DORA compliance

DORA compliance,
pillar by pillar.

The Digital Operational Resilience Act sets one ICT risk rulebook for the EU financial sector, and reaches every software and cloud provider that serves it through contracts. This guide explains who is covered and what each pillar asks. General guidance, not legal advice. TryTrustable does not model DORA as a framework; this page is a guide only.

Regulation (EU) 2022/2554Applies since 17 Jan 2025ICT riskIncident reportingTLPTRegister of information

Last updated Published by TryTrustableNot legal advice

Short answer

DORA compliance means meeting the EU Digital Operational Resilience Act, Regulation (EU) 2022/2554, which has applied directly in every member state since 17 January 2025. It covers banks, payment and e-money institutions, investment firms, insurers, crypto-asset service providers and other financial entities. They must run an ICT risk management framework owned by the management body, classify and report major ICT incidents on fixed deadlines, test their resilience (including threat-led penetration testing for some), manage ICT third-party risk with a register of information, and share threat information. Critical ICT providers are overseen directly by the EU supervisory authorities.

01

What is DORA?

The Digital Operational Resilience Act is Regulation (EU) 2022/2554. As a regulation it applies directly in every member state without national transposition, and it has applied since 17 January 2025. It is supported by regulatory and implementing technical standards that set out the detail, such as the incident reporting deadlines and the register of information templates.

DORA's aim is that a financial entity can withstand, respond to and recover from ICT disruption, whether the cause is a cyberattack, a failed change or the outage of a cloud provider. Where DORA applies, its ICT risk and incident rules take precedence over the general NIS2 requirements for the same entities.

02

Who does DORA apply to?

Article 2 lists twenty types of financial entity, including credit institutions, payment institutions, account information service providers, electronic money institutions, investment firms, crypto-asset service providers, central securities depositories, central counterparties, trading venues, managers of alternative investment funds, UCITS management companies, insurance and reinsurance undertakings and intermediaries, occupational pension institutions, credit rating agencies, administrators of critical benchmarks and crowdfunding service providers. It also covers ICT third-party service providers, which are subject to the oversight framework if designated as critical.

For SaaS and cloud companies, including US ones: if you sell to EU financial entities, DORA reaches you through their contracts even if you are never designated critical. Expect DORA clauses (Article 30), requests for information for their register, incident notification duties, audit and access rights, participation in their testing, and exit assistance. Our DORA applicability checker gives a first answer.

03

The five pillars of DORA, plus information sharing

PillarArticlesWhat it requires
ICT risk management5 to 16A documented ICT risk management framework, owned by the management body, covering identification, protection, detection, response and recovery, backup, learning and communication
ICT incident management and reporting17 to 23A process to detect, classify and record ICT incidents, and report major ones to the competent authority on fixed deadlines
Digital operational resilience testing24 to 27A risk-based testing programme; threat-led penetration testing (TLPT) at least every three years for entities identified by their authority
ICT third-party risk28 to 30A strategy on ICT third-party risk, a register of information on every ICT contract, pre-contract assessment, mandatory contract terms and exit strategies
Oversight of critical ICT third-party providers31 to 44Designation of critical providers by the European Supervisory Authorities and direct oversight by a Lead Overseer
Information sharing45Voluntary arrangements between financial entities to share cyber threat intelligence

Smaller and less interconnected entities listed in Article 16 follow a simplified ICT risk management framework.

04

DORA ICT risk management requirements

Article 5 puts the management body in charge: it defines, approves and oversees the ICT risk management framework, bears ultimate responsibility for ICT risk, approves the digital operational resilience strategy, and must keep its own ICT risk knowledge up to date. Article 6 requires a sound, comprehensive and well-documented framework within the overall risk management system, protecting information and ICT assets and the physical infrastructure they depend on.

Articles 8 to 14 then set out the working parts: identify and classify ICT assets, functions and dependencies; protect and prevent; detect anomalies; respond and recover with business continuity and disaster recovery plans; back up and restore; learn from incidents; and communicate. A financial entity running ISO 27001 will recognise most of it, but DORA is more prescriptive on governance, ICT business continuity and third-party dependencies. A risk assessment and register is the usual starting point.

05

DORA incident reporting timelines

Financial entities must classify ICT-related incidents using criteria such as clients affected, duration, geographic spread, data losses, criticality of services and economic impact, and report those that are major.

ReportDeadlineSource
Initial notificationWithin 4 hours of classifying the incident as major, and no later than 24 hours after becoming aware of itDelegated Regulation (EU) 2025/301
Intermediate reportWithin 72 hours of the initial notification, updated when regular activities are recoveredDelegated Regulation (EU) 2025/301
Final reportNo later than one month after the latest intermediate reportDelegated Regulation (EU) 2025/301

Reports go to the financial entity's competent authority using the standard templates. Significant cyber threats can be notified voluntarily. If an incident is classified as major later than 24 hours after awareness, the 4-hour clock runs from that classification.

Where personal data is involved, GDPR breach notification under Article 33 runs in parallel. Our incident response plan template is a starting point for the process; add the DORA deadlines and templates to it.

06

Digital operational resilience testing and TLPT

Test typeWhoWhat it involves
Testing programme (Article 25)All financial entities except microenterprises (which test proportionately)Vulnerability assessments and scans, open source analysis, network security assessments, gap analyses, physical security reviews, source code reviews where feasible, scenario-based, performance and end-to-end testing, penetration testing
Yearly testing of critical systemsAll financial entities except microenterprisesICT systems and applications supporting critical or important functions tested at least yearly
TLPT (Article 26)Entities identified by their competent authorityThreat-led penetration testing on live production systems supporting critical or important functions, at least every three years, with scope validated by the authority; ICT providers in scope must take part

TLPT follows regulatory technical standards that build on the European TIBER-EU framework. Article 27 sets requirements for the testers.

07

ICT third-party risk and the register of information

Financial entities stay fully responsible for compliance when they use ICT providers. Article 28 requires a strategy on ICT third-party risk, an assessment before entering a contract, and a register of information on all contractual arrangements for ICT services, distinguishing those that support critical or important functions. Entities report on new arrangements to their competent authority at least yearly and must provide the full register on request. The first registers were collected by the authorities and passed to the European Supervisory Authorities by 30 April 2025.

Article 30 lists the key contractual provisions: a clear description of services and locations, data protection and access, service levels, incident assistance, cooperation with authorities, termination rights and, for critical or important functions, further terms on reporting, business continuity, participation in TLPT, audit rights and exit strategies. Our vendor risk management guide covers the general process of tiering and reviewing suppliers.

08

Oversight of critical ICT third-party providers

The European Supervisory Authorities (EBA, EIOPA and ESMA), acting through their Joint Committee, designate ICT providers as critical based on systemic impact, the importance of the financial entities relying on them, reliance for critical functions, and how hard they are to substitute. Each critical provider gets a Lead Overseer that can request information, run investigations and inspections, and issue recommendations, including on subcontracting. Non-cooperation can bring a periodic penalty payment of up to 1% of the provider's average daily worldwide turnover, imposed daily for up to six months. The ESAs' roadmap set designation and the start of oversight for 2025; check the ESAs' published list for which providers are designated.

09

DORA penalties

For financial entities, DORA does not set a single EU fine. Member states lay down administrative penalties and remedial measures, and may add criminal penalties; competent authorities can require access to documents, carry out inspections and order corrective action, and administrative penalties can be published. The fixed EU-level figure is the periodic penalty payment for critical ICT providers described above.

10

DORA compliance checklist

  1. Confirm you are a financial entity under Article 2, or an ICT provider serving them, and whether the simplified framework applies.
  2. Have the management body approve the ICT risk management framework and resilience strategy.
  3. Map critical or important functions and the ICT assets and providers behind them.
  4. Classify incidents and set up reporting to the 4-hour, 24-hour, 72-hour and one-month deadlines.
  5. Run a testing programme; prepare for TLPT if your authority identifies you.
  6. Build the register of information and bring ICT contracts up to Article 30.
  7. Write exit strategies for providers supporting critical or important functions.
11

Does TryTrustable support DORA?

No. DORA is not a modelled framework in TryTrustable, and we do not claim DORA coverage. Some general capabilities help with work that DORA also asks for: a vendor register with tiers, reviews and evidence on file, a risk register, incident management, and modelled ISO 27001 and NIS2 requirements on a shared control library. The platform does not build a DORA register of information, compute DORA reporting deadlines or run TLPT. If DORA is your primary obligation, use this guide alongside specialist advice.

Questions

The things people ask us

When did DORA come into force?

DORA entered into force in January 2023 and has applied since 17 January 2025. As a regulation it applies directly in every EU member state.

Does DORA apply to SaaS providers?

Indirectly, for most. If you provide ICT services to EU financial entities, they must put DORA terms in your contract, include you in their register of information and may involve you in testing. You are only overseen directly by the EU supervisory authorities if you are designated a critical ICT third-party service provider.

What are the DORA incident reporting deadlines?

An initial notification within 4 hours of classifying an incident as major and no later than 24 hours after becoming aware of it, an intermediate report within 72 hours of the initial notification, and a final report within one month of the latest intermediate report.

What is the DORA register of information?

A register every financial entity keeps of all its contractual arrangements for ICT services from third-party providers, distinguishing those that support critical or important functions. It is reported to the competent authority and used by the EU supervisory authorities to identify critical providers.

What is TLPT under DORA?

Threat-led penetration testing: an intelligence-led test on live production systems supporting critical or important functions. Entities identified by their competent authority must carry it out at least every three years.

What is the difference between DORA and NIS2?

NIS2 is a directive covering many sectors, applied through national laws. DORA is a regulation for the financial sector that applies directly. Where DORA applies, its ICT risk and incident rules take precedence over NIS2's for the same entities.

Does TryTrustable support DORA compliance?

No. DORA is not modelled in the product. TryTrustable models ISO 27001 and NIS2 and has vendor and risk registers that help with related work, but it does not claim DORA coverage.

Book a walkthrough

Selling to EU financial institutions?

Thirty minutes on the ISO 27001 and NIS2 controls, vendor register and evidence your financial customers will ask about. We will be clear about what is not covered.