Why DORA Matters for Every EU Financial Firm
DORA is the European Union's Digital Operational Resilience Act, Regulation (EU) 2022/2554. It entered into force on 16 January 2023 and has applied since 17 January 2025. DORA gives the EU financial sector a single, binding rulebook for surviving severe technology disruptions, covering around 20 types of financial entities and, for the first time, placing critical ICT third-party providers under direct EU oversight. It rests on five pillars: ICT risk management, incident reporting, resilience testing, third-party risk, and information sharing. This guide explains what DORA is, who it covers, what the five pillars require, how it differs from NIS2, and what financial entities should do now.
What DORA Actually Is
A Regulation for Financial-Sector Resilience
DORA, Regulation (EU) 2022/2554, is the EU's dedicated law on the digital operational resilience of the financial sector. Its purpose is to make sure financial firms can withstand, respond to, and recover from all types of ICT-related disruption and threats, from cyberattacks to outages at a key technology supplier. It consolidates and harmonizes rules that were previously scattered across different EU and national frameworks.
A Regulation, Not a Directive
Unlike NIS2, DORA is a regulation, so it applies directly and uniformly across all member states without national transposition. That means a bank in Dublin and a payment firm in Madrid face the same DORA text, supplemented by detailed technical standards. The ESMA DORA page sets out the regulation and the technical standards that sit beneath it.
Why It Exists
The financial sector runs on technology and on a small number of shared providers, especially for cloud services. A serious incident at one provider can ripple across many firms at once. DORA responds by setting a common resilience baseline and, crucially, by giving regulators direct oversight of the critical technology suppliers the sector depends on.
Who DORA Covers
Around 20 Types of Financial Entity
DORA applies to almost the entire EU financial sector: banks, insurers and reinsurers, investment firms, payment and electronic-money institutions, crypto-asset service providers, trading venues, fund managers, and more, around 20 categories in total. Proportionality applies, so the depth of obligation scales with the size and risk profile of the entity, but the core duties reach widely.
Critical ICT Third-Party Providers
DORA's most novel feature is that it reaches beyond financial firms to the technology providers that serve them. ICT providers designated as critical, which includes major cloud and software vendors, fall under a direct EU oversight framework run by the European Supervisory Authorities. The EIOPA DORA page describes how this oversight of critical third parties works alongside entity-level supervision.
Reach Beyond the EU
Non-EU technology providers are not outside the picture. A cloud or software provider based elsewhere that is critical to EU financial entities can be drawn into the oversight regime, and global firms supplying EU financial clients are adjusting contracts and controls accordingly. As with other EU digital law, the practical reach extends well past the Union's borders.
The Five Pillars of DORA
| Pillar | What it requires |
|---|---|
| 1. ICT risk management | A governed framework covering the full lifecycle: identify assets and risks, protect and prevent, detect, respond and recover, learn, and communicate, owned by the management body. |
| 2. Incident management and reporting | Classify ICT incidents and report major ones to regulators on a standardized timeline, so authorities can see and respond to systemic risk. |
| 3. Digital operational resilience testing | Test resilience regularly, with advanced threat-led penetration testing for the most significant entities, carried out by independent parties. |
| 4. ICT third-party risk management | Maintain a documented third-party framework, a register of ICT arrangements, and contractual safeguards; critical providers face direct EU oversight. |
| 5. Information and intelligence sharing | Voluntarily share cyber-threat information and intelligence with peers to strengthen collective resilience across the sector. |
The pillars are designed to work together: risk management sets the foundation, incident reporting and testing prove it works, third-party rules extend it across the supply chain, and information sharing lifts the whole sector. ENISA's Threat Landscape explains why this layered approach matters, with the financial sector among the most targeted by ransomware and supply-chain attacks.
DORA vs NIS2: How They Differ
Sector-Specific vs Cross-Sector
NIS2 is a broad, cross-sector cybersecurity directive covering 18 sectors; DORA is a deep, finance-only resilience regulation. Where both could apply, DORA generally takes precedence for financial entities as the more specific law, a relationship known as lex specialis. Firms that map ISO/IEC 27001 to NIS2 can reuse much of that work for DORA, then add the finance-specific testing and third-party rules.
Directive vs Regulation
NIS2 is a directive that each country writes into national law, with some local variation; DORA is a regulation that applies directly and identically across the EU. For a financial group operating in several member states, DORA brings welcome consistency, while NIS2 obligations can differ country by country.
Third-Party Oversight
Both regimes care about supply-chain risk, but DORA goes further by creating direct EU oversight of critical ICT providers to finance, something NIS2 does not do. For the major cloud and software firms, DORA is the regime that brings them into a financial-regulator relationship for the first time.
What Financial Entities Should Do Now
Complete the Register and Gap Assessment
Because DORA already applies, the priority is to close gaps, not to plan for a future deadline. That means a complete register of ICT third-party arrangements, a gap assessment against the five pillars, and remediation of the highest-risk items, especially around incident classification and contractual safeguards with key providers.
Build Board and Management Capability
DORA makes the management body explicitly accountable for ICT risk, so board and executive cyber literacy is now a supervisory expectation. Structured programs across cybersecurity and digital transformation help senior teams own the framework, the reporting workflow, and the resilience-testing program with confidence.
Operationalize Testing and Reporting
Resilience testing and incident reporting only protect the firm if they are rehearsed. Standing up the testing calendar, the incident-classification logic, and the reporting path before a real event is the difference between a controlled response and a scramble. Many firms align this with their wider enterprise risk and training programs so resilience is owned across functions, not just by IT.
DORA reframes operational resilience as a board-level, sector-wide responsibility: not just keeping systems running, but being able to prove to a regulator that the firm and its critical suppliers can withstand and recover from the next major disruption.
Frequently Asked Questions
When did DORA come into effect?
DORA entered into force on 16 January 2023 and has applied since 17 January 2025. Because the application date has passed, financial entities are now expected to be compliant, not preparing for a future deadline.
Who has to comply with DORA?
Around 20 types of EU financial entity, including banks, insurers, investment firms, payment and e-money institutions, and crypto-asset service providers, plus critical ICT third-party providers that serve them, which fall under direct EU oversight.
What are the five pillars of DORA?
ICT risk management; ICT incident management and reporting; digital operational resilience testing; ICT third-party risk management; and information and intelligence sharing. Together they form the resilience framework financial entities must implement.
What is the difference between DORA and NIS2?
NIS2 is a broad cross-sector cybersecurity directive; DORA is a finance-specific operational-resilience regulation that applies directly across the EU. For financial entities, DORA generally takes precedence as the more specific law and adds direct oversight of critical ICT providers.
Does DORA apply to non-EU technology providers?
It can. A non-EU ICT provider that is critical to EU financial entities can be brought into DORA's oversight framework, and global providers serving EU financial clients are adjusting contracts and controls to meet the requirements.
Make Operational Resilience a Board-Level Strength
EuroQuest International delivers cybersecurity, risk, and digital-transformation programs for boards, resilience leaders, and the teams that support them. Build the ICT risk, incident-reporting, testing, and third-party governance capability DORA now expects across the financial sector.
Browse EuroQuest Training Categories