DORA for the financial sector: digital operational resilience
Regulation (EU) 2022/2554 harmonises ICT risk management, incident reporting, resilience testing and oversight of critical providers.
DORA — the Digital Operational Resilience Act, Regulation (EU) 2022/2554 — is Europe’s answer to a simple observation: the financial system depends on technology so deeply that a serious IT failure is now a systemic risk, not an operational incident. The regulation applies from 17 January 2025 and is directly binding across the Union, with no national transposition.
The population is broad and deliberately so: banks, insurers, investment firms, asset managers, payment and e-money institutions, trading venues, and even crypto-asset service providers. DORA harmonises into a single body of law requirements that were previously scattered across guidance from different authorities, resting on five pillars.
Governance and ICT risk management
The first pillar requires a comprehensive, documented ICT risk-management framework for which the management body is ultimately responsible — non-delegable. That means an inventory of assets and dependencies, classifying functions by criticality, defining continuity and recovery objectives, and periodically reviewing the framework. DORA insists on one idea: resilience is a leadership responsibility, and leadership must hold enough knowledge to understand and oversee it.
It is worth noting that DORA applies proportionality explicitly: microenterprises and smaller entities follow a simplified framework, while the most significant operators are held to more elaborate requirements. The regulation does not expect a small payment institution and a systemic bank to run the same apparatus, but it does expect both to keep their defences coherent with the risk they take on. Much of the operational detail, moreover, does not live in the regulation text alone: a good part is set out in technical standards (RTS and ITS) drawn up by the European Supervisory Authorities, which are best read alongside the main articles.
Incident reporting: a harmonised format
The second pillar standardises the classification and reporting of ICT-related incidents. Major incidents must be classified against common criteria (number of clients affected, duration, geographic spread, data losses, economic impact) and reported to the competent authority on a staged timeline: an initial notification, an intermediate report on developments, and a final report with root-cause analysis. The aim is to give regulators a comparable, aggregable view at European level, overcoming the fragmentation of formats.
Digital operational resilience testing
The third pillar mandates a risk-proportionate testing programme: vulnerability assessments, security analyses, scenario-based tests. For the most significant operators DORA also introduces Threat-Led Penetration Testing (TLPT), advanced tests based on real threat intelligence conducted under the European TIBER-EU framework, on a periodic basis. This is not a formal box-tick: it is the empirical check that continuity plans and defences actually hold under pressure, not just on paper.
ICT third-party risk
The fourth pillar is perhaps the most innovative. DORA recognises that much of a bank’s operational risk sits outside the bank itself: in the cloud, in software vendors, in managed services. It therefore imposes minimum contractual requirements (access and audit rights, service levels, exit strategies, cooperation during incidents), a register of information on all ICT provider arrangements, and careful management of concentration — because entrusting critical functions to a few large providers creates a shared point of fragility.
On top of this comes an institutional novelty: ICT third-party providers deemed critical at Union level are subject to a direct Oversight Framework run by the European Supervisory Authorities. For the first time a cloud hyperscaler can be supervised as such by the European financial regulator.
Information sharing
The fifth, lighter pillar encourages the exchange of information on threats and indicators of compromise among financial entities, within trusted arrangements and in line with data protection. It is not an obligation, but a recognition that collective resilience exceeds the sum of individual defences.
The practical crux: providers and data
In my experience the point where DORA really bites is provider management. Building the register of information, renegotiating contracts so they carry genuine audit rights and exit strategies, and measuring concentration is long, cross-functional work spanning legal, procurement, risk and technology. It is also the work where a delay shows immediately, because it depends on third parties who do not answer to internal deadlines.
The takeaway
DORA does not ask financial institutions to be invulnerable — it asks them to be resilient: to know what can break, to prove that recovery plans work, and to control the risk they have outsourced without controlling it. It is a shift from perimeter defence to continuity of service, and on that ground paper is not enough: you need evidence.




