DORA regulation: digital operational resilience for the financial sector
The DORA regulation, also known as the Digital Operational Resilience Act, is the most transformative piece of legislation to affect the European financial sector in the last decade. It requires banks, insurers, fund managers and ICT providers to implement strict resilience measures against technological risks, operational incidents and cyberattacks.
DORA regulation: origin and purpose
This is Regulation (EU) 2022/2554 of the European Parliament and of the Council, published in December 2022, fully applicable since January 2025. Its objective is to unify in a single framework the digital operational resilience requirements for the European financial sector, which until then were scattered across sectoral regulations.
From sectoral guidelines to a common standard
Moreover, before DORA there were European Banking Authority (EBA) guidelines, ECB guidance and national frameworks that overlapped and even contradicted each other. An entity with operations in several European countries had to manage different requirements in each jurisdiction. DORA harmonises the landscape and reduces the administrative burden in the medium term, even if its initial implementation is demanding.
DORA regulation: a paradigm shift
On the other hand, the regulation represents an important conceptual change: it moves from the “comply with the controls” approach to the “demonstrate resilience” approach. For this reason, entities can no longer limit themselves to implementing security measures and documenting them: they must regularly prove that those measures work under pressure.
DORA regulation: who it applies to
This regulation has a much broader scope than many assume. It is not limited to banks.
Direct financial entities
DORA applies to more than 20 types of financial entities: banks, payment institutions, electronic money institutions, investment firms, fund managers, insurers, reinsurers, crypto-asset providers and pension fund managers, among others. Practically any organisation in the European financial sector is within its scope.
Critical ICT providers
On the other hand, the regulation also establishes a regime of direct supervision over the technology providers considered critical for the financial sector. Large cloud providers, core banking software providers (many still running on COBOL projects being modernised with AI) and payment platforms can be designated as Critical Third-Party Providers (CTPPs) and become subject to direct supervision by the European supervisory authorities.
Impact on the supply chain
Finally, even companies that are neither financial entities nor critical providers can be affected indirectly if they provide ICT services to entities under DORA. Because of this, contracts with financial-sector clients must align with the regulation’s requirements.
DORA regulation: the five pillars
Undoubtedly, the regulation is structured around five areas of obligation that entities must cover in an integrated way. You cannot comply with some and ignore others.
DORA regulation: pillar 1, ICT risk management
The first pillar requires establishing a comprehensive ICT risk management framework approved by the management body. This framework must include asset identification, risk assessment, proportionate controls and periodic review. Ultimate responsibility rests with the board of directors, not the CISO.
Pillar 2: incident management and notification
Moreover, entities must classify, manage and notify incidents according to harmonised criteria. Major incidents must be reported to the competent authorities within strict deadlines: an initial notification within 4 hours, an intermediate report within 72 hours and a final report within a month. The capacity to detect and classify incidents becomes critical.
Pillar 3: resilience testing
For this reason, DORA introduces a tiered testing regime according to the criticality of the entity. Systemic entities must undergo advanced Threat-Led Penetration Testing (TLPT) every three years. Because of this, the tests must be real, not documentary simulations.
Pillar 4: third-party risk management
Entities must keep a register of all their agreements with ICT providers, assess their concentration risk and establish exit strategies. Contracts with critical providers must include specific clauses on access, auditing, data portability and cooperation with authorities.
Pillar 5: information sharing
Finally, DORA encourages voluntary sharing between financial entities of information on cyber threats, incidents and indicators of compromise. The sector gains collective resilience against organised threats.
DORA regulation: how to implement it successfully
On the other hand, many entities have underestimated the implementation effort. These are the critical factors that make the difference between a successful programme and one that only passes formally.
DORA regulation: governance and leadership
In this context, the first step is to establish clear governance with responsibility at the highest level. A cross-cutting DORA committee —with representatives from IT, cybersecurity, operational risk, compliance and business— is the minimum viable structure. In entities that need expert external support, having a DORA consultant in banking with experience in compliance programmes speeds up the gap analysis and the prioritisation of remediations. Moreover, the board of directors must receive regular reporting on the state of the programme.
Initial maturity assessment
For example, before launching initiatives, it is wise to carry out a maturity assessment against the five pillars to identify gaps. According to the European Banking Authority (EBA), the level of preparedness varies significantly between entities and sectors, which makes it possible to prioritise investment where the gap is greatest.
Multi-year plan with milestones
However, DORA is not complied with in six months. Mature entities structure a multi-year plan with concrete milestones: year 1 for governance and risk management, year 2 for testing and third-party management, years 2-3 for advanced maturity. Because of this, the Project Manager or Programme Manager leading this initiative becomes a strategic figure within the organisation.
DORA regulation: relationship with other regulations
Finally, this regulation does not operate in isolation. It works together with other European regulations that entities must comply with simultaneously.
DORA vs NIS2
NIS2 is the general European cybersecurity directive, while DORA is the lex specialis of the financial sector. Financial entities comply with DORA and NIS2 stops applying to them in the aspects covered by DORA. Many technology providers in the financial sector are under NIS2 even if not under DORA.
DORA and the EU AI Act
AI systems used in financial decisions (credit scoring, fraud detection, algorithmic trading) can be classified as high-risk under the EU AI Act. For this reason, the compliance programme must integrate both frameworks to avoid duplication and gaps.
In conclusion, the DORA regulation is a profound transformation of the European financial sector that goes beyond bureaucratic compliance. Entities that tackle it with strategic vision will build real operational resilience, protect their customers and be better positioned to compete in an environment of growing threats. Anyone who treats it as a simple box-ticking exercise will have missed a unique opportunity to transform.
Frequently asked questions about the DORA regulation
To complement the regulatory framework: IT regulations that apply in 2026 and modern banking security.
The DORA regulation (Digital Operational Resilience Act, Regulation EU 2022/2554) is the European digital operational resilience regulation that requires the financial sector to manage ICT risks, report major incidents, carry out resilience testing, supervise its technology providers and share intelligence on cyber threats. It is fully applicable since 17 January 2025.
DORA applies to credit institutions, payment and electronic money institutions, investment firms, fund managers (UCITS, AIFM), insurers and reinsurers, pension funds, credit rating agencies, crowdfunding platforms, crypto-asset service providers (MiCA) and ICT providers critical to the financial sector. More than 22,000 entities in the EU.
The five pillars of DORA are: (1) ICT risk management, with a framework documented and approved by management; (2) management, classification and notification of major incidents to the competent authorities; (3) digital operational resilience testing (TLPT); (4) ICT provider risk management, including mandatory contractual clauses; and (5) sharing of information on cyber threats between entities.
More on the DORA regulation
Penalties for breaching DORA can reach 1% of daily global turnover until compliance, administrative penalties from national regulators (Bank of Spain, CNMV, DGSFP), personal disqualification of executives, critical reputational damage and operational restrictions. The European authorities (EBA, ESMA, EIOPA) coordinate the supervision of critical ICT providers.
NIS2 is the general cybersecurity directive for essential infrastructure (energy, healthcare, transport, banking, etc.), while DORA is lex specialis for the financial sector: it prevails over NIS2 where they overlap. DORA is more technically detailed (it specifies types of tests, exact notification deadlines, ICT contract content) and applies directly without national transposition.
A programme to run with little margin for error? See how I have done it.
See the nine case studies