Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

DORA regulation explained - the Digital Operational Resilience Act five pillars and scope

DORA Explained: The Digital Operational Resilience Act Guide

The DORA regulation — the Digital Operational Resilience Act — is the EU’s landmark law for making the financial sector resilient to technology failures and cyber attacks. Formally Regulation (EU) 2022/2554, it applies from 17 January 2025 and reshapes how banks, insurers, investment firms, and their technology suppliers manage digital risk. This guide is your complete introduction to what DORA requires and how to comply.

DORA regulation explained - the Digital Operational Resilience Act five pillars and scope

Below we cover what the DORA regulation is, who it applies to, its five pillars, the critical role of ICT third-party risk, the deadline, penalties, and a practical path to compliance.

What is the DORA regulation?

DORA is a regulation that establishes a single, harmonised framework for digital operational resilience across the EU financial sector. Before DORA, rules on managing information and communication technology (ICT) risk were fragmented across member states and sub-sectors. DORA replaces that patchwork with one consistent rulebook covering how financial entities prevent, withstand, and recover from ICT-related disruptions — whether caused by a system outage, a failed supplier, or a cyber attack. Because it is a regulation rather than a directive, it applies directly and uniformly in every member state, with no national transposition required.

Who does DORA apply to?

DORA’s scope is broad. It covers virtually all regulated financial entities in the EU — banks, credit institutions, payment and e-money institutions, investment firms, insurers and intermediaries, crypto-asset service providers, trading venues, fund managers, and more. Critically, it also reaches the ICT third-party providers that serve them, including cloud platforms and software vendors, some of which fall under direct EU oversight. If your organization provides financial services in the EU, or provides technology to those that do, DORA almost certainly applies to you.

The five pillars of DORA

DORA’s requirements are organised around five pillars that together build end-to-end resilience:

  • ICT risk management — a comprehensive framework to identify, protect, detect, respond to, and recover from ICT risks, owned at board level.
  • ICT incident management and reporting — classifying incidents and reporting major ones to regulators within strict timelines.
  • Digital operational resilience testing — regular testing of systems, including advanced threat-led penetration testing for larger entities.
  • ICT third-party risk management — governing the risks that come from outsourcing to technology suppliers, with mandatory contractual provisions.
  • Information sharing — voluntary exchange of cyber threat intelligence among financial entities.

Each pillar generates its own policies, processes, and records — which is where structured documentation makes compliance manageable.

DORA and ICT third-party risk

One of DORA’s most significant shifts is its focus on the supply chain. Financial entities must maintain a register of all ICT third-party arrangements, assess concentration risk, embed specific contractual clauses (covering audit rights, exit strategies, and service levels), and monitor providers throughout the relationship. The largest, most systemically important technology providers — think major cloud platforms — can be designated as critical and placed under direct EU oversight. For both financial entities and their suppliers, third-party risk is no longer a back-office concern but a board-level obligation.

The DORA compliance deadline

DORA has applied since 17 January 2025. Unlike a phased rollout, its obligations became enforceable on that single date, which means compliance is already expected — not a future project. Entities still closing gaps should prioritise the areas regulators scrutinise first: the ICT risk-management framework, the incident-reporting process, and the third-party register and contracts.

Penalties and oversight

National competent authorities supervise financial entities’ compliance and can impose administrative penalties and remediation measures for breaches. Designated critical ICT third-party providers face direct oversight from the European Supervisory Authorities, with the power to issue recommendations and levy penalties. Beyond fines, the reputational and operational cost of a resilience failure — and of being seen to fall short of DORA — is a powerful incentive to get compliance right.

How to prepare for DORA

A pragmatic approach starts with a gap analysis against the five pillars, then builds out the missing framework: an ICT risk-management policy, an incident classification and reporting procedure, a resilience testing programme, and a complete third-party register with compliant contracts. Assign clear board-level accountability, and document everything — supervisors will want evidence, not intentions. Starting from a mapped toolkit turns this from a blank-page project into a structured, achievable programme.

Build DORA resilience the fast way.

Our DORA Toolkit delivers the policies, incident-reporting procedures, resilience-testing plans, and third-party register you need across all five pillars — mapped to the regulation and editable in Word and Excel.

Explore the DORA Toolkit →

Frequently asked questions

What is the DORA regulation in simple terms?

DORA is an EU law that requires financial entities and their technology providers to be resilient to ICT disruptions and cyber attacks, through a single harmonised framework covering risk management, incident reporting, testing, and third-party risk.

Who has to comply with DORA?

Nearly all EU financial entities — banks, insurers, investment firms, payment institutions, crypto-asset providers and more — plus the ICT third-party providers that serve them.

When did DORA come into effect?

DORA has applied since 17 January 2025. Its obligations are already enforceable, so compliance is expected now.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.