Skip to content
NewOFAC Watcher checks your watchlist each day and emails you when a sanctions-list change looks like a possible match.See OFAC Watcher · $29 / month
Covered
  • OFAC SDN list
  • UN sanctions list
  • EU sanctions list
  • Public on-chain data
  • MiCA
  • EU AI Act
  • GDPR
  • DORA
  • FinCEN BOI
  • VARA
  • SOC 2
  • AML / KYC

DORA compliance in France: who is in scope and what is owed

How DORA applies to companies operating in or serving France — scope tests, the obligations that follow, and the primary sources to verify each one against.

The Digital Operational Resilience Act (DORA) establishes uniform requirements for the security of network and information systems of financial entities operating within the European Union, including France. Supervised by European Supervisory Authorities such as ESMA, EBA, and EIOPA, the regulation reaches entities established in France or providing financial services into the French market. Organisations must align their operations with the baseline standards detailed in the primary regulation text at Regulation (EU) 2022/2554 (DORA) — full text.

Extraterritorial Scope and Application to French Market Participants

The scope of DORA applies broadly to financial entities established in France as well as third-country entities that provide digital or financial services to clients located within the territory. Entities operating from France must evaluate their status against the categories defined in the primary regulation text at Regulation (EU) 2022/2554 (DORA) — full text. Financial entities ranging from credit institutions and investment firms to crypto-asset service providers fall directly under the jurisdiction of the European Supervisory Authorities, which include ESMA, EBA, and EIOPA.

When entities sell cross-border into France without a physical establishment, the jurisdictional test examines whether the services directly impact French consumers or financial market participants. Regulatory oversight requires these cross-border participants to maintain operational resilience standards equivalent to locally established institutions. Teams can review overarching supervisory expectations through the guidance published on the ESMA — Digital Operational Resilience Act (DORA) portal.

The regulatory reach extends beyond traditional financial institutions to encompass technology vendors and service providers supporting the financial sector. Entities should utilize resources such as the Cross-Border Compliance Hub to map out their multi-jurisdiction exposures within the EU single market. Organizations must verify their precise obligations by consulting the foundational legal instruments rather than relying solely on secondary summaries.

Core Obligations for ICT Risk Management Frameworks

Regulated entities in France must put in place a comprehensive ict risk management framework capable of identifying, classifying, and protecting all ICT assets and sensitive data. This framework forms the backbone of operational resilience, requiring documented policies, continuous monitoring, and asset inventory controls. Guidance from authorities such as EIOPA, available at the EIOPA — Digital Operational Resilience Act (DORA) page, highlights the necessity of structured governance.

The framework mandates specific mechanisms for protection and prevention, including network security controls, access management, and continuous vulnerability assessments. Financial entities must document these processes thoroughly to satisfy supervisory inspections conducted by French or European authorities. Detailed methodologies for structuring these compliance programs are accessible via the Methodology Library Hub.

Below is an overview of the primary operational components required under the core risk management mandate:

| Obligation Area | Core Requirement | Primary Reference | | --- | --- | --- | | Risk Identification | Map business functions and ICT assets | Regulation (EU) 2022/2554 (DORA) — full text | | Protection & Prevention | Implement access controls and patching policies | EIOPA — Digital Operational Resilience Act (DORA) | | Detection | Monitor for anomalous activities continuously | ESMA — Digital Operational Resilience Act (DORA) |

Organizations must ensure their internal documentation aligns directly with the statutory text provided in Regulation (EU) 2022/2554 (DORA) — full text to withstand regulatory scrutiny.

Incident Reporting and Major ICT Incident Classifications

Managing disruptions requires a structured approach to detecting, logging, and reporting operational failures. Under the regulation, entities must establish processes to identify any major ict-related incident according to predefined thresholds involving downtime, affected clients, and economic impact. These thresholds are established in the legal text found at Regulation (EU) 2022/2554 (DORA) — full text.

When a significant disruption occurs, financial institutions operating in France must submit initial notifications, intermediate reports, and final root-cause analyses to the relevant competent authorities. Supervisory bodies like ESMA, referenced on the ESMA — Digital Operational Resilience Act (DORA) site, utilize these reports to monitor systemic stability across the financial sector. Compliance teams can also reference the DORA ICT Compliance Guide for operationalizing incident workflows.

Establishing an automated logging mechanism assists compliance teams in capturing the necessary metadata for incident classification. Entities must regularly test their incident response plans through simulation exercises to verify that notification timelines can be met under operational stress.

Digital Operational Resilience Testing and Advanced Assessments

Financial entities established in France are required to perform routine digital operational resilience testing on their ICT systems. These tests must validate the effectiveness of security measures and identify vulnerabilities across applications, networks, and hardware. The testing regime scales depending on the size, systemic importance, and risk profile of the financial entity as outlined in Regulation (EU) 2022/2554 (DORA) — full text.

For entities identified as high-risk or systemically significant, advanced testing involves threat-led penetration testing. This specific form of testing simulates real-world cyberattacks against live production systems supporting critical functions. Regulatory updates and supervisory expectations regarding advanced testing methodologies are detailed further on the ESMA — Digital Operational Resilience Act (DORA) resource center.

Remediation tracking is an essential component of the testing lifecycle. Any vulnerabilities or systemic weaknesses discovered during resilience tests must be logged, prioritized, and remediated within defined internal windows. Compliance teams often coordinate these remediation efforts alongside independent auditors and supervisory examiners.

ICT Third-Party Risk Management and Register of Information

Outsourcing critical functions to technology vendors introduces complex dependencies that require rigorous governance. Financial entities must evaluate every ict third-party service provider before entering into contractual arrangements. Specific contractual clauses regarding audit rights, data access, and termination assistance are mandated by Regulation (EU) 2022/2554 (DORA) — full text.

Institutions must maintain a comprehensive register of information detailing all contractual arrangements with technology vendors. This register must be made available to competent authorities upon request. If a vendor is designated as a critical ict-third-party provider by European oversight authorities, enhanced monitoring and oversight rules apply to those relationships, as described on the EIOPA — Digital Operational Resilience Act (DORA) portal.

Organizations should review their vendor contracting pipelines to ensure all service level agreements incorporate the mandatory statutory provisions. Legal and procurement teams must work in tandem to update legacy vendor contracts prior to supervisory audits.

BizLegal AI is regulatory research software, not a law firm. This page is general information, not legal advice, and does not create a lawyer-client relationship. Verify every deadline, threshold and obligation against the primary source cited before you act on it, and consult qualified counsel in the relevant jurisdiction.

Frequently asked questions

Does DORA apply to foreign technology companies selling software to French banks?

Technology vendors providing services to financial entities are classified as ICT third-party service providers. While direct regulatory obligations primarily target financial institutions, these vendors must contractually support their financial clients' compliance mandates, and designated critical providers face direct oversight from European supervisory authorities.

Which supervisory authorities oversee DORA compliance in France?

Supervision is coordinated across European authorities including ESMA, EBA, and EIOPA, working alongside national competent authorities in France such as the Autorité des Marchés Financiers and the Autorité de Contrôle Prudentiel et de Résolution.

What is the primary document required for vendor oversight?

Regulated entities must maintain a detailed register of information covering all contractual arrangements with ICT third-party service providers, capturing outsourcing details, asset classifications, and service locations.

How frequently must resilience testing be conducted?

Testing frequency depends on the entity's risk profile, size, and classification, with baseline vulnerability assessments occurring regularly and advanced threat-led penetration testing required for systemically important institutions.

Sources

BizLegal AI is regulatory research software, not a law firm. This page is general information, not legal advice, and does not create a lawyer-client relationship. Verify every deadline, threshold and obligation against the primary source cited before you act on it, and consult qualified counsel in the relevant jurisdiction.

Last reviewed 2026-10-08.

Contact