DORA

Henry Bewicke Author Profile Headshot
Written byHenry Bewicke
October 8, 2026

The Digital Operational Resilience Act (DORA) is a European regulatory framework designed to strengthen IT security and operational resilience across financial entities. The regulation became fully applicable across all EU member states on 17 January 2025, directing financial organisations to official supervisory publications for specific statutory rules and requirements.

What is the Digital Operational Resilience Act (DORA)?

DORA introduces harmonised European rules for financial organisations managing technology risks. Technological systems now underpin everyday operations across banking, payments, and investments, making digital reliability a regulatory priority.

For complete statutory definitions, scoping criteria, and technical requirements, organisations should consult official European regulatory publications.

Who needs to comply with DORA?

The framework covers a wide range of regulated entities, including:

  • Credit institutions, investment firms, and credit rating agencies
  • Payment institutions and electronic money institutions governed under frameworks like PSD2
  • Insurance and reinsurance undertakings, as well as insurance intermediaries
  • Crypto-asset service providers (CASPs) and issuers of asset-referenced tokens
  • Alternative investment fund managers (AIFMs) and UCITS management companies
  • Central counterparties, trading venues, and central securities depositories

Organisations should consult the official regulatory text for complete scoping rules.

The 5 pillars of DORA regulation

DORA is structured around five functional pillars that govern how organisations design, test, and maintain their technological defences.

ICT risk management framework

Financial entities must maintain an ICT risk management framework as part of their broader risk management system. This framework requires organisations to identify critical business functions and map the information assets and network architectures that support them. Firms must implement security controls, continuous network monitoring tools, and backup mechanisms to minimise the operational impact of disruptions.

DORA establishes a harmonised classification system and reporting mechanism for ICT-related incidents. Under DORA, whether an incident affects critical functions is an initial classification criterion, but it is categorised as a major incident only if specific quantitative impact thresholds under Delegated Regulation (EU) 2024/1772 are also met.

Under Commission Delegated Regulation (EU) 2025/301, financial entities must submit an initial notification of a major incident within 4 hours of classification. This is followed by an intermediate report within 72 hours of the initial notification, followed by a final root-cause analysis report once the incident is resolved or according to regulatory standards.

Digital operational resilience testing

Testing helps financial entities verify that their defences function as intended. DORA requires financial entities, other than microenterprises, to ensure at least yearly that appropriate tests are conducted on all ICT systems and applications supporting critical or important functions.

Financial entities identified by competent authorities are also subject to threat-led penetration testing (TLPT) requirements, with testing frequencies and scope defined in official regulatory standards. These exercises evaluate how live systems respond to simulated cyber incidents.

Management of ICT third-party risk

DORA places clear controls on the financial sector's reliance on external technology vendors. Financial entities must maintain a Register of Information documenting all contractual arrangements with ICT third-party service providers.

European Supervisory Authorities can impose periodic penalty payments on Critical ICT Third-Party Service Providers to compel adherence, with specific thresholds and enforcement procedures set out in official supervisory documentation. Financial entities and vendors should review regulatory technical standards for specific contract compliance guidelines.

Information and intelligence sharing

The final pillar encourages financial institutions to exchange cyber threat intelligence and defensive indicators with one another. DORA establishes trusted arrangements for exchanging threat information within closed financial communities while adhering to privacy and competition standards, helping organisations strengthen collective sector resilience.

Does DORA apply in the UK?

DORA is a European Union regulation rather than domestic UK legislation. However, cross-border financial operations mean that if your organisation operates across borders, you will frequently interact with its rules.

If your UK financial group operates licensed subsidiaries or branches across EU member states, you must ensure those European entities achieve full DORA compliance. Similarly, if you are a UK technology supplier providing services to EU financial institutions, you must accommodate European contractual requirements, as EU institutions cannot use non-compliant third-party contracts.

Domestically, we operate under the UK's own operational resilience regime supervised by the Financial Conduct Authority (FCA) and the Prudential Regulation Authority (PRA). The transition period for UK operational resilience rules under FCA PS21/3 and PRA SS1/21 concluded on 31 March 2025, requiring firms to operate within defined impact tolerances for their important business services.

Alongside this, UK rules under FCA PS24/16 and PRA PS16/24 took effect on 1 January 2025 for designated critical third parties. UK regulators and European authorities have established arrangements, including a Memorandum of Understanding, to coordinate third-party oversight frameworks despite regulatory divergence.

Key requirements for DORA compliance

Achieving and maintaining compliance requires coordinated oversight across your finance, risk, legal, and IT teams:

  • Review governance structures: Align internal risk management policies and governance arrangements with published official regulatory guidelines.
  • Compile vendor registers: Maintain an accurate Register of Information detailing contractual arrangements with external ICT service providers.
  • Update third-party contracts: Ensure contractual arrangements for ICT services incorporate mandatory contractual provisions governing service standards and operational rights, with specific additional requirements for ICT services supporting critical or important functions.
  • Establish rapid reporting workflows: Configure your incident detection and response workflows to submit notifications for major incidents within the required 4-hour window once classified.
  • Schedule resilience testing: Establish annual testing routines across critical systems, and prepare for threat-led penetration testing where designated by your supervisory authorities.

FAQs

Henry Bewicke Author Profile Headshot

Written by

Henry Bewicke

Having written for clients inluding the World Economic Forum and Harvard University Press, Henry has spent the last six years in the world of b2B SaaS. As Moss's Senior Content Manager he now writes about the tools and trends reshaping how modern finance teams work.