Jurisdiction
European Union
Authority
EBA + EIOPA + ESMA (Joint Committee) + National Competent Authorities
Max Penalty
€5M or 1% of worldwide daily turnover per violation
Compliance Difficulty82/100
Regulation (EU) 2022/2554, the Digital Operational Resilience Act, entered force on 16 January 2023 and became fully applicable on 17 January 2025. DORA imposes uniform ICT risk management, major incident reporting, digital operational resilience testing, and ICT third-party risk management obligations across more than 22,000 financial entities in the EU. Critically, DORA applies not just to regulated financial institutions but to any ICT third-party service provider — including cloud providers, data analytics vendors, and software-as-a-service platforms — that provides services to in-scope entities.

What DORA Covers

DORA establishes five core pillars: (1) ICT Risk Management — a comprehensive internal framework covering identification, protection, detection, response, and recovery; (2) ICT-Related Incident Management — classification, internal management procedures, and reporting to regulators; (3) Digital Operational Resilience Testing — annual threat-led penetration testing (TLPT) for significant entities; (4) ICT Third-Party Risk Management — pre-contractual due diligence, contract requirements, and concentration risk monitoring; and (5) Information Sharing — voluntary participation in cyber threat intelligence networks.

DORA's scope extends beyond traditional banks. In-scope entities include: credit institutions, payment institutions, e-money institutions, crypto-asset service providers (MiCA CASPs), insurance and reinsurance undertakings, investment firms, trading venues, AIFMs, UCITS management companies, credit rating agencies, and ICT third-party service providers deemed "critical" by the ESAs.

Who Must Comply

The following entities are subject to DORA Compliance Hub obligations:

  • Credit institutions, payment institutions, and e-money institutions operating in the EU
  • Crypto-asset service providers (CASPs) authorised under MiCA
  • Investment firms, alternative investment fund managers (AIFMs), and UCITS management companies
  • Insurance and reinsurance undertakings and insurance intermediaries
  • Trading venues, central counterparties (CCPs), and central securities depositories (CSDs)
  • ICT third-party service providers (cloud, SaaS, data analytics) serving in-scope EU financial entities
  • Critical ICT third-party providers (CTPPs) designated by the Joint Committee of ESAs

Penalties and Enforcement History

DORA confers penalty powers on national competent authorities. For financial entities, penalties can reach €5,000,000 or 1% of the total annual worldwide turnover of the entity for each day of violation, up to 5% of total annual worldwide turnover. For individuals in management, personal penalties of up to €1,000,000 or 2% of annual remuneration apply. Critical ICT third-party providers designated by the ESAs are subject to oversight measures and can be compelled to remediate deficiencies or terminate contracts with EU financial entities.

Enforcement Timeline

Nov 2022
DORA Published
Regulation (EU) 2022/2554 published in the Official Journal. 24-month implementation clock began for financial entities and regulators.
Jan 2023
Entry into Force
DORA entered into force on 16 January 2023. EBA, EIOPA, and ESMA commenced drafting Level 2 Regulatory Technical Standards (RTS) and Implementing Technical Standards (ITS).
Jan 2024
First RTS/ITS Published
Joint Committee published the first batch of technical standards covering ICT risk management, incident classification, and TLPT requirements. Entities integrated standards into implementation programs.
Jan 2025
Full Application
DORA became fully applicable on 17 January 2025 across all 27 EU Member States. MiCA-authorised CASPs added to scope. Entities without mature ICT risk management programs faced immediate supervisory scrutiny.
2025–2026
First Enforcement Actions
NCAs commenced supervisory reviews and inspections of DORA compliance frameworks. Entities lacking documented ICT risk policies, incident playbooks, and third-party registers are primary enforcement targets.

Regulatory Comparison

DimensionDORANIS2 DirectiveISO 27001
ApplicabilityEU financial entities + ICT providersEssential and important entities broadlyVoluntary — any organisation
Max Fine€5M or 1% daily turnover€10M or 2% annual turnover (essential)N/A (certification standard)
Enforcement BodyEBA + EIOPA + ESMA + NCAsNational CERT/NIS authoritiesUKAS/accredited CBs
Testing MandateAnnual TLPT for significant entitiesVulnerability scans + auditsInternal/external audit
Third-Party RulesMandatory CTPP oversight frameworkSupply chain security principlesSupplier relationships control set
Crypto ScopeYes — MiCA CASPs includedIndirectly via CASP digital infraOptional add-on

Mitigation Strategy

01
Build a DORA-Compliant ICT Risk Management Framework

The DORA ICT risk management framework (Articles 6-16) must cover: ICT risk strategy, ICT asset inventory, network segmentation, access controls, encryption, business continuity and disaster recovery (BCDR), ICT-related incident management procedures, and a learning-from-incidents review cycle. Document the framework in a board-approved ICT risk management policy. Cross-reference against ISO 27001:2022 Annex A to identify gaps.

02
Implement ICT-Related Incident Reporting Playbooks

DORA classifies incidents by materiality criteria set in Commission Delegated Regulation (EU) 2024/1772. Major ICT incidents must be reported to the competent authority within 4 hours of classification (initial report), 72 hours of discovery (intermediate report), and 1 month of resolution (final report). Operationalise via an incident response playbook with defined classification thresholds, NCA notification templates, and automated escalation triggers.

03
Register and Manage All ICT Third-Party Providers

Maintain a register of all ICT third-party service providers under Article 28. For each provider, document: contractual DORA-required clauses (audit rights, incident notification, SLA, data portability, exit), concentration risk assessment, and substitutability analysis. Assess whether any provider qualifies for Critical Third-Party Provider (CTPP) designation by the ESAs — CTPP designation triggers direct ESA oversight.

EBA DORA Supervisory Guidance (2025): "Entities operating under DORA must demonstrate not merely formal policy adoption but operational resilience through tested and exercised capabilities. The requirements of Regulation (EU) 2022/2554 apply to crypto-asset service providers authorised under MiCA from the date of their authorisation, without prejudice to the application of equivalent requirements previously imposed under applicable national law." — European Banking Authority.Enforcement Precedent

Frequently Asked Questions

Q: Does DORA apply to SaaS companies providing software to EU banks?

A: Potentially yes. DORA applies to ICT third-party service providers that provide ICT services to EU financial entities. "ICT services" is defined broadly to include digital and data services, including SaaS. The degree of obligation depends on whether your service is designated "critical" by the ESAs (making you a CTPP, subject to direct oversight) or non-critical (requiring DORA-compliant contractual clauses from your financial entity clients).

Q: What is Threat-Led Penetration Testing (TLPT) under DORA?

A: TLPT is an advanced form of penetration testing that simulates real-world cyber attacker techniques based on threat intelligence relevant to the specific financial entity. Under DORA Article 26, significant institutions must conduct TLPT at least every 3 years, using approved testers in a live production environment. TLPT results are reported to the competent authority. ICT third-party service providers used by the financial entity may also be in scope for the test.

Q: How does DORA interact with GDPR and NIS2?

A: DORA, GDPR, and NIS2 are complementary but distinct. An ICT security incident at an EU bank may trigger DORA incident reporting (to NCA within 4 hours), NIS2 incident notification (if the bank is also an essential entity), and GDPR personal data breach notification (to DPA within 72 hours). Compliance officers must map all three notification regimes to avoid missed deadlines.

Q: Which EU Member State regulates a DORA entity operating in multiple countries?

A: DORA follows the principle of home Member State supervision. A credit institution licensed in France is primarily supervised by the French NCA (ACPR or AMF) for DORA purposes, regardless of branches in other EU states. For ICT third-party providers, the Lead Overseer for CTPP designation is determined by the ESAs based on EU revenue and systemic importance of the client base.

Q: What must DORA contracts with ICT third-party providers include?

A: Under DORA Article 30, contracts must include: clear service descriptions and SLAs; provisions allowing the financial entity and its regulator to conduct audits and inspections; incident notification obligations aligned with DORA timeframes; data location and portability rights; termination rights triggered by material security breaches; a plan for the orderly exit of services; and cooperation obligations for TLPT testing. Existing contracts must be brought into DORA compliance — a contract remediation exercise covering all in-scope ICT providers is a Day-1 priority.

Deep Dive Guide

DORA ICT Compliance Guide → Five DORA pillars, Article 30 contract checklist, 4h/72h/1-month incident reporting, CTPP designation, and TLPT obligations for ICT vendors serving EU financial entities.

About the Author

This hub was written and is maintained by an LLB, LLM-qualified international commercial lawyer, notary, and arbitrator with 20 years of active practice. The analysis draws on direct practitioner experience across UAE, EU, US, UK, and Singapore jurisdictions — not synthesis from secondary sources.

LLB · LLM
International Commercial Law
20 Years
Active Legal Practice
Notary + Arbitrator
Commissioned & International
Jurisdictions
UAE · EU · US · UK · Singapore
Full credentials and methodology →