Compliance Mandatory Since January 2025

Understanding the
Digital Operational Resilience Act

DORA establishes a comprehensive framework for digital operational resilience in the EU financial sector. It requires financial entities to manage ICT risks, report incidents, test resilience, and oversee third-party providers.

The Five Pillars of DORA

DORA is built on five key pillars that together ensure comprehensive digital operational resilience for financial entities.

Articles 5-16

ICT Risk Management

Establish comprehensive ICT risk management frameworks, policies, and procedures.

Articles 17-23

Incident Reporting

Classify, report, and manage major ICT-related incidents to competent authorities.

Articles 24-27

Digital Resilience Testing

Regular testing including vulnerability assessments and threat-led penetration testing (TLPT).

Articles 28-44

Third-Party Risk

Manage ICT third-party risks and maintain oversight of critical service providers.

Article 45

Information Sharing

Participate in cyber threat intelligence and information exchange arrangements.

Who Must Comply?

DORA applies to virtually all regulated financial entities in the EU, as well as critical ICT third-party service providers. The regulation affects over 22,000 entities across the financial sector.

Credit Institutions (Banks)Mandatory
Investment FirmsMandatory
Insurance & Reinsurance CompaniesMandatory
Payment InstitutionsMandatory
E-Money InstitutionsMandatory
Central Securities DepositoriesMandatory
Trading VenuesMandatory
Trade RepositoriesMandatory
Crypto-Asset Service ProvidersMandatory
ICT Third-Party Service ProvidersMandatory

Proportionality Principle

DORA applies requirements proportionally based on the size, risk profile, and complexity of the financial entity. Smaller entities may have simplified requirements, while significant entities face more stringent obligations, including mandatory TLPT testing.

Large/Significant Entities

Full DORA requirements including TLPT every 3 years

Medium Entities

Core requirements with simplified testing

Small/Micro Entities

Proportionate simplified ICT framework

Determine Your Requirements

DORA Timeline

Key milestones in the implementation of DORA.

December 2022
DORA officially published in EU Official Journal
January 2023
DORA entered into force
2023-2024
Development of Regulatory Technical Standards (RTS)
January 17, 2025
DORA becomes fully applicable
Ongoing
Continuous compliance and TLPT testing cycles

Need Help with DORA Compliance?

Our team of certified security professionals can help you understand your DORA obligations and implement the required security testing.