved ICT framework that identifies critical systems in your IT environment, maps their vulnerabilities, and defines recovery plans. Review the framework annually or immediately after any major incident.
  2. Incident reporting Create a clear process for detecting, classifying, and reporting ICT incidents. Assign clear ownership of reporting so information about incidents reaches regulators within DORA’s required timeframes.
  3. Digital operational resilience testing Run regular tests, from vulnerability scans to scenario-based exercises, to confirm your systems and recovery plans work as intended.
  4. Third-party risk oversight Maintain a full register of ICT vendors and assess concentration risk across your supply chain. Also, make sure to include audit rights and clear exit terms in every contract.
  5. Information-sharing (optional) Share threat information with other financial organizations to learn from each other and identify potential attacks earlier.