European Regulation

DORA · Digital Operational Resilience

The regulation that requires the financial sector to ensure its digital operational resilience against cyberattacks and technology failures.

Published: December 27, 2022 Entry into force: January 16, 2023 Application date: January 17, 2025 Applies to: Financial entities within its scope + oversight framework for designated critical ICT providers

What is DORA?

The DORA Regulation (Digital Operational Resilience Act) is the European regulatory framework that establishes uniform requirements for the digital operational resilience of the financial sector. Its goal is to ensure that financial entities can prevent, respond to and recover from ICT-related incidents.

DORA applies directly in all Member States without requiring national transposition, meaning its requirements are enforceable from its application date. DORA has applied directly since January 17, 2025 to financial entities within its scope. Regarding third-party ICT providers, DORA also establishes a specific risk management regime for financial entities and a direct oversight framework for providers designated as critical.

Key change: DORA introduces an integrated approach to ICT risk management covering the entire value chain, including external providers. Financial entities remain responsible for complying with their DORA obligations when using third-party ICT services and must manage the associated risk.

Who does it apply to?

DORA applies to financial entities within its scope and also establishes a European oversight framework for third-party ICT providers designated as critical:

  • Financial entities: Banks, payment institutions, e-money institutions, asset managers, investment funds, insurers, reinsurers.
  • Critical ICT providers: Cloud service providers, data platforms, security services, digital infrastructure.
  • Financial market infrastructure entities: Exchanges, clearing and settlement systems.

Key deadlines

  • January 16, 2023: Entry into force of Regulation (EU) 2022/2554 at the European level.
  • January 17, 2025: DORA becomes applicable to financial entities within its scope, and the regulatory framework for third-party ICT risk management and oversight of designated critical ICT providers takes effect.
Important: DORA is a directly applicable regulation in all 27 Member States, without requiring national transposition. It has been enforceable since January 17, 2025.

DORA's penalty regime

DORA (Regulation EU 2022/2554) establishes a differentiated penalty regime:

  • Financial entities: The penalty regime refers to each Member State's national legislation (art. 50). In Spain, the competent authorities (Banco de España, CNMV, DGSFP) will apply the infringement and penalty regime of the corresponding sector-specific regulation.
  • Designated critical ICT providers: ESMA, EBA and EIOPA, upon proposal by the competent authorities, may impose periodic penalty payments of up to 1% of average daily worldwide turnover for a maximum period of 6 months (art. 35.8).

Additional measures: Competent authorities may require corrective measures, restrict activities or demand management changes at infringing entities.

What does DORA require?

Entities must implement a comprehensive digital operational resilience framework:

  • ICT risk management: Risk management framework integrated into overall governance.
  • Incident management: Processes for detecting, responding to and reporting ICT incidents.
  • Resilience testing: Periodic testing, including TLPT (Threat-Led Penetration Testing) for critical entities.
  • Provider management: Continuous assessment and oversight of critical ICT providers.
  • Information sharing: Participation in cyber threat information-sharing mechanisms.
  • Incident register: Detailed record of ICT incidents and their impact.

How can I help you with DORA?

DORA GAP Audit

We assess your current compliance level, identify gaps and design an action plan to achieve compliance.

View service →

DORA Management System Implementation

We implement all measures required by DORA, including policies, procedures, resilience testing and provider management.

View service →

TLPT and Tabletop Exercises

We design and lead advanced resilience tests, including TLPT and crisis simulations for your Management Committee.

View service →

Do you need to prepare your entity for DORA?

Request an assessment meeting →

20–30 minutes · No commitment · We review context, need and next steps.