DORA Explained Simply: What Companies Need to Know About Requirements, Obligations, and Implementation
The Digital Operational Resilience Act (DORA) is the European Union's central regulation for strengthening digital operational resilience in the financial sector. Since January 17, 2025, Regulation (EU) 2022/2554 on EUR-Lex has been binding for over 20 categories of financial entities and their critical third-party ICT service providers.
The regulation aims to make the European financial system more resilient to cyber risks and IT outages through uniform requirements for ICT risk management, incident management, resilience testing, and third-party risks.
DORA at a glance
- Legal status: As an EU regulation, DORA is directly applicable and does not require national transposition legislation. The German DORA Implementation Act (DORA-AfG) provides supplementary regulations for purely national supervisory powers and sanction mechanisms.
- Scope of application: In addition to traditional banks and insurers, DORA explicitly applies to FinTechs, crypto-asset service providers (CASPs under MiCA), payment and e-money institutions, and third-party ICT service providers (e.g., cloud providers, SaaS vendors).
- The 5 pillars: ICT risk management, classification and reporting of ICT-related incidents, digital resilience testing, management of ICT third-party risk, and information sharing.
- Supervisory focus: The European supervisory authorities (BaFin's DORA supervision, EBA, ESMA, EIOPA) are closely reviewing the submitted information registers and the contractual flow-down of DORA requirements to ICT service providers.
What is DORA?
DORA stands for Digital Operational Resilience Act (Regulation EU 2022/2554) and establishes the European legal framework for IT security and digital operational resilience across the entire financial sector. While previous requirements (such as BaFin's BAIT or VAIT) were largely national in nature, DORA creates a fully harmonized level of protection across all EU member states.
The regulation requires financial companies to treat cybersecurity and IT risk management not merely as an IT task, but as a direct governance responsibility of the management board .
Who does DORA apply to?
DORA applies to more than 20 categories of financial entities and, for the first time, directly or indirectly to their ICT third-party service providers. Affected entities include:
- Credit institutions and investment firms
- Payment institutions and electronic money institutions
- Insurance and reinsurance undertakings
- Crypto-asset service providers (CASPs) under the MiCA regulation
- Alternative investment fund managers (AIFMs) and UCITS management companies
- ICT third-party service providers: IT service providers, SaaS vendors, data centers, and cloud providers that deliver services to the financial sector.
Important note for FinTechs and ICT service providers: Even if your B2B software company is not directly regulated as a financial institution, financial clients will contractually require strict DORA compliance, security certifications, audit rights, and exit strategies under Art. 30 DORA .
What are the 5 pillars of DORA?
DORA organizes digital operational resilience requirements into five core areas:
How does ICT risk management work under DORA?
ICT risk management under DORA (Pillar 1) requires companies to implement a dynamic control system. Specifically, this means:
- Strategy & Governance: Management must define risk tolerance thresholds, approve ICT strategies, and regularly participate in training on cyber risks.
- Asset Management & Identification: All ICT assets and business processes must be mapped, classified, and continuously monitored for vulnerabilities.
- Business Continuity: Companies must establish precise continuity and contingency plans (Business Continuity Plans) as well as tested backup and recovery processes.
What are the reporting deadlines for ICT security incidents?
For ICT-related incidents classified as major , DORA mandates a three-stage reporting process to the competent supervisory authority (e.g., BaFin):
- Initial notification: Within 4 hours after the incident is classified as major (no later than 24 hours after detection).
- Intermediate report: Within 72 hours, once normal operations are restored or new information becomes available.
- Final report: No later than 1 month after the incident, including a detailed root cause analysis (Root Cause Analysis).
What does ICT third-party risk management mean?
Third-party risk (Pillar 4) is one of the most complex areas of action. Financial institutions must systematically monitor all ICT service arrangements.
The information register
Every supervised entity must maintain a structured information register in accordance with the EU's technical implementation standards (ITS). This must contain all contracts with ICT service providers, categorized by critical and non-critical functions as well as their sub-contractor chains.
Contractual adjustments under Art. 30 DORA
Existing and new contracts with ICT service providers must mandatorily include the following required clauses:
- Access & Audit Rights: Unrestricted inspection and audit rights for the financial institution and regulatory authorities.
- SLAs & Security Levels: Precisely defined service level agreements and security standards.
- Subcontractors: Clear rules for the subcontracting of critical functions.
- Exit Strategies: Contractually guaranteed cooperation upon contract termination, including orderly data migration.
What is the difference between DORA and NIS2?
The fundamental difference between DORA and the NIS2 Directive lies in their scope and the principle of specialty (lex specialis):
- Priority of DORA: Financial institutions subject to DORA are exempt from the corresponding NIS2 requirements regarding their ICT security and reporting obligations. DORA takes precedence as lex specialis .
- Legal Form: DORA is an EU regulation and applies directly in all member states. NIS2 is a directive that must first be transposed into national law through domestic legislation (regulated in Germany via the BSI – Federal Office for Information Security).
- Replacing legacy standards: With the entry into force of DORA, previous BaFin circulars (BAIT, VAIT) have been incorporated into the new EU regulatory framework and superseded.
What penalties and sanctions apply for DORA violations?
Non-compliance can lead to significant regulatory measures:
- Periodic penalty payments for critical ICT third-party service providers (CTPPs): Up to 1% of the average daily worldwide turnover of the preceding business year – imposed for each day of continued non-compliance.
- National fines: Supervisory authorities (such as BaFin) can impose tiered fines on institutions and service providers.
- Personal liability: Supervisory authorities may temporarily prohibit executives from holding management positions in cases of serious failures in ICT risk management.
Achieve legally compliant and digital DORA implementation with heyData
Meeting DORA requirements necessitates a structured approach to recording service providers, contracts, and risk assessments. heyData helps FinTechs, financial institutions, and ICT service providers automate compliance processes efficiently:
- Structured information register: Automated recording and management of all ICT service provider contracts in accordance with the requirements of EU supervisory authorities.
- Contract review pursuant to Art. 30 DORA: Digital review of third-party contracts regarding audit rights, SLAs, and exit strategies.
- Audit readiness checks: Rapid identification of security and governance gaps to prepare for regulatory audits.
Further resources & official documents
FAQ
When did DORA take effect?
When did DORA take effect?
DORA took effect on January 16, 2023, and, following a two-year transition period, has been mandatory in all EU member states since January 17, 2025.
Does DORA replace ISO 27001 certification?
Does DORA replace ISO 27001 certification?
No. ISO 27001 certification provides an excellent foundation for an information security management system (ISMS). However, DORA requires specific regulatory evidence, such as the information register for ICT contracts, specific reporting deadlines, and threat-based penetration tests (TLPT).
Does DORA also apply to small businesses and fintechs?
Does DORA also apply to small businesses and fintechs?
Yes, DORA generally applies regardless of company size. However, the principle of proportionality applies: micro-enterprises and less complex institutions may rely on simplified requirements for ICT risk management (Art. 16 DORA).








