Regulations · DORA

Digital Operational Resilience Act

Regulation (EU) 2022/2554DORA (Regulation EU 2022/2554) applies to EU financial entities and their critical ICT third-party providers from 17 January 2025. ICT risk, incident reporting, resilience testing and third-party oversight.

In force since
2025-01-17
Atomic obligations
23
Max exposure
€10M
or 2% global turnover

Who is concerned?

DORA is the EU's digital operational resilience framework for the financial sector.

  • Banks, payment institutions, insurance, investment firms
  • Crypto-asset service providers (under MiCA scope)
  • Critical ICT third-party service providers designated by ESAs (typically large cloud/SaaS vendors serving the financial sector)

If you sell ICT to EU financial institutions — DORA touches you indirectly via third-party risk obligations cascaded from your customers.

What it requires (high-level)

  • ICT risk management framework (Art. 6) — comprehensive policy, governance, board oversight.
  • ICT third-party register (Art. 28) — exhaustive inventory of providers + risk classification + contract clauses.
  • Threat-led penetration testing (TLPT, Art. 26) — advanced testing for systemically important entities, every 3 years.
  • Simplified testing (Art. 25) — for smaller entities, baseline testing requirements.
  • Incident reporting — major ICT-related incidents to competent authorities within strict deadlines.
  • Information sharing — voluntary intelligence sharing in trusted communities.

Penalty exposure

  • €10M or 2% of global annual turnover for financial entities.
  • Critical ICT third-party providers : up to 1% of worldwide turnover per day for non-compliance with EU oversight.

How NexCyber helps with DORA

  • Third-party register (Art. 28) — structured inventory + tier-1 risk scoring + contract clause checklist.
  • TLPT readiness — gap analysis vs threat-led pentest requirements.
  • Incident reporting workflow — pre-filled templates matching ECB / ESMA / EBA notification formats.
  • NIS2 / DORA overlap — auto-detected and reconciled (no double effort on overlapping controls).

In force since 17 January 2025. If you haven't started DORA implementation, you are non-compliant.

DORA — Frequently asked questions

Who must comply with DORA?+

All EU financial entities (banks, payment institutions, insurance, investment firms, crypto-asset service providers, central securities depositories, trading venues) plus critical third-party ICT service providers (CTPPs) designated by the Joint Committee of the European Supervisory Authorities. CTPP designation is renewable annually.

What does DORA require for ICT risk management?+

A comprehensive ICT risk management framework approved by the management body, ICT-related incident classification and reporting (major incidents within 4 hours of classification + final report within 1 month), digital operational resilience testing including TLPT every 3 years for significant entities, and ICT third-party risk management covering register, contractual provisions and concentration risk.

When does DORA apply?+

DORA entered into force on 16 January 2023 and applies from 17 January 2025. The European Supervisory Authorities (EBA, ESMA, EIOPA) have published binding Regulatory Technical Standards and Implementing Technical Standards covering each pillar. Annual ICT risk management framework reviews are mandatory.

How does DORA penalise non-compliance?+

Penalties depend on national transposition but cannot fall below €10 million or 2% of total annual worldwide turnover for legal persons. Critical third-party providers can be fined up to 1% of average daily worldwide turnover per day of breach for non-cooperation, capped at 6 months.

See your DORA readiness in 5 minutes.

Free assessment. No credit card. EU-hosted. Auditable engine.

Run free assessment