DORA

DORA for financial services: the pillars of resilience

Explore DORA’s five main areas, its effects on financial entities and ICT suppliers, implementation planning and the overlap with NIS2.

Financial services depend on technology. An outage in a core banking system, payment channel or cloud provider can affect customers and markets within minutes. The Digital Operational Resilience Act (DORA) provides a consistent, directly applicable European framework. This article explains its scope, five main areas, supplier implications and realistic implementation planning.

Who is covered by DORA?

DORA has applied since 17 January 2025 to the financial entities listed in Article 2, subject to the exceptions there. Designated critical ICT providers face a separate direct oversight regime; other suppliers may be affected through their financial clients’ contracts. Relevant entities include:

  • credit institutions, payment and electronic money institutions;
  • investment firms, trading venues and central counterparties;
  • insurers, reinsurers and insurance intermediaries;
  • fund managers, crypto-asset service providers and crowdfunding platforms;
  • ICT third-party providers, such as cloud, data centre and software suppliers, particularly those designated critical.

Unlike NIS2, which requires national transposition, DORA is a regulation applied directly across the EU. It provides sector-specific rules for corresponding NIS2 obligations. This does not exclude every additional national requirement. A scope assessment should establish your position.

What are DORA’s five pillars?

The requirements create a verifiable cycle of governance: identify risks, handle and report incidents, test capabilities and oversee suppliers.

PillarRequirementPractical focus
1. ICT risk managementA management-supervised frameworkAsset inventory, controls and BCP/DRP
2. Incident handling and reportingClassification and regulatory reportingProcesses, deadlines and templates
3. Resilience testingRegular, proportionate testingVulnerability assessment and TLPT
4. Third-party riskSupplier risk management and contractsRegisters and exit strategies
5. Information sharingA framework for voluntary arrangementsSecure exchange of threat information

1. ICT risk management

Use a documented method to identify, assess and treat ICT risks. Maintain asset and dependency inventories, access controls, encryption, logging and continuity and recovery plans. Management accountability is central: senior leaders must approve and oversee the strategy, rather than delegating it entirely to IT.

2. ICT incident handling and reporting

Use a consistent process to classify, manage and report major ICT incidents. Define owners, detection, impact assessment and staged regulatory reporting in advance. A practised scenario makes the response more reliable under pressure.

3. Digital operational resilience testing

DORA requires regular, risk-based testing, including vulnerability assessments, source code analysis and scenario tests. Entities identified by the competent authority under the regulation must also perform Threat-Led Penetration Testing (TLPT). This simulates real adversary techniques on live production systems with required safeguards, extending beyond a conventional penetration test.

4. ICT third-party risk management

The financial entity remains responsible for outsourced services. DORA sets minimum contractual terms, information register requirements, concentration risk management and exit strategies for ICT services supporting critical or important functions.

5. Voluntary information sharing

The regulation provides a framework for exchanging cyber threat information, with appropriate protection for trade secrets, personal data and competition law requirements.

Digital resilience is an ongoing capability. The requirements provide effective protection when they work together, are tested regularly and receive management oversight.

How does DORA differ from NIS2?

The key differences are legal form and scope. DORA is a directly applicable regulation for financial services; NIS2 is a directive spanning many sectors and requiring national implementation. A financial organisation may fall within both frameworks, but DORA acts as lex specialis for the corresponding financial ICT resilience requirements.

FactorDORANIS2
Legal formDirectly applicable regulationDirective requiring transposition
FocusFinancial sector ICT resilienceBroad range of critical sectors
SuppliersEU oversight of designated critical ICT providersSupply chain security
TestingMandatory, including TLPT for designated entitiesRisk-proportionate requirements
PenaltiesApplied by national authoritiesDepend on classification and national rules

Controls overlap substantially. Existing foundations built through NIS2 preparation can support DORA, although testing and supplier requirements need specific attention.

How does DORA affect suppliers?

Financial entities extend requirements through their ICT supply chains. Contracts must address service levels, audit and access rights, data handling and termination. Designated critical providers also face direct European oversight.

In practice:

  • financial clients request contract changes and compliance evidence;
  • dependence on a single provider must be actively managed;
  • critical outsourcing needs a workable exit strategy.

For providers serving financial clients, readiness can affect market access and contract retention.

How long does preparation take?

Size and maturity determine the effort. In our experience, a structured DORA project typically takes 3–6 months, and longer for major entities subject to TLPT. A practical sequence is:

  1. Clarify applicability and scope.
  2. Assess gaps against the regulation.
  3. Prioritise actions by risk.
  4. Implement controls and documentation, including the framework, incident process and supplier register.
  5. Establish testing, including TLPT where required.
  6. Maintain readiness through reviews, reporting preparations and training.

An existing ISO/IEC 27001 ISMS provides a useful foundation. Many controls can support DORA after explicit mapping to its requirements. Our ISO 27001 implementation guide explains that foundation.

How zemITis helps

Our Budapest-based team supports DORA implementation from scope assessment to testing programme design, with CISA, CISM and ISO 27001 / 42001 Lead Auditor expertise and independent peer review. For ongoing support, our outsourced security officer service can also cover operational resilience. Book a free consultation to discuss your next steps.

Next steps

Strengthen your digital operational resilience.

Bring clarity to ICT risk, incident response and third-party requirements. Let’s discuss your DORA implementation priorities.