EU Regulation · DORA

Digital Operational Resilience for the Financial Sector

EU Regulation 2022/2554, applicable since 17 January 2025, imposes a unified framework for managing ICT-related risks on financial entities operating in the European Union.

DORA — Scope and Stakes

DORA (Digital Operational Resilience Act) is an EU regulation with direct applicability across Member States. It applies to a broad range of financial entities — credit institutions, investment firms, payment and electronic money institutions, insurance and reinsurance undertakings, alternative investment fund managers, crypto-asset service providers, market infrastructure operators — as well as critical ICT third-party service providers serving them.

Key concept · Digital Operational Resilience

The ability of a financial entity to build, assure and review its operational integrity and reliability by ensuring, either directly or indirectly through the use of services of ICT third-party service providers, the full range of ICT-related capabilities needed to address the security of the network and information systems which a financial entity uses, and which support the continued provision of financial services and their quality, including throughout disruptions (DORA, Art. 3(1)).

DORA is structured around five pillars covering all ICT-related requirements imposed on in-scope entities. These requirements are further specified through Regulatory Technical Standards (RTS) and Implementing Technical Standards (ITS) published by the European Supervisory Authorities (EBA, ESMA, EIOPA).

The Five Pillars of the Regulation

Pillar 1

ICT Risk Management

ICT risk management framework, digital resilience strategy, security policies, business continuity and ICT recovery plans. Enhanced requirements for significant financial entities.

Pillar 2

Incident Management and Reporting

Classification of ICT-related incidents, internal management process, notification to competent authorities under harmonised criteria and deadlines, annual major incident reporting.

Pillar 3

Digital Operational Resilience Testing

Threat-Led Penetration Testing (TLPT) for significant entities, baseline testing for all in-scope entities, mutual recognition conditions between Member States.

Pillar 4

ICT Third-Party Risk Management

Third-party risk policy, contract register, mandatory minimum contractual clauses, direct supervision by European Supervisory Authorities of designated critical ICT third-party providers.

Pillar 5

Cyber Threat Information Sharing

Provisions enabling financial entities to participate voluntarily in cyber threat intelligence sharing arrangements, within the applicable regulatory framework.

My Teaching Approach

DORA cannot be understood in isolation. Its operational grasp requires placing it within the surrounding normative and regulatory environment — particularly the ISO standards it references explicitly or implicitly, and the other regulatory requirements that apply simultaneously to financial entities.

DORA · EU 2022/2554

EU Digital Operational Resilience Act — applicable since 17 January 2025

Technical Standards (RTS / ITS)

RTS ICT Risk Management

Risk management framework, tools, methods, policies · Commission delegated acts

RTS Incident Classification · TLPT

Classification criteria, notification thresholds, TLPT methodology

Reference ISO standards

ISO/IEC 27001

ISMS — security governance foundation

ISO/IEC 27005

Information security risk management

ISO 22301

Business continuity — ICT recovery plans

ISO 31000

Generic risk management framework

Related regulatory environment

NIS2

Cybersecurity directive — essential and important entities

TIBER-EU

ECB framework for threat-led resilience testing

EBA Guidelines

Guidelines on ICT and security risk management

GDPR

Intersection with personal data security

Pillar 1 — ICT Risk Management: articulation with ISO/IEC 27001 and ISO 31000

The ICT risk management framework required by DORA connects naturally with ISO/IEC 27001 for ISMS governance and ISO 31000 for generic risk management principles. DORA's requirements on business continuity and ICT recovery plans find their normative counterpart in ISO 22301. My approach shows how organisations already engaged in these normative frameworks can leverage existing work to meet DORA requirements — avoiding duplication and building on established governance structures.

Pillar 2 — ICT Incidents: classification, management and regulatory notification

DORA imposes classification of ICT-related incidents based on precise criteria (number of affected clients, duration, geographic impact, financial losses, systemic importance) and strict notification timelines to competent authorities — initial, intermediate and final reports. Mastering these processes is an immediate operational requirement for security, compliance and incident management teams.

Pillar 3 — TLPT: Threat-Led Penetration Testing

Threat-Led Penetration Testing (TLPT) is DORA's most advanced requirement for significant entities. Based on the ECB's TIBER-EU framework, it engages professional red teams simulating realistic attacks using threat intelligence. Understanding the implementation modalities, governance requirements and mutual recognition between Member States is essential for in-scope entities and their technology partners.

Pillar 4 — ICT Third-Party Risk: supervision and contractual requirements

Third-party ICT risk is at the heart of DORA. The regulation requires a dedicated policy, a contract register, mandatory minimum contractual clauses and, for critical ICT third-party providers designated by the European Supervisory Authorities, a direct supervision regime. This dimension is particularly sensitive for financial entities heavily reliant on cloud services — and for technology providers themselves.

International Experience

This approach draws on operational experience gained with major international financial groups, entities regulated by the European Supervisory Authorities, defence sector organisations and Big Four firms. It is grounded in field practice developed in France, Luxembourg and Scandinavia — three jurisdictions particularly exposed to DORA requirements given the concentration of financial entities and critical ICT providers established there.

DORA compliance is not merely a regulatory project: it engages governance at the highest level, mobilises legal, compliance, security, operations and procurement functions, and requires a thorough review of relationships with technology providers. My approach transmits this cross-functional perspective, anchored in the operational reality of financial entities.

DORA requires financial entities to demonstrate, in a structured and auditable manner, their ability to withstand ICT disruptions and recover from them. It is a paradigm shift: digital operational resilience becomes an obligation of result, not merely of means.

Dominique Bourra  ·  PECB Platinum Trainer

Training your teams on DORA or pursuing individual certification?
On-site or remote, instructor-led or self-paced.

Get in touch →