DORA (Digital Operational Resilience Act): Overview, requirements, and implementation

Martin Bastius
10.09.2026
5
min.

Use AI to summarize this article

DORA Explained Simply: What Companies Need to Know About Requirements, Obligations, and Implementation

The Digital Operational Resilience Act (DORA) is the European Union's central regulation for strengthening digital operational resilience in the financial sector. Since January 17, 2025, Regulation (EU) 2022/2554 on EUR-Lex has been binding for over 20 categories of financial entities and their critical third-party ICT service providers.

The regulation aims to make the European financial system more resilient to cyber risks and IT outages through uniform requirements for ICT risk management, incident management, resilience testing, and third-party risks.

DORA at a glance

  • Legal status: As an EU regulation, DORA is directly applicable and does not require national transposition legislation. The German DORA Implementation Act (DORA-AfG) provides supplementary regulations for purely national supervisory powers and sanction mechanisms.
  • Scope of application: In addition to traditional banks and insurers, DORA explicitly applies to FinTechs, crypto-asset service providers (CASPs under MiCA), payment and e-money institutions, and third-party ICT service providers (e.g., cloud providers, SaaS vendors).
  • The 5 pillars: ICT risk management, classification and reporting of ICT-related incidents, digital resilience testing, management of ICT third-party risk, and information sharing.
  • Supervisory focus: The European supervisory authorities (BaFin's DORA supervision, EBA, ESMA, EIOPA) are closely reviewing the submitted information registers and the contractual flow-down of DORA requirements to ICT service providers.

What is DORA?

DORA stands for Digital Operational Resilience Act (Regulation EU 2022/2554) and establishes the European legal framework for IT security and digital operational resilience across the entire financial sector. While previous requirements (such as BaFin's BAIT or VAIT) were largely national in nature, DORA creates a fully harmonized level of protection across all EU member states.

The regulation requires financial companies to treat cybersecurity and IT risk management not merely as an IT task, but as a direct governance responsibility of the management board .

Who does DORA apply to?

DORA applies to more than 20 categories of financial entities and, for the first time, directly or indirectly to their ICT third-party service providers. Affected entities include:

  • Credit institutions and investment firms
  • Payment institutions and electronic money institutions
  • Insurance and reinsurance undertakings
  • Crypto-asset service providers (CASPs) under the MiCA regulation
  • Alternative investment fund managers (AIFMs) and UCITS management companies
  • ICT third-party service providers: IT service providers, SaaS vendors, data centers, and cloud providers that deliver services to the financial sector.

Important note for FinTechs and ICT service providers: Even if your B2B software company is not directly regulated as a financial institution, financial clients will contractually require strict DORA compliance, security certifications, audit rights, and exit strategies under Art. 30 DORA .

What are the 5 pillars of DORA?

DORA organizes digital operational resilience requirements into five core areas:

Säule Bezeichnung Kernanforderungen & Details
Säule 1 IKT-Risikomanagement (Art. 5–16) Einrichtung eines umfassenden IKT-Risikorahmens. Die Verantwortung liegt unübertragbar bei der Geschäftsleitung (inkl. Schulungspflichten).
Säule 2 Meldung IKT-bezogener Vorfälle (Art. 17–23) Harmonisiertes Schema zur Klassifizierung von IT-Sicherheitsvorfällen und strikte Meldefristen an Aufsichtsbehörden.
Säule 3 Testen der digitalen Resilienz (Art. 24–27) Regelmäßige Schwachstellenanalysen; für bedeutende Institute mindestens alle 3 Jahre bedrohungsorientierte Penetrationstests (TLPT / Threat-Led Penetration Testing).
Säule 4 IKT-Drittparteienrisiko (Art. 28–44) Führung eines vollständigen Informationsregisters über alle IKT-Verträge; Anpassung aller Dienstleisterverträge gemäß Art. 30 DORA.
Säule 5 Informationsaustausch (Art. 45) Freiwillige Beteiligung an Netzwerken zum Austausch von Informationen über Cyberbedrohungen und Indikatoren (IOCs).

How does ICT risk management work under DORA?

ICT risk management under DORA (Pillar 1) requires companies to implement a dynamic control system. Specifically, this means:

  1. Strategy & Governance: Management must define risk tolerance thresholds, approve ICT strategies, and regularly participate in training on cyber risks.
  2. Asset Management & Identification: All ICT assets and business processes must be mapped, classified, and continuously monitored for vulnerabilities.
  3. Business Continuity: Companies must establish precise continuity and contingency plans (Business Continuity Plans) as well as tested backup and recovery processes.

What are the reporting deadlines for ICT security incidents?

For ICT-related incidents classified as major , DORA mandates a three-stage reporting process to the competent supervisory authority (e.g., BaFin):

  • Initial notification: Within 4 hours after the incident is classified as major (no later than 24 hours after detection).
  • Intermediate report: Within 72 hours, once normal operations are restored or new information becomes available.
  • Final report: No later than 1 month after the incident, including a detailed root cause analysis (Root Cause Analysis).

What does ICT third-party risk management mean?

Third-party risk (Pillar 4) is one of the most complex areas of action. Financial institutions must systematically monitor all ICT service arrangements.

The information register

Every supervised entity must maintain a structured information register in accordance with the EU's technical implementation standards (ITS). This must contain all contracts with ICT service providers, categorized by critical and non-critical functions as well as their sub-contractor chains.

Contractual adjustments under Art. 30 DORA

Existing and new contracts with ICT service providers must mandatorily include the following required clauses:

  • Access & Audit Rights: Unrestricted inspection and audit rights for the financial institution and regulatory authorities.
  • SLAs & Security Levels: Precisely defined service level agreements and security standards.
  • Subcontractors: Clear rules for the subcontracting of critical functions.
  • Exit Strategies: Contractually guaranteed cooperation upon contract termination, including orderly data migration.

What is the difference between DORA and NIS2?

The fundamental difference between DORA and the NIS2 Directive lies in their scope and the principle of specialty (lex specialis):

  1. Priority of DORA: Financial institutions subject to DORA are exempt from the corresponding NIS2 requirements regarding their ICT security and reporting obligations. DORA takes precedence as lex specialis .
  2. Legal Form: DORA is an EU regulation and applies directly in all member states. NIS2 is a directive that must first be transposed into national law through domestic legislation (regulated in Germany via the BSI – Federal Office for Information Security).
  3. Replacing legacy standards: With the entry into force of DORA, previous BaFin circulars (BAIT, VAIT) have been incorporated into the new EU regulatory framework and superseded.

What penalties and sanctions apply for DORA violations?

Non-compliance can lead to significant regulatory measures:

  • Periodic penalty payments for critical ICT third-party service providers (CTPPs): Up to 1% of the average daily worldwide turnover of the preceding business year – imposed for each day of continued non-compliance.
  • National fines: Supervisory authorities (such as BaFin) can impose tiered fines on institutions and service providers.
  • Personal liability: Supervisory authorities may temporarily prohibit executives from holding management positions in cases of serious failures in ICT risk management.

Achieve legally compliant and digital DORA implementation with heyData

Meeting DORA requirements necessitates a structured approach to recording service providers, contracts, and risk assessments. heyData helps FinTechs, financial institutions, and ICT service providers automate compliance processes efficiently:

  • Structured information register: Automated recording and management of all ICT service provider contracts in accordance with the requirements of EU supervisory authorities.
  • Contract review pursuant to Art. 30 DORA: Digital review of third-party contracts regarding audit rights, SLAs, and exit strategies.
  • Audit readiness checks: Rapid identification of security and governance gaps to prepare for regulatory audits.

Further resources & official documents

FAQ

When did DORA take effect?

DORA took effect on January 16, 2023, and, following a two-year transition period, has been mandatory in all EU member states since January 17, 2025.

Does DORA replace ISO 27001 certification?

No. ISO 27001 certification provides an excellent foundation for an information security management system (ISMS). However, DORA requires specific regulatory evidence, such as the information register for ICT contracts, specific reporting deadlines, and threat-based penetration tests (TLPT).

Does DORA also apply to small businesses and fintechs?

Yes, DORA generally applies regardless of company size. However, the principle of proportionality applies: micro-enterprises and less complex institutions may rely on simplified requirements for ICT risk management (Art. 16 DORA).

Published
10.09.2026
Last updated
10.09.2026
Martin Bastius
Co-Founder & CLO

More articles

Porträt eines lächelnden Mannes mit kurzem dunklem Haar und Bart vor grauem Hintergrund.
View all articles
Cybersecurity & Risk Management
4/1/26

Managing Director Liability: Why NIS2 Makes IT Security an Executive Priority

Managing Director Liability: Why NIS2 Makes IT Security an Executive Priority
Cybersecurity & Risk Management
1/30/23

What Is Password Hashing and Salting?

What Is Password Hashing and Salting?
Cybersecurity & Risk Management
11/5/25

Human Weaknesses in Cybersecurity 2025: Risks, Facts, and Solutions

Human Weaknesses in Cybersecurity 2025: Risks, Facts, and Solutions
Porträt eines lächelnden Mannes mit kurzem dunklem Haar und Bart vor grauem Hintergrund.
Discover all stories