LinkedInInstagramXTikTok

DORA explained: what the Digital Operational Resilience Act means for financial firms

Why DORA matters for the financial sector

Financial services now run on technology. Banks, insurers, payment providers and investment firms depend on cloud platforms, data centres and software vendors to serve customers every second of the day. When those systems fail – through a cyberattack, an outage or a supplier collapse – the disruption can spread across the whole market. The EU’s Digital Operational Resilience Act (DORA) was created to address exactly this risk, and it has applied directly in every member state since 17 January 2025.

DORA is not a light-touch guideline. It is a binding regulation with detailed technical standards, and there was no transition period. If your business is a financial entity, or if you supply technology to one, DORA already shapes how you must manage, test and report on your digital operations.

What DORA is and who it applies to

DORA is Regulation (EU) 2022/2554. It creates a single, harmonised framework for managing information and communication technology (ICT) risk across the EU financial sector, replacing a patchwork of national rules and overlapping guidance.

Its scope is deliberately broad. Around twenty categories of financial entity fall within it, including banks, insurers and reinsurers, investment firms, payment and electronic money institutions, crypto-asset service providers, fund managers and trading venues. Crucially, DORA also reaches the ICT third-party providers that serve these firms – from cloud hosting to software and data analytics.

The five pillars of DORA

ICT risk management

Every financial entity must maintain a documented ICT risk management framework, owned and overseen by the management body. This includes mapping critical systems, protecting them, detecting anomalies and having clear response and recovery plans.

Incident reporting

Firms must classify ICT-related incidents against harmonised criteria and report major incidents to their competent authority within set deadlines, using a common template. This gives regulators a clearer, comparable view of what is happening across the market.

Digital operational resilience testing

Entities must test their systems regularly, from vulnerability assessments to scenario testing. The most significant firms must also carry out threat-led penetration testing (TLPT) at least every three years, simulating real attacks against live systems.

ICT third-party risk management

DORA sets prescriptive rules for outsourcing. Firms must keep a register of information covering every contractual arrangement with ICT providers, assess concentration risk, and ensure contracts contain mandatory clauses on access, audit, security and exit.

Information and intelligence sharing

DORA encourages financial entities to share cyber threat intelligence with trusted peers, helping the sector defend itself collectively without breaching confidentiality or competition rules.

Oversight of critical ICT providers

One of DORA’s most novel features is an EU-level oversight framework for critical ICT third-party providers (CTPPs), such as major cloud platforms. These providers are designated and supervised directly by the European Supervisory Authorities, which can issue recommendations and, ultimately, impose periodic penalty payments of up to 1% of the provider’s average daily worldwide turnover for non-compliance. The aim is to reduce the systemic and concentration risk that arises when much of the sector relies on a handful of suppliers.

Practical example: a payment institution and its cloud provider

Imagine a mid-sized payment institution that runs its core services on a single external cloud platform. Under DORA, it must record that relationship in its register of information, assess what would happen if the provider suffered an outage, and ensure the contract guarantees audit rights and a workable exit plan. If the cloud service went down and disrupted payments for several hours, the incident would need to be classified and, if major, reported to the competent authority within the required timeframe. Preparing for this in advance is far cheaper than improvising during a live crisis.

Common mistakes companies make

The most frequent error is treating DORA as an IT-department project rather than a board-level responsibility – the regulation explicitly places accountability with the management body. Others underestimate the third-party pillar, discovering too late that their supplier contracts lack the mandatory clauses. Many firms also leave their register of information incomplete, or fail to test recovery plans against realistic scenarios. Smaller entities sometimes assume DORA does not apply to them, when in fact scope is wide and proportionality, not exemption, is the guiding principle.

Recommended actions

Start by confirming whether your organisation is in scope, either as a financial entity or as an ICT provider to one. Build or complete your register of information, review every ICT contract against DORA’s requirements, and renegotiate where clauses are missing. Establish a clear incident classification and reporting process, and rehearse it. Put a realistic testing programme in place, and make sure your board receives regular, understandable reporting on ICT risk. Where the picture is complex, take specialist advice early rather than after an incident.

Frequently asked questions

When did DORA start to apply?

DORA has applied directly across the EU since 17 January 2025, with no transition period.

Does DORA apply to technology suppliers?

Yes. ICT third-party providers serving financial entities are affected through contractual requirements, and the most systemically important providers can be designated as critical and supervised at EU level.

What happens if a firm does not comply?

National competent authorities can impose administrative penalties and remedial measures on financial entities, while critical ICT providers face EU-level oversight and periodic penalty payments.

Conclusion

DORA marks a decisive shift: digital operational resilience is now a legal obligation, not just good practice. Financial entities and their technology partners need robust ICT risk management, tested recovery plans, disciplined incident reporting and carefully drafted supplier contracts. Getting this right protects your customers, your reputation and your licence to operate. At Lawgent, we help financial firms and their suppliers interpret DORA, review contracts and build practical, proportionate compliance frameworks – combining legal expertise with a clear understanding of the technology behind it. Get in touch to make sure your organisation is resilient by design.

Leave a Reply

Your email address will not be published. Required fields are marked *


0Cart0,00 

No products in the cart.

Return to shop