The Cyber Academy take
DORA is the EU regulation that imposes a unified resilience framework on financial entities and their critical ICT providers. Five pillars: ICT risk management, incident reporting, resilience testing including TLPT, third-party ICT risk, information-sharing. Applicable since 17 January 2025. It bites harder than NIS 2 on the ICT angle, and lex specialis means it wins for financial entities.
Why DORA exists and who it binds
Before DORA, digital operational resilience for financial entities in the EU was a patchwork. Banks answered to one set of supervisory expectations, insurers to another, and the rules on ICT incidents, outsourcing, and testing varied by sector and by member state. DORA replaces that fragmentation with a single regulation that applies directly across the Union, no national transposition required. Its scope is deliberately wide: banks, insurers, investment firms, payment and e-money institutions, crypto-asset service providers, trading venues, and many more, plus the critical ICT third-party providers those entities depend on.
That last point is what makes DORA different from a normal financial rule. It does not only regulate the supervised firms; it reaches into their supply chain. Cloud providers, data centre operators, and software vendors that are deemed critical to the financial system can be placed under direct oversight at EU level. For a practitioner, the practical consequence is that resilience is no longer something you can fully outsource and forget. You remain accountable for the ICT risk your providers carry, and you have to prove it.
The five pillars in practice
DORA is built on five pillars, and each one translates into concrete programme work rather than paperwork:
- ICT risk management. A governance framework owned by the management body, covering identification, protection, detection, response, and recovery for ICT assets. This is the backbone the other four pillars hang from.
- Incident management and reporting. Classify ICT-related incidents by severity, and report the major ones to the competent authority on a defined timeline. The emphasis is on a harmonised taxonomy so supervisors across the EU see comparable data.
- Digital operational resilience testing. A regular testing programme that ranges from vulnerability assessments up to threat-led penetration testing (TLPT) for the most significant entities, modelled on real adversary behaviour.
- ICT third-party risk management. Contractual safeguards, registers of information on all ICT arrangements, exit strategies, and the oversight regime for critical third-party providers.
- Information sharing. Voluntary exchange of cyber threat intelligence between financial entities, encouraged rather than mandated, to raise collective defence.
DORA next to NIS 2
The question practitioners ask most is how DORA relates to NIS 2, since both are EU instruments touching cybersecurity and both reach roughly the same maturity bar. The short answer is lex specialis: where DORA and NIS 2 would both apply to a financial entity on the ICT angle, DORA prevails because it is the more specific rule. NIS 2 sets a broad cybersecurity baseline across many sectors; DORA goes deeper on the financial sector's ICT resilience and adds the third-party oversight regime NIS 2 does not have.
| Dimension | DORA | NIS 2 |
|---|---|---|
| Instrument type | Regulation, directly applicable | Directive, transposed by member states |
| Primary scope | Financial entities and their critical ICT providers | Essential and important entities across many sectors |
| Focus | Digital operational resilience of the financial system | General cybersecurity risk management and reporting |
| Third-party oversight | Direct EU oversight of critical ICT providers | Supply chain security expected, no direct oversight regime |
| Precedence for finance | Wins as lex specialis on the ICT angle | Yields to DORA where both would apply |
In day-to-day terms, a bank does not get to pick one. It maps its obligations and finds that for ICT risk, incident reporting, and resilience testing, DORA is the controlling text, while NIS 2 may still matter for parts of the group that fall outside DORA's financial scope. The clean way to run this is a single control framework, often anchored on ISO 27001 and ISO 22301, that satisfies both regimes and lets you evidence compliance once.
Frequently asked questions
01When did DORA become applicable?
DORA has applied since 17 January 2025. As an EU regulation it took effect directly, without needing national transposition, so the date is the same across all member states.
02Does DORA apply to my cloud provider?
It can. ICT third-party providers judged critical to the financial system can be designated and placed under direct EU oversight. Even where a provider is not designated, the financial entity that uses it remains accountable for the ICT risk under DORA's third-party pillar.
03How is DORA different from NIS 2?
NIS 2 is a broad cybersecurity directive across many sectors, transposed nationally. DORA is a directly applicable regulation specific to financial entities, deeper on ICT resilience and third-party oversight. For financial entities, DORA wins on the ICT angle as lex specialis.
04What is TLPT under DORA?
Threat-led penetration testing is advanced, intelligence-driven testing that mimics real adversary tactics against live systems. DORA requires it periodically for the most significant financial entities as the top tier of its resilience testing pillar.
05Does DORA replace business continuity work?
No, it reinforces it. DORA's focus on staying operational under stress, with recovery and continuity for critical functions, sits naturally alongside business continuity management and the ISO 22301 standard rather than replacing them.