We use a few strictly-necessary cookies, no marketing trackers, and cookieless analytics. Read our cookie policy, or pick a preference.
The EU's rulebook for keeping the financial system running when its technology fails. DORA makes digital operational resilience a board-level duty for financial entities, and pulls their critical technology suppliers, cloud and AI included, under direct EU oversight for the first time.
DORA treats technology failure as a systemic risk to finance and builds a single resilience regime across the sector. Four of its five pillars carry direct obligations: an ICT risk-management framework, the classification and reporting of major ICT incidents, a testing programme, and the management of third-party ICT risk. The fifth encourages voluntary threat-intelligence sharing.
Its sharpest innovation is reaching past the regulated firm to its suppliers. Critical ICT third-party providers, the large cloud and, increasingly, AI vendors the sector depends on, come under direct EU oversight. For AI in finance, models are ICT systems inside the framework, and model vendors are third parties you must map, monitor, and be able to exit.
A documented framework the management body owns: identify, protect, detect, respond, recover, and learn.
Classify major ICT-related incidents against set criteria and report them to the competent authority on a defined clock.
A regular testing programme, with threat-led penetration testing for the most significant entities.
A register of information, concentration-risk limits, exit strategies, and oversight of critical providers.
Under DORA, the management body bears ultimate responsibility for managing the entity's ICT risk. It must define, approve, and oversee the ICT risk-management framework, set the entity's risk tolerance, and review the arrangements regularly, and its members must keep sufficient knowledge and skills to understand ICT risk, through ongoing training. Responsibility for resilience sits with named individuals at the top of the firm, not with the technology function alone.
DORA is fully in force. The current phase is the build-out of the critical-provider oversight regime and the first supervisory cycles.
Regulation enters into force, with a two-year implementation window.
DORA applies in full across EU financial entities.
The ESAs designate and begin overseeing critical ICT third-party providers.
Source: Official Journal of the EU · DORA regulatory and implementing technical standards · confirm the current RTS/ITS before relying on detail
DORA covers financial entities broadly, and for the first time reaches the technology providers they depend on.
Nearly the whole regulated sector, plus crypto-asset service providers. Each runs the full five-pillar programme, proportionate to size and risk.
Own the ICT risk framework, set risk tolerance, and maintain the skills to oversee it, under Article 5.
Designated cloud and technology providers, coming under direct oversight by the European Supervisory Authorities.
National regulators supervise entities; the ESAs run the pan-EU oversight of critical providers.
DORA leaves administrative penalties on financial entities to national law, while giving the ESAs a direct tool against critical providers.
| Against | Exposure |
|---|---|
| Nationalset by each authority | Financial entities face effective, proportionate, and dissuasive administrative penalties set by their competent authority, plus remediation orders. |
| 1% / dayup to six months | Critical ICT third-party providers face periodic penalty payments of up to 1% of average daily worldwide turnover, imposed by the ESAs to compel compliance. |
Figures per DORA Articles 35 and 50 · national penalty regimes vary · confirm the applicable rules locally
"Our cloud provider is responsible for our resilience."
DORA keeps the accountability with you. You must maintain a register of ICT third parties, manage concentration risk, and hold a tested exit strategy for each critical dependency.
"Operational resilience is an IT and operations matter."
Article 5 makes the management body own the ICT risk framework and keep the skills to oversee it. It is a board-level, personally-held duty.
"We run an annual penetration test, so testing is covered."
DORA requires a full testing programme, and threat-led penetration testing on a multi-year cycle for the most significant entities, going well beyond a routine annual test.
A bank meets DORA, NIS2, the GDPR, and the AI Act on the same high-risk system. We map at the level of the obligation, so one resilience programme answers several regimes at once.