Financial resilience regulation
DORA: digital operational resilience for EU financial entities
In short
The Digital Operational Resilience Act (Regulation (EU) 2022/2554), known as DORA, is EU law that requires financial entities to withstand, respond to and recover from ICT-related disruptions. It has applied since 17 January 2025 and standardizes ICT risk management, incident reporting, resilience testing, and oversight of third-party ICT providers across the EU financial sector.
Last reviewed: August 2026
Who it applies to
DORA covers a broad set of financial entities — banks, payment and e-money institutions, investment firms, insurers, crypto-asset service providers, trading venues, fund managers and more — as well as the critical ICT third-party providers that serve them. Proportionality applies: smaller entities face lighter requirements, but the core duties are common.
The five pillars
- ICT risk management — a governance framework owned by the management body
- ICT incident management, classification and reporting to authorities
- Digital operational resilience testing, including threat-led penetration testing (TLPT) for larger entities
- ICT third-party risk management, with a register of information and contractual requirements
- Information and intelligence sharing on cyber threats
Typical compliance challenges
- Building and maintaining the register of information for ICT third-party arrangements
- Meeting standardized incident classification and reporting duties
- Coordinating resilience testing and, for some, TLPT
- Getting the management body genuinely accountable for ICT risk
- Reconciling DORA with existing ISO 27001 and business-continuity (ISO 22301) work
What can reasonably be automated
- The ICT third-party register and continuous supplier monitoring
- Control monitoring and evidence collection for the ICT risk framework
- An incident workflow aligned to DORA’s classification and reporting
- Mapping DORA controls onto ISO 27001 and ISO 22301 to reuse evidence
- A management-body reporting pack for oversight and sign-off
Evidence and documentation
- ICT risk-management framework and policies approved by the management body
- Register of information for ICT third-party arrangements
- Incident classification records and reports to competent authorities
- Resilience-testing plans and results (including TLPT where required)
- Business-continuity and recovery plans and their test evidence
Relationship to NIS2 and ISO 27001
DORA is lex specialis for the financial sector: where it applies, its ICT resilience requirements take precedence over the more general NIS2. A mature ISO 27001 ISMS and ISO 22301 continuity program cover much of the underlying control work, so the practical task is mapping and evidencing, not starting over.
How Isodora supports DORA
Isodora operationalizes DORA’s ICT risk, third-party and incident duties on the same engine that runs your ISO controls.
ICT third-party register
Maintain the register of information and continuously monitor critical ICT providers.
Incident workflow
Classification and reporting steps aligned to DORA, with owners and timelines.
Shared controls
Reuse ISO 27001 and ISO 22301 evidence for DORA’s ICT risk-management framework.
Oversight reporting
A management-body pack so the accountable body can own ICT risk, as DORA requires.
Isodora helps you operationalize DORA’s requirements. Regulatory interpretation, supervisory expectations and TLPT engagements remain the responsibility of your entity and its advisers.
Frequently asked questions
- When did DORA start applying?
- DORA has applied since 17 January 2025. It entered into force in January 2023 with a two-year implementation window.
- Who does DORA apply to?
- A broad range of EU financial entities — banks, payment and e-money institutions, investment firms, insurers, crypto-asset service providers and more — plus the critical ICT third-party providers that serve them, subject to proportionality.
- What is the difference between DORA and NIS2?
- Both address cyber resilience, but DORA is sector-specific EU law for financial entities and, where it applies, takes precedence over the more general NIS2 as lex specialis. Financial entities focus on DORA; many still have NIS2-style obligations for parts of their operations.
- What is TLPT under DORA?
- Threat-led penetration testing is an advanced, intelligence-driven resilience test that significant financial entities must undertake periodically, based on the TIBER-EU framework, to test critical functions against realistic attack scenarios.