Back to Frameworks
Frameworks

DORA (Digital Operational Resilience Act)

Framework Name

Digital Operational Resilience Act (DORA)

Type

Mandatory

Region / Jurisdiction

European Union

Enforcing Body / Certifying Party

National Competent Authorities in each EU member state, coordinated by the European Supervisory Authorities (the EBA, EIOPA, and ESMA). The largest, most critical ICT third-party providers are overseen directly at the EU level by a designated Lead Overseer, rather than through national regulators alone

Penalty / Consequence of Non-Compliance

Financial penalties are set by each member state's own implementing law, so the exact amounts vary by country rather than following one harmonized EU-wide figure. Separately, the EU can impose periodic penalty payments directly on Critical ICT Third-Party Providers that fail to meet oversight requirements

What It Is & Why It Matters

DORA requires financial entities, banks, insurers, investment firms, and roughly 20 categories of financial services companies in total, to manage ICT risk in a structured way, report major cyber incidents quickly (initial notification within hours of classifying an incident as major), regularly test their digital resilience, and maintain active oversight of the technology vendors they depend on. Larger, more significant entities must also undergo Threat-Led Penetration Testing, a more advanced form of simulated attack testing, at least every three years.

It matters because the financial sector has become deeply dependent on a small number of outside technology providers, cloud platforms, data processors, core banking software, and a serious failure at one of those providers could cascade across many banks and insurers simultaneously. DORA directly targets that concentration risk, which is why it also reaches ICT providers themselves, even ones based outside the EU, if they serve EU financial entities. It's also written as the specialized law for finance specifically: where NIS2 sets baseline cybersecurity rules across many industries, DORA takes precedence for financial entities, its more detailed and specific requirements apply instead of NIS2's general ones.

Who Needs It

  • You are a bank, insurer, investment firm, or one of the other categories of financial entity operating in the EU
  • You are an ICT provider, cloud, data processing, IT infrastructure, serving EU financial entities, even without an EU office yourself
  • You've been formally designated a Critical ICT Third-Party Provider and face direct EU-level oversight
  • You're already working through NIS2 and need to know DORA overrides it for anything financial-sector-specific
Book A Demo