DORA compliance cost is the first number a board asks for and the last one anyone can defend, because the Digital Operational Resilience Act has no certification, no audit fee and no published price list. What it has is five pillars of obligations, a proportionality clause that removes whole line items for smaller entities, and one 2020 Commission impact assessment that nobody quoting “€2 to €5 million” has read. This guide rebuilds the budget from those primary sources, line by line, so you can tell which costs are fixed, which scale with your ICT estate, and which you are legally allowed to skip.
DORA compliance cost: why there is no certificate to pay for
Regulation (EU) 2022/2554 has applied since 17 January 2025. Unlike ISO 27001, it is not a standard you certify against. Your national competent authority supervises you (BaFin, the CSSF, the Central Bank of Ireland and so on), and it does not send an invoice for doing so. That removes the two largest fixed costs in an ISO budget, the certification body and the three-year surveillance cycle, and replaces them with something less predictable: the internal effort to produce evidence an examiner will accept on request.
Two consequences follow. First, DORA compliance cost is almost entirely a function of your own scope decisions, not a registrar’s day rate. Second, the penalty side is national. Article 50 requires Member States to lay down administrative penalties that are “effective, proportionate and dissuasive” but sets no fine amount or turnover percentage for financial entities. The “2% of worldwide turnover” figure circulating in vendor blogs does not appear in the Regulation. The only turnover-based figure in DORA is Article 35(8), a periodic penalty payment of up to 1% of average daily worldwide turnover, for a maximum of six months, and it applies to designated critical ICT third-party providers, not to you. Budget for national enforcement, which since 2026 has moved from awareness letters to on-site inspections, rather than for a number that does not exist.
What the primary sources actually say
Almost every DORA compliance cost article leans on the same Deloitte statistic. It is real, but it needs context. Deloitte’s DORA European Survey, published 15 July 2025, asked CISOs, CROs and DORA programme managers across 28 countries what they planned to spend on advisory, systems and implementation. 64% said €2 to €5 million; 17% could not give an estimate. That sample skews to institutions large enough to employ a DORA programme manager, so it is a ceiling for a mid-sized firm, not a benchmark. The same survey found that 46% named the register of information as the hardest single requirement, and 92% did not consider themselves fully compliant on resilience testing or third-party risk.
The older and more useful source is the Commission’s impact assessment accompanying the DORA proposal, SWD(2020) 198 of September 2020. It is the only official document that prices individual DORA obligations, and the German implementing bill (Bundestag Drucksache 20/10280) explicitly defers to it rather than producing its own estimate. Its figures are in 2020 prices and were built from consultation responses and “a limited survey to a few big European banks”, so treat them as order-of-magnitude anchors:
| Obligation | Commission estimate (2020) | Basis |
|---|---|---|
| Threat-led penetration test (TLPT) | €250,000–€500,000 per test | Consultation respondents; ESAs’ technical advice put TLPT at 0.1–0.3% of total ICT budget |
| Entities newly subject to TLPT | ~100 across the EU (€25–€50 million in total) | ~1% of 21,233 financial entities deemed significant, half already tested under TIBER-style schemes |
| Incident reporting, one-off | ~€9,000 per large bank | Developing an internal reporting template; 1,000–2,000 entities newly in scope |
| Incident reporting, recurring | ~€18,000 per year per large bank | Classification, regulatory scouting, template updates |
| Threat-intelligence sharing (voluntary) | €1,000–€50,000 plus 1–3 FTE | Membership fees, platform set-up, staff |
| Cybersecurity baseline | 6–14% of IT budget (average 10%); 0.2–0.9% of revenue | Deloitte/FS-ISAC survey cited by the Commission |
Source: European Commission, SWD(2020) 198, sections 6 and 7 and Annex 3. All figures 2020 prices.
Two things stand out for anyone modelling DORA compliance cost. The Commission never estimated a total per-entity figure, because it assumed most of the work was already required by existing sectoral rules (EBA ICT guidelines, Solvency II, PSD2). And it expected the largest new cost, TLPT, to hit only around a hundred firms. If you are not one of them, the “millions” headline is not about you.
DORA compliance cost by line item
The ranges below are typical 2026 figures drawn from published guidance by consultancies, TLPT providers and GRC vendors, not from a survey or a regulator. Where the Commission gave a number, it is shown alongside.
| Line item | DORA basis | Small entity (simplified or micro) | Mid-sized entity | TLPT-tier entity |
|---|---|---|---|---|
| Gap assessment | Art. 5–16 | €5,000–€20,000 or internal | €20,000–€60,000 | €60,000–€200,000 |
| ICT risk management framework and policies | Art. 6–14 (Art. 16 simplified) | €2,000–€15,000 with templates | €15,000–€80,000 | €100,000+ (programme) |
| Register of information | Art. 28(3), ITS (EU) 2024/2956 | Spreadsheet; 5–15 person-days | 20–60 person-days; GRC module €10,000–€40,000/yr | Dedicated team; €50,000–€200,000/yr tooling |
| Incident classification and reporting | Art. 17–19, RTS (EU) 2025/301 | €2,000–€10,000 set-up | ~€9,000 set-up, ~€18,000/yr (Commission) | 24/7 capability, €100,000+/yr |
| Annual resilience testing programme | Art. 24–25 | Exempt if microenterprise; otherwise risk-based | €15,000–€60,000/yr (scans, pen tests, scenario tests) | €100,000–€500,000/yr |
| Threat-led penetration test | Art. 26–27, RTS (EU) 2025/1190 | Not required | Not required unless designated | €250,000–€500,000 (Commission); €150,000–€620,000 (2026 provider guidance) every 3 years |
| Contract remediation (Art. 30 clauses) | Art. 30 | €500–€2,000 per critical contract | €20,000–€100,000 across the estate | €200,000+; often the largest legal spend |
| Internal audit of the ICT framework | Art. 6(6) | Exempt if microenterprise | €10,000–€40,000 co-sourced | Internal function |
| Staffing | Art. 5, 6(4) | Part of an existing role | 0.5–2 FTE | Dedicated programme team |
Typical 2026 ranges from published consultancy, TLPT-provider and GRC-vendor guidance. Person-day figures assume documented ICT contracts already exist.
For a reference point at the small end, one compliance vendor’s published 2026 estimate for a fintech of 100–250 employees was €150,000–€400,000 to reach compliance and €80,000–€200,000 a year to maintain it. That is consistent with the table above once TLPT is excluded, and about one-tenth of the Deloitte respondents’ plans.
What proportionality removes from the bill
DORA is unusual among EU financial rules in how much of it switches off by entity type, and that is the biggest lever on DORA compliance cost. Before you price anything, establish which of three tiers you are in, because the tier decides whether the two most expensive rows in the table exist at all.
Microenterprises, defined in Article 3(60) as fewer than 10 staff with turnover or balance sheet of €2 million or less, are excluded from the digital operational resilience testing programme under Article 24(1) and from the yearly testing of critical systems under Article 24(6). They need not assign ICT risk to a separate control function (Article 6(4)) or subject the framework to internal audit (Article 6(6)), and Article 6(5) lets them review the framework “periodically” rather than annually. They are never required to run a TLPT.
Simplified-framework entities under Article 16 replace Articles 5 to 15 with a lighter set of requirements. The list is exhaustive: small and non-interconnected investment firms, payment institutions exempted under PSD2, electronic money institutions exempted under the E-Money Directive, credit institutions exempted under Article 2(5) CRD where the Member State has opted out, and small institutions for occupational retirement provision. If you are on that list, the framework documentation cost falls to a fraction of the full Chapter II build.
TLPT-tier entities are identified by their authority under Article 26(8), using the thresholds in Delegated Regulation (EU) 2025/1190, in force since 8 July 2025: G-SIIs and O-SIIs and their group members, payment and e-money institutions above €150 billion in annual payment transactions (or €40 billion of outstanding e-money), CSDs, CCPs, the largest trading venues, and insurers above €1.5 billion gross written premium plus €10 billion of technical provisions, further filtered by market share. If you meet none of these, no one can compel a €300,000 red-team exercise; your obligation is the Article 24 testing programme, which you scope yourself.
Everyone in scope, regardless of tier, owes the register of information and major-incident reporting. Those two are the floor of DORA compliance cost, and neither can be delegated to a provider. Our guide to DORA requirements across the five pillars maps every article to the document it expects to see.
Three worked budgets
Payment institution under Article 16, 25 staff, 12 ICT providers. Gap assessment done internally against the simplified framework; policies from templates (€3,000–€10,000 in licences and two weeks of editing); register of information built in a spreadsheet to the ITS schema over 10 person-days; incident procedure and three report templates in a week; Article 30 clauses negotiated into four critical contracts (€4,000–€8,000 in legal time). Year-one total, typical range: €20,000–€50,000 including internal time. Annual run cost: €10,000–€25,000, mostly the register refresh and testing.
Investment firm, 200 staff, full Chapter II, not TLPT-designated. External gap assessment (€30,000–€50,000); framework build and policy set (€40,000–€80,000 with a consultant, half that with templates and an internal owner); GRC module for the register (€15,000–€30,000 a year); 60 person-days of contract inventory and remediation plus €40,000–€70,000 in outside counsel; annual testing programme (€30,000–€50,000); co-sourced internal audit (€15,000–€25,000). Year-one DORA compliance cost: €200,000–€400,000. Annual run cost: €90,000–€180,000. This is the profile the Deloitte “€2 to €5 million” respondents are not describing.
O-SII bank or large insurer, TLPT-designated. Everything above at programme scale, plus one TLPT every three years at €250,000–€500,000 in provider fees (the Commission’s range, which 2026 provider quotes still bracket), plus internal control-team time that firms consistently underestimate at 8 to 12 weeks. One insurer responding to the ESAs’ TLPT consultation put its average cost impact at around €500,000 for 10 to 12 weeks of testing. Multi-year DORA compliance cost in the low millions is realistic here, which is where the survey figure comes from.
Where the money leaks
The register of information. Nearly half of Deloitte’s respondents called it the hardest requirement, and the reason is data quality, not the template. The ITS asks for provider LEIs, the function each service supports, its criticality assessment, and the subcontracting chain beneath every critical service. Firms that never inventoried ICT contracts pay for that discovery twice: once to populate the register for the first submission in April 2025, and again when the 2026 cycle (competent authorities forward registers to the ESAs by 31 March each year from 2026) exposes what the first pass missed. Build the register from a contract inventory, not the other way round.
Duplicated testing. The Commission’s own justification for DORA was that cross-border groups faced two to five similar national tests at €250,000–€500,000 each. Article 26(4) pooled tests and the joint-TLPT provisions in the RTS exist to stop that. If you are in a group, the cheapest TLPT is the one your parent’s authority agrees you can share.
Contract remediation done contract by contract. Article 30 sets out the clauses every ICT contract must carry, and a longer list for those supporting critical or important functions. Firms that negotiate them bilaterally pay legal fees per supplier. A clause library plus a standard addendum sent to every provider at once turns a €100,000 exercise into a €20,000 one; the 19 critical ICT providers the ESAs designated on 18 November 2025 have, for the most part, already published DORA addenda you can accept rather than draft.
Incident reporting built for the wrong clock. The reporting timelines in DORA incident reporting (initial notification within four hours of classification, intermediate within 72 hours, final within a month) are cheap to meet if classification is fast and expensive if it is not. The cost is in the classification decision tree, not the report template.
How to cut DORA compliance cost without cutting corners
Reuse before you build. If you hold ISO 27001:2022, most of Chapter II already exists under different headings; the incremental documents are the DORA-specific ones (register, classification methodology, TLPT set, Article 30 clauses). If you are also in scope of NIS2, the overlap in risk management and reporting is substantial and the NIS2 compliance cost breakdown shows which artefacts serve both regimes.
Scope the testing programme to Article 24(6) literally: “appropriate tests” on systems supporting critical or important functions, at least yearly. Article 25 lists the acceptable test types, and vulnerability scanning plus a scenario exercise satisfies it for most non-designated firms. Do not buy a red team because a vendor called it “DORA-mandated”.
Watch the Digital Omnibus. The Commission’s 19 November 2025 proposal would route incident reports through a single entry point maintained by ENISA. It is a proposal, not law, so budget on the current three-report process and treat any saving as upside.
Finally, price the documentation honestly. A full DORA document set written from scratch by a consultant is the single largest discretionary spend for a mid-sized firm. Our DORA Toolkit supplies 100+ editable templates for $99, structured article by article, with a register-of-information workbook built to the ITS schema, the three-stage incident report set, the full TLPT document set, and an Article 30 clause library. It replaces the framework-build row in the table, not the judgment behind it.
Frequently asked questions
Does DORA compliance cost include a certification or audit fee?
No. DORA has no certification. Your national competent authority supervises you at no direct charge, though it can require you to pay for a TLPT if you are designated under Article 26(8). Any “DORA certificate” on offer is a private attestation with no regulatory standing.
What is the biggest single cost under DORA?
For designated entities, the threat-led penetration test: €250,000–€500,000 per test in the Commission’s 2020 estimate, €150,000–€620,000 in 2026 provider guidance, every three years. For everyone else, it is the register of information and the contract remediation behind it, which is people time rather than fees.
Can a small firm keep DORA compliance cost under €50,000?
A microenterprise or an Article 16 simplified-framework entity with a modest ICT estate can, provided contracts are already documented. The cost rises quickly with the number of ICT providers, because each critical contract needs Article 30 clauses and a register entry with its subcontracting chain.
What are the fines for DORA non-compliance?
DORA sets none for financial entities. Article 50 leaves administrative penalties to Member States, which must make them effective, proportionate and dissuasive. The 1% of average daily worldwide turnover figure in Article 35(8) applies only to critical ICT third-party providers under ESA oversight, and for at most six months.
Is DORA compliance cost recurring?
Yes. The register of information is refreshed annually, the framework is reviewed at least yearly, the testing programme runs every year and a TLPT recurs every three years. A reasonable planning rule is that annual run cost settles at 40–60% of year-one spend once the framework exists.
Primary sources: Regulation (EU) 2022/2554 on EUR-Lex; European Commission impact assessment SWD(2020) 198; Deloitte DORA European Survey (15 July 2025); ESAs Final Report JC 2024-29 on the TLPT RTS; Commission Delegated Regulation (EU) 2025/1190.