We use a few strictly-necessary cookies, no marketing trackers, and cookieless analytics. Read our cookie policy, or pick a preference.
The EU's rulebook for keeping the financial system running when its technology fails. DORA makes digital operational resilience a board-level duty for financial entities, and pulls their critical technology suppliers, cloud and AI included, under direct EU oversight for the first time.
Under DORA, the management body bears ultimate responsibility for managing the entity's ICT risk. It must define, approve, and oversee the ICT risk-management framework, set the entity's risk tolerance, and review the arrangements regularly, and its members must keep sufficient knowledge and skills to understand ICT risk, through ongoing training. Responsibility for resilience sits with named individuals at the top of the firm, not with the technology function alone.
A bank meets DORA, NIS2, the GDPR, and the AI Act on the same high-risk system. We map at the level of the obligation, so one resilience programme answers several regimes at once.
DORA treats technology failure as a systemic risk to finance and builds a single resilience regime across the sector. Four of its five pillars carry direct obligations: an ICT risk-management framework, the classification and reporting of major ICT incidents, a testing programme, and the management of third-party ICT risk. The fifth encourages voluntary threat-intelligence sharing.
Its sharpest innovation is reaching past the regulated firm to its suppliers. Critical ICT third-party providers, the large cloud and, increasingly, AI vendors the sector depends on, come under direct EU oversight. For AI in finance, models are ICT systems inside the framework, and model vendors are third parties you must map, monitor, and be able to exit.
A documented framework the management body owns: identify, protect, detect, respond, recover, and learn.
Classify major ICT-related incidents against set criteria and report them to the competent authority on a defined clock.
A regular testing programme, with threat-led penetration testing for the most significant entities.
A register of information, concentration-risk limits, exit strategies, and oversight of critical providers.
DORA is fully in force. The current phase is the build-out of the critical-provider oversight regime and the first supervisory cycles.
Regulation enters into force, with a two-year implementation window.
DORA applies in full across EU financial entities.
The ESAs designate and begin overseeing critical ICT third-party providers.
Source: Official Journal of the EU · DORA regulatory and implementing technical standards · confirm the current RTS/ITS before relying on detail
DORA covers financial entities broadly, and for the first time reaches the technology providers they depend on.
Nearly the whole regulated sector, plus crypto-asset service providers. Each runs the full five-pillar programme, proportionate to size and risk.
Own the ICT risk framework, set risk tolerance, and maintain the skills to oversee it, under Article 5.
Designated cloud and technology providers, coming under direct oversight by the European Supervisory Authorities.
National regulators supervise entities; the ESAs run the pan-EU oversight of critical providers.
DORA leaves administrative penalties on financial entities to national law, while giving the ESAs a direct tool against critical providers.
| Against | Exposure |
|---|---|
| Nationalset by each authority | Financial entities face effective, proportionate, and dissuasive administrative penalties set by their competent authority, plus remediation orders. |
| 1% / dayup to six months | Critical ICT third-party providers face periodic penalty payments of up to 1% of average daily worldwide turnover, imposed by the ESAs to compel compliance. |
Figures per DORA Articles 35 and 50 · national penalty regimes vary · confirm the applicable rules locally
"Our cloud provider is responsible for our resilience."
DORA keeps the accountability with you. You must maintain a register of ICT third parties, manage concentration risk, and hold a tested exit strategy for each critical dependency.
"Operational resilience is an IT and operations matter."
Article 5 makes the management body own the ICT risk framework and keep the skills to oversee it. It is a board-level, personally-held duty.
"We run an annual penetration test, so testing is covered."
DORA requires a full testing programme, and threat-led penetration testing on a multi-year cycle for the most significant entities, going well beyond a routine annual test.
DORA applies to a broad set of EU financial entities, including banks, insurers, investment firms, payment and e-money institutions, crypto-asset service providers, and more, plus the critical ICT third-party providers that serve them. Article 2 lists the covered entity types; if you are a regulated financial entity in the EU, you are almost certainly in scope.
DORA has applied since 17 January 2025. There is no further transition period for financial entities; the obligations are live and national competent authorities have held enforcement powers since that date.
For critical ICT third-party providers, the Lead Overseer can impose periodic penalty payments of up to 1% of average daily worldwide turnover, charged daily for up to six months until compliance (Article 35). Fines and administrative penalties on financial entities are set by each Member State under Articles 50-52, so the quantum varies by jurisdiction.
DORA rests on five pillars: ICT risk management (Articles 5-16), ICT-related incident reporting to competent authorities (Articles 17-23), digital operational resilience testing including threat-led penetration testing for larger entities (Articles 24-27), ICT third-party risk management (Articles 28-44), and information-sharing arrangements (Article 45).
No. Those frameworks overlap but do not substitute for DORA. DORA imposes specific requirements, such as the ICT incident classification and reporting timelines, resilience testing regime, and contractual clauses for ICT third-party arrangements under Article 30, that general information-security certification does not cover.
Yes, in two ways. Financial entities must embed DORA-mandated contractual terms in ICT third-party contracts (Article 30), and providers designated as "critical" come under direct EU oversight by a Lead Overseer, with the periodic penalty powers noted above.