AuditXYZ

Compliance Framework

Regulation (EU) 2022/2554 — Digital Operational Resilience Act (DORA)

DORA establishes ICT risk management and resilience requirements for EU financial entities. Learn how to comply with this regulation covering testing, incidents, and third-party risk.

$50,000–$500,0006–24 monthsAudit Required2022
Issuing BodyEuropean Parliament and Council of the European Union
First Published2023-01-16
Latest Version2022
Typical Cost$50,000–$500,000
Typical Timeline6–24 months
Audit RequiredYes
Audit FrequencyOngoing supervisory oversight. Threat-led penetration testing (TLPT) required every 3 years for significant entities.
Geographyeuropean-union, eea

DORA: Digital Operational Resilience Act Guide

The Digital Operational Resilience Act (DORA) is an EU regulation that establishes a comprehensive framework for digital operational resilience across the financial sector. Effective from January 2025, DORA ensures financial entities can withstand, respond to, and recover from ICT-related disruptions and threats.

What DORA Covers

DORA is built on five pillars:

ICT Risk Management — Financial entities must establish and maintain a comprehensive ICT risk management framework including identification, protection, detection, response, and recovery capabilities.

ICT-Related Incident Management — Entities must classify, manage, and report major ICT-related incidents. Significant cyber threats must also be reported on a voluntary basis.

Digital Operational Resilience Testing — Regular testing of ICT systems including vulnerability assessments, network security tests, and for significant entities, advanced threat-led penetration testing (TLPT) at least every three years.

ICT Third-Party Risk Management — Comprehensive management of risks from ICT third-party service providers, including mandatory contractual provisions, concentration risk monitoring, and exit strategies.

Information Sharing — Voluntary frameworks for sharing cyber threat intelligence among financial entities.

Who DORA Affects

DORA applies to virtually all regulated financial entities in the EU: credit institutions, payment institutions, investment firms, insurance companies, pension funds, crypto-asset service providers, crowdfunding providers, and more. Critically, it also applies to critical ICT third-party service providers (CTPPs) serving these entities — including cloud providers, data analytics firms, and software vendors.

Compliance Approach

  1. Gap assessment — Map current ICT risk management practices against DORA requirements
  2. ICT risk framework — Establish or enhance your ICT risk management framework
  3. Incident management — Implement incident classification, escalation, and reporting processes
  4. Testing program — Design a resilience testing program meeting DORA's tiered requirements
  5. Third-party register — Create and maintain a register of all ICT third-party arrangements
  6. Contract remediation — Update third-party contracts to include DORA-mandated provisions
  7. Board governance — Ensure management body oversight and accountability for ICT risk

Key Differences from Existing Regulation

DORA harmonizes digital resilience requirements across EU financial services, replacing the patchwork of national guidelines. Its direct applicability as a regulation (not a directive) means consistent requirements across all member states without transposition differences.

The Five DORA Pillars in Detail

ICT Risk Management Framework — DORA requires financial entities to establish a comprehensive ICT risk management framework covering: ICT governance and organization; ICT strategy aligned with business strategy; ICT risk tolerance definition; ICT asset management; ICT risk identification and assessment; protection and prevention measures; detection of anomalous activities; response and recovery capabilities; and communication with stakeholders. The framework must be reviewed at least annually and after major incidents.

ICT-Related Incident Management — Entities must establish incident management processes with defined classification criteria. DORA defines major incidents by specific impact thresholds (users affected, geographic scope, economic impact). Reporting timelines are strict: an initial notification within 4 hours of classifying an incident as major, an intermediate report within 72 hours, and a final report within one month. The European Supervisory Authorities (ESAs) have published regulatory technical standards (RTS) specifying exact classification criteria.

Digital Operational Resilience Testing — Testing requirements are tiered by entity size and systemic importance. All financial entities must conduct basic vulnerability assessments annually. Significant entities must additionally conduct threat-led penetration testing (TLPT) every three years. TLPT must follow the TIBER-EU framework or an equivalent recognized framework and be performed by certified external testers with controlled red team conditions. No other penetration testing methodology satisfies the TLPT requirement.

ICT Third-Party Risk Management — DORA imposes detailed requirements on how financial entities manage ICT third-party providers. These include: pre-engagement due diligence; mandatory contractual provisions covering audit rights, exit strategies, security standards, and data location; ongoing monitoring of provider risk; concentration risk management (limiting systemic dependence on single providers); and register maintenance covering all ICT arrangements.

Information Sharing — Financial entities may voluntarily participate in information sharing arrangements to share cyber threat intelligence with peers. The ESAs support and encourage these arrangements as a collective defense mechanism.

Critical Third-Party Provider Designation

A distinctive feature of DORA is its extraterritorial reach to ICT service providers. The ESAs can designate ICT third-party providers as Critical Third-Party Providers (CTPPs) based on the systemic importance of their services to the EU financial sector. Designated CTPPs are subject to direct oversight by a lead ESA, including annual supervisory fees and inspection rights.

Cloud providers, financial market data providers, and software vendors serving significant portions of EU financial infrastructure are candidates for CTPP designation. If your company provides ICT services to EU financial institutions, you may face DORA oversight indirectly through your customers' contractual requirements or directly as a CTPP.

The Contractual Requirements for ICT Providers

Even for non-designated providers, DORA's contractual provisions are significant. Financial entities cannot engage ICT providers without contracts that include:

  • Clear description of services and service levels with measurable performance metrics
  • Provisions for change notification and management
  • Data location requirements and restrictions on sub-processing
  • Cooperative assistance in incident management
  • Right-to-audit and information access for the financial entity and its competent authorities
  • Termination rights and exit assistance provisions
  • Penalties or remedies for service failures

If your company sells ICT services to EU financial entities, expect your customers to require DORA-compliant contract provisions before or at renewal.

Costs and Timeline

ComponentLow EstimateHigh Estimate
Gap assessment against DORA requirements$15,000$50,000
ICT risk framework development$20,000$80,000
Incident management process$10,000$30,000
Testing program design$10,000$30,000
ICT third-party register and contracts$15,000$60,000
TLPT (every 3 years)$30,000$150,000
Total first-year (excluding TLPT)$70,000$250,000

Timeline: 6 to 24 months. Larger institutions with many ICT third parties face the longest implementations due to contract remediation work.

DORA vs. NIS2 — Financial entities subject to DORA satisfy NIS2's more general cybersecurity requirements through DORA compliance. Where DORA and NIS2 requirements overlap, DORA's more specific sector-level requirements take precedence (lex specialis). See /frameworks/security-governance/nis2.

DORA vs. ISO 27001 — Approximately 60% overlap. ISO 27001 covers information security management; DORA covers ICT operational resilience with specific financial sector regulatory obligations. ISO 27001-certified financial entities have a strong foundation but need DORA-specific additions around testing, third-party risk, and incident reporting timelines.

DORA vs. ISO 22301 — About 55% overlap. ISO 22301 addresses business continuity management broadly; DORA's resilience requirements are specifically ICT-focused and more prescriptive for EU financial entities. ISO 22301 provides a certifiable business continuity framework that supports DORA compliance without fully substituting for it.

How Automation Helps

DORA's ongoing requirements — ICT third-party register maintenance, continuous monitoring, incident classification and reporting, and testing program evidence — are operationally intensive without automation. The strict notification timelines (4 hours for initial major incident notification) make manual incident management processes a compliance liability.

LowerPlane supports DORA compliance monitoring across its 50-plus framework library, providing ICT risk framework documentation, third-party risk tracking, and incident management workflow support. At $4,000/year entry pricing with a free tier, it is accessible for smaller in-scope entities as well as large institutions. AuditXYZ rates it 9.4/10. Compare at Best Compliance Automation Platforms.

Frequently Asked Questions

When did DORA become effective? DORA became applicable on January 17, 2025. The regulation was published in December 2022 and provided a two-year implementation period. Financial entities were expected to be compliant from January 17, 2025. Regulatory technical standards from the ESAs providing detailed implementation guidance were published throughout 2024.

Does DORA apply to non-EU financial entities? DORA applies to financial entities operating in the EU, regardless of where they are headquartered. A U.S. bank operating EU branches, or a payment institution serving EU customers through an EU-authorized entity, is subject to DORA. The regulation also reaches ICT providers through its third-party risk management requirements.

What is threat-led penetration testing (TLPT) and who can perform it? TLPT is an advanced red team exercise that tests financial entities against realistic threat actor tactics, techniques, and procedures. It must follow the TIBER-EU framework or an equivalent recognized methodology. External testers must be certified against applicable standards (CREST, PTES, or similar). Internal testers may participate in limited roles. TLPT is required every three years for significant financial entities identified by competent authorities.

How does the ICT third-party register work? Financial entities must maintain a register of all ICT third-party arrangements, containing the service provided, classification (critical or important vs. non-critical), contractual terms, concentration risk information, and monitoring status. The register must be available to competent authorities on request. The ESAs specify the exact fields required in the register format through implementing technical standards.

Request a DORA consultation

Step 1 of 520%

Which framework do you need?

Framework Mappings

Overlap with other frameworks

ISO 27001Medium60%
ISO 22301Medium55%
NIS2Medium50%

Get matched with a DORA auditor in 24 hours

Free, no-obligation — just tell us your email and we'll do the rest.

By submitting, you agree to our privacy policy.