Skip to main content

DORA Digital Operational Resilience Act.

DORA is the EU regulation that imposes a unified resilience framework on financial entities and their critical ICT providers. Five pillars: ICT risk management, incident reporting, resilience testing including TLPT, third-party ICT risk, information-sharing. Applicable since 17 January 2025. It bites harder than NIS 2 on the ICT angle, and lex specialis means it wins for financial entities.

By Christophe Mazzola, Practicing CISO · Founder of Cyber AcademyEU regulationsAll entries

The Cyber Academy take

DORA is the EU regulation that imposes a unified resilience framework on financial entities and their critical ICT providers. Five pillars: ICT risk management, incident reporting, resilience testing including TLPT, third-party ICT risk, information-sharing. Applicable since 17 January 2025. It bites harder than NIS 2 on the ICT angle, and lex specialis means it wins for financial entities.

Why DORA exists and who it binds

Before DORA, digital operational resilience for financial entities in the EU was a patchwork. Banks answered to one set of supervisory expectations, insurers to another, and the rules on ICT incidents, outsourcing, and testing varied by sector and by member state. DORA replaces that fragmentation with a single regulation that applies directly across the Union, no national transposition required. Its scope is deliberately wide: banks, insurers, investment firms, payment and e-money institutions, crypto-asset service providers, trading venues, and many more, plus the critical ICT third-party providers those entities depend on.

That last point is what makes DORA different from a normal financial rule. It does not only regulate the supervised firms; it reaches into their supply chain. Cloud providers, data centre operators, and software vendors that are deemed critical to the financial system can be placed under direct oversight at EU level. For a practitioner, the practical consequence is that resilience is no longer something you can fully outsource and forget. You remain accountable for the ICT risk your providers carry, and you have to prove it.

The five pillars in practice

DORA is built on five pillars, and each one translates into concrete programme work rather than paperwork:

  • ICT risk management. A governance framework owned by the management body, covering identification, protection, detection, response, and recovery for ICT assets. This is the backbone the other four pillars hang from.
  • Incident management and reporting. Classify ICT-related incidents by severity, and report the major ones to the competent authority on a defined timeline. The emphasis is on a harmonised taxonomy so supervisors across the EU see comparable data.
  • Digital operational resilience testing. A regular testing programme that ranges from vulnerability assessments up to threat-led penetration testing (TLPT) for the most significant entities, modelled on real adversary behaviour.
  • ICT third-party risk management. Contractual safeguards, registers of information on all ICT arrangements, exit strategies, and the oversight regime for critical third-party providers.
  • Information sharing. Voluntary exchange of cyber threat intelligence between financial entities, encouraged rather than mandated, to raise collective defence.

DORA next to NIS 2

The question practitioners ask most is how DORA relates to NIS 2, since both are EU instruments touching cybersecurity and both reach roughly the same maturity bar. The short answer is lex specialis: where DORA and NIS 2 would both apply to a financial entity on the ICT angle, DORA prevails because it is the more specific rule. NIS 2 sets a broad cybersecurity baseline across many sectors; DORA goes deeper on the financial sector's ICT resilience and adds the third-party oversight regime NIS 2 does not have.

DORA compared to NIS 2
DimensionDORANIS 2
Instrument typeRegulation, directly applicableDirective, transposed by member states
Primary scopeFinancial entities and their critical ICT providersEssential and important entities across many sectors
FocusDigital operational resilience of the financial systemGeneral cybersecurity risk management and reporting
Third-party oversightDirect EU oversight of critical ICT providersSupply chain security expected, no direct oversight regime
Precedence for financeWins as lex specialis on the ICT angleYields to DORA where both would apply

In day-to-day terms, a bank does not get to pick one. It maps its obligations and finds that for ICT risk, incident reporting, and resilience testing, DORA is the controlling text, while NIS 2 may still matter for parts of the group that fall outside DORA's financial scope. The clean way to run this is a single control framework, often anchored on ISO 27001 and ISO 22301, that satisfies both regimes and lets you evidence compliance once.

Frequently asked questions

01When did DORA become applicable?

DORA has applied since 17 January 2025. As an EU regulation it took effect directly, without needing national transposition, so the date is the same across all member states.

02Does DORA apply to my cloud provider?

It can. ICT third-party providers judged critical to the financial system can be designated and placed under direct EU oversight. Even where a provider is not designated, the financial entity that uses it remains accountable for the ICT risk under DORA's third-party pillar.

03How is DORA different from NIS 2?

NIS 2 is a broad cybersecurity directive across many sectors, transposed nationally. DORA is a directly applicable regulation specific to financial entities, deeper on ICT resilience and third-party oversight. For financial entities, DORA wins on the ICT angle as lex specialis.

04What is TLPT under DORA?

Threat-led penetration testing is advanced, intelligence-driven testing that mimics real adversary tactics against live systems. DORA requires it periodically for the most significant financial entities as the top tier of its resilience testing pillar.

05Does DORA replace business continuity work?

No, it reinforces it. DORA's focus on staying operational under stress, with recovery and continuity for critical functions, sits naturally alongside business continuity management and the ISO 22301 standard rather than replacing them.

Need more than a definition?

Book a free 20-minute discovery call. We map the cohort that turns this term into an audit-ready practice.