DORA (Digital Operational Resilience Act) is an EU regulation with direct applicability across Member States. It applies to a broad range of financial entities — credit institutions, investment firms, payment and electronic money institutions, insurance and reinsurance undertakings, alternative investment fund managers, crypto-asset service providers, market infrastructure operators — as well as critical ICT third-party service providers serving them.
Key concept · Digital Operational Resilience
The ability of a financial entity to build, assure and review its operational integrity and reliability by ensuring, either directly or indirectly through the use of services of ICT third-party service providers, the full range of ICT-related capabilities needed to address the security of the network and information systems which a financial entity uses, and which support the continued provision of financial services and their quality, including throughout disruptions (DORA, Art. 3(1)).
DORA is structured around five pillars covering all ICT-related requirements imposed on in-scope entities. These requirements are further specified through Regulatory Technical Standards (RTS) and Implementing Technical Standards (ITS) published by the European Supervisory Authorities (EBA, ESMA, EIOPA).
Pillar 1
ICT Risk Management
ICT risk management framework, digital resilience strategy, security policies, business continuity and ICT recovery plans. Enhanced requirements for significant financial entities.
Pillar 2
Incident Management and Reporting
Classification of ICT-related incidents, internal management process, notification to competent authorities under harmonised criteria and deadlines, annual major incident reporting.
Pillar 3
Digital Operational Resilience Testing
Threat-Led Penetration Testing (TLPT) for significant entities, baseline testing for all in-scope entities, mutual recognition conditions between Member States.
Pillar 4
ICT Third-Party Risk Management
Third-party risk policy, contract register, mandatory minimum contractual clauses, direct supervision by European Supervisory Authorities of designated critical ICT third-party providers.
Pillar 5
Cyber Threat Information Sharing
Provisions enabling financial entities to participate voluntarily in cyber threat intelligence sharing arrangements, within the applicable regulatory framework.
DORA cannot be understood in isolation. Its operational grasp requires placing it within the surrounding normative and regulatory environment — particularly the ISO standards it references explicitly or implicitly, and the other regulatory requirements that apply simultaneously to financial entities.
DORA · EU 2022/2554
EU Digital Operational Resilience Act — applicable since 17 January 2025
Technical Standards (RTS / ITS)
RTS ICT Risk Management
Risk management framework, tools, methods, policies · Commission delegated acts
RTS Incident Classification · TLPT
Classification criteria, notification thresholds, TLPT methodology
Reference ISO standards
ISO/IEC 27001
ISMS — security governance foundation
ISO/IEC 27005
Information security risk management
ISO 22301
Business continuity — ICT recovery plans
ISO 31000
Generic risk management framework
Related regulatory environment
NIS2
Cybersecurity directive — essential and important entities
TIBER-EU
ECB framework for threat-led resilience testing
EBA Guidelines
Guidelines on ICT and security risk management
GDPR
Intersection with personal data security
Pillar 1 — ICT Risk Management: articulation with ISO/IEC 27001 and ISO 31000
The ICT risk management framework required by DORA connects naturally with ISO/IEC 27001 for ISMS governance and ISO 31000 for generic risk management principles. DORA's requirements on business continuity and ICT recovery plans find their normative counterpart in ISO 22301. My approach shows how organisations already engaged in these normative frameworks can leverage existing work to meet DORA requirements — avoiding duplication and building on established governance structures.
Pillar 2 — ICT Incidents: classification, management and regulatory notification
DORA imposes classification of ICT-related incidents based on precise criteria (number of affected clients, duration, geographic impact, financial losses, systemic importance) and strict notification timelines to competent authorities — initial, intermediate and final reports. Mastering these processes is an immediate operational requirement for security, compliance and incident management teams.
Pillar 3 — TLPT: Threat-Led Penetration Testing
Threat-Led Penetration Testing (TLPT) is DORA's most advanced requirement for significant entities. Based on the ECB's TIBER-EU framework, it engages professional red teams simulating realistic attacks using threat intelligence. Understanding the implementation modalities, governance requirements and mutual recognition between Member States is essential for in-scope entities and their technology partners.
Pillar 4 — ICT Third-Party Risk: supervision and contractual requirements
Third-party ICT risk is at the heart of DORA. The regulation requires a dedicated policy, a contract register, mandatory minimum contractual clauses and, for critical ICT third-party providers designated by the European Supervisory Authorities, a direct supervision regime. This dimension is particularly sensitive for financial entities heavily reliant on cloud services — and for technology providers themselves.
This approach draws on operational experience gained with major international financial groups, entities regulated by the European Supervisory Authorities, defence sector organisations and Big Four firms. It is grounded in field practice developed in France, Luxembourg and Scandinavia — three jurisdictions particularly exposed to DORA requirements given the concentration of financial entities and critical ICT providers established there.
DORA compliance is not merely a regulatory project: it engages governance at the highest level, mobilises legal, compliance, security, operations and procurement functions, and requires a thorough review of relationships with technology providers. My approach transmits this cross-functional perspective, anchored in the operational reality of financial entities.
DORA requires financial entities to demonstrate, in a structured and auditable manner, their ability to withstand ICT disruptions and recover from them. It is a paradigm shift: digital operational resilience becomes an obligation of result, not merely of means.