DORA

← All instruments
in forcesectoral
Type
regulation
Layer
sectoral
Status
in force
In force
2023-01-16
Key date
2025-01-17 applies
Last verified
2026-07-16

DORA — the financial sector’s own cyber regime

Regulation (EU) 2022/2554 on digital operational resilience for the financial sector. Applies since 17 January 2025. Where NIS2 sets a baseline for 18 sectors, DORA is the stricter, directly-applicable lex specialis for finance — on the premise that a firm can fail operationally (via ICT) as surely as financially.

Who is in scope

~20 types of financial entity: credit institutions; payment & e-money institutions; investment firms; crypto-asset service providers (MiCA); trading venues; CCPs and CSDs; managers of AIFs and UCITS; (re)insurers and intermediaries; pension institutions; credit-rating agencies; crowdfunding providers; and more — plus, uniquely, the ICT third-party providers serving them (pillar 5). Proportionality applies: a simplified framework for small/non-interconnected firms; relief for micro-enterprises.

The five pillars

1. ICT risk management (Arts. 5–16)

The management body bears final responsibility. Full framework: strategy, protection & prevention, detection, response & recovery, backups, learning/evolution, communication — mapped to identified critical functions. RTS from the ESAs specify the content.

2. ICT incident management & reporting (Arts. 17–23)

Classify all ICT incidents against harmonised criteria (clients affected, duration, geographic spread, data losses, criticality, economic impact). Major incidents are reported to the competent authority in three steps:

  • Initial notification: within 4 hours of classifying as major, and no later than 24 hours from awareness;
  • Intermediate report: within 72 hours;
  • Final report: within one month. Significant cyber threats may be reported voluntarily; clients are informed when affected.

3. Digital operational resilience testing (Arts. 24–27)

Annual testing programme for all (vulnerability scans, scenario tests). Significant entities run Threat-Led Penetration Testing (TLPT) at least every 3 years on live production systems of critical functions, TIBER-EU-aligned — including relevant critical ICT providers.

4. ICT third-party risk management (Arts. 28–30)

Lifecycle governance of tech providers: a third-party risk strategy; the Register of Information (inventory of all ICT contractual arrangements — first regulatory submissions ran in 2025); pre-contract risk assessment; concentration-risk analysis; and mandatory contract clauses (Art. 30: access/audit rights, SLAs, termination/exit strategies, sub-outsourcing conditions, cooperation with authorities).

5. Oversight of Critical ICT Third-Party Providers (Arts. 31–44)

The novel part: the ESAs directly oversee designated CTPPs (hyperscale cloud and similar) via appointed Lead Overseers — information requests, inspections, recommendations, penalty payments up to 1% of average daily worldwide turnover. First CTPP designations were made by the ESAs; oversight is ramping through 2025–2026. ⚠️ VERIFY current designation list.

Plus voluntary information-sharing arrangements (Art. 45).

Enforcement

No harmonised EU fine ceilings for financial entities — supervision and sanctions flow through the existing financial stack (ECB/SSM; EBA/ESMA/EIOPA; national authorities such as BaFin, Banca d’Italia/CONSOB/IVASS, ACPR/AMF). Supervisory expectations on governance, testing, exit strategies and audit rights matured through 2026.

Interplay

NIS2 is displaced for financial entities (lex specialis), though the national CSIRT ecosystem still serves them; DORA major-incident reports are slated to flow through the future Single Entry Point; cloud certification (EUCS) and CTPP oversight are converging themes for financial cloud usage.

Sources