What DORA Covers
DORA establishes five core pillars: (1) ICT Risk Management — a comprehensive internal framework covering identification, protection, detection, response, and recovery; (2) ICT-Related Incident Management — classification, internal management procedures, and reporting to regulators; (3) Digital Operational Resilience Testing — annual threat-led penetration testing (TLPT) for significant entities; (4) ICT Third-Party Risk Management — pre-contractual due diligence, contract requirements, and concentration risk monitoring; and (5) Information Sharing — voluntary participation in cyber threat intelligence networks.
DORA's scope extends beyond traditional banks. In-scope entities include: credit institutions, payment institutions, e-money institutions, crypto-asset service providers (MiCA CASPs), insurance and reinsurance undertakings, investment firms, trading venues, AIFMs, UCITS management companies, credit rating agencies, and ICT third-party service providers deemed "critical" by the ESAs.
Who Must Comply
The following entities are subject to DORA Compliance Hub obligations:
- →Credit institutions, payment institutions, and e-money institutions operating in the EU
- →Crypto-asset service providers (CASPs) authorised under MiCA
- →Investment firms, alternative investment fund managers (AIFMs), and UCITS management companies
- →Insurance and reinsurance undertakings and insurance intermediaries
- →Trading venues, central counterparties (CCPs), and central securities depositories (CSDs)
- →ICT third-party service providers (cloud, SaaS, data analytics) serving in-scope EU financial entities
- →Critical ICT third-party providers (CTPPs) designated by the Joint Committee of ESAs
Penalties and Enforcement History
DORA confers penalty powers on national competent authorities. For financial entities, penalties can reach €5,000,000 or 1% of the total annual worldwide turnover of the entity for each day of violation, up to 5% of total annual worldwide turnover. For individuals in management, personal penalties of up to €1,000,000 or 2% of annual remuneration apply. Critical ICT third-party providers designated by the ESAs are subject to oversight measures and can be compelled to remediate deficiencies or terminate contracts with EU financial entities.
Enforcement Timeline
Regulatory Comparison
| Dimension | DORA | NIS2 Directive | ISO 27001 |
|---|---|---|---|
| Applicability | EU financial entities + ICT providers | Essential and important entities broadly | Voluntary — any organisation |
| Max Fine | €5M or 1% daily turnover | €10M or 2% annual turnover (essential) | N/A (certification standard) |
| Enforcement Body | EBA + EIOPA + ESMA + NCAs | National CERT/NIS authorities | UKAS/accredited CBs |
| Testing Mandate | Annual TLPT for significant entities | Vulnerability scans + audits | Internal/external audit |
| Third-Party Rules | Mandatory CTPP oversight framework | Supply chain security principles | Supplier relationships control set |
| Crypto Scope | Yes — MiCA CASPs included | Indirectly via CASP digital infra | Optional add-on |
Mitigation Strategy
The DORA ICT risk management framework (Articles 6-16) must cover: ICT risk strategy, ICT asset inventory, network segmentation, access controls, encryption, business continuity and disaster recovery (BCDR), ICT-related incident management procedures, and a learning-from-incidents review cycle. Document the framework in a board-approved ICT risk management policy. Cross-reference against ISO 27001:2022 Annex A to identify gaps.
DORA classifies incidents by materiality criteria set in Commission Delegated Regulation (EU) 2024/1772. Major ICT incidents must be reported to the competent authority within 4 hours of classification (initial report), 72 hours of discovery (intermediate report), and 1 month of resolution (final report). Operationalise via an incident response playbook with defined classification thresholds, NCA notification templates, and automated escalation triggers.
Maintain a register of all ICT third-party service providers under Article 28. For each provider, document: contractual DORA-required clauses (audit rights, incident notification, SLA, data portability, exit), concentration risk assessment, and substitutability analysis. Assess whether any provider qualifies for Critical Third-Party Provider (CTPP) designation by the ESAs — CTPP designation triggers direct ESA oversight.
Frequently Asked Questions
A: Potentially yes. DORA applies to ICT third-party service providers that provide ICT services to EU financial entities. "ICT services" is defined broadly to include digital and data services, including SaaS. The degree of obligation depends on whether your service is designated "critical" by the ESAs (making you a CTPP, subject to direct oversight) or non-critical (requiring DORA-compliant contractual clauses from your financial entity clients).
A: TLPT is an advanced form of penetration testing that simulates real-world cyber attacker techniques based on threat intelligence relevant to the specific financial entity. Under DORA Article 26, significant institutions must conduct TLPT at least every 3 years, using approved testers in a live production environment. TLPT results are reported to the competent authority. ICT third-party service providers used by the financial entity may also be in scope for the test.
A: DORA, GDPR, and NIS2 are complementary but distinct. An ICT security incident at an EU bank may trigger DORA incident reporting (to NCA within 4 hours), NIS2 incident notification (if the bank is also an essential entity), and GDPR personal data breach notification (to DPA within 72 hours). Compliance officers must map all three notification regimes to avoid missed deadlines.
A: DORA follows the principle of home Member State supervision. A credit institution licensed in France is primarily supervised by the French NCA (ACPR or AMF) for DORA purposes, regardless of branches in other EU states. For ICT third-party providers, the Lead Overseer for CTPP designation is determined by the ESAs based on EU revenue and systemic importance of the client base.
A: Under DORA Article 30, contracts must include: clear service descriptions and SLAs; provisions allowing the financial entity and its regulator to conduct audits and inspections; incident notification obligations aligned with DORA timeframes; data location and portability rights; termination rights triggered by material security breaches; a plan for the orderly exit of services; and cooperation obligations for TLPT testing. Existing contracts must be brought into DORA compliance — a contract remediation exercise covering all in-scope ICT providers is a Day-1 priority.
DORA ICT Compliance Guide → Five DORA pillars, Article 30 contract checklist, 4h/72h/1-month incident reporting, CTPP designation, and TLPT obligations for ICT vendors serving EU financial entities.
This hub was written and is maintained by an LLB, LLM-qualified international commercial lawyer, notary, and arbitrator with 20 years of active practice. The analysis draws on direct practitioner experience across UAE, EU, US, UK, and Singapore jurisdictions — not synthesis from secondary sources.