Speak to a rep about your business needs
See our product support options
General inquiries and locations
Contact usUnderstanding DORA is the first step toward compliance. Explore the essentials, discover how to build resilience, and prepare your organization for regulatory success with the right combination of strategies and technology.
The Digital Operational Resilience Act (DORA) was formally adopted by both the Council of the European Union and the European Parliament in November 2022, with its regulations coming into force on 17 January 2025. With this date having now passed, financial institutions and third-party ICT service providers are obligated to comply with DORA, and regulatory monitoring and enforcement have commenced.
DORA sets out critical requirements for organizations, focusing on areas such as service transparency, risk management, continuity planning, incident response, and governance. These guidelines help entities establish robust frameworks designed to withstand operational challenges and adapt to the evolving digital environment.
Provided for informational purposes only. This information should not be considered legal advice, and may not reflect the latest in legal/regulatory/compliance/etc. Always consult with council or qualified legal professionals, and/or relevant authorities.
DORA requires organizations to assess, manage, and prove the effectiveness of ICT controls across all areas. Every role is accountable for digital resilience, with evidence needed for disruption preparedness. This includes up-to-date data recovery plans, formal incident response protocols, and cyber risk measures, verified through audits and reviews.
Organizations must have real-time systems for monitoring and reporting ICT incidents, promptly notifying regulators and affected parties. Structured reporting, with initial alerts, updates, and root cause analysis, is supported by documented procedures and templates to ensure transparency.
Organizations are obligated to demonstrate effective testing of ICT systems, including regular resilience checks and threat-led penetration testing. Results and remediation actions are provided to regulators as part of the compliance process.
Firms must manage ICT third-party risks with documented exit strategies, audit rights, and performance objectives, reviewed regularly. Evidence of contractual terms and risk assessments ensures a transparent approach overseen by authorities.
DORA expects organizations to join threat intelligence sharing initiatives, complying with GDPR and other guidelines. Each company is expected to actively record their involvement and the insights gained, thereby demonstrating their commitment to bolstering resilience across the entire sector.
DORA requires organizations to assess, manage, and prove the effectiveness of ICT controls across all areas. Every role is accountable for digital resilience, with evidence needed for disruption preparedness. This includes up-to-date data recovery plans, formal incident response protocols, and cyber risk measures, verified through audits and reviews.
Organizations must have real-time systems for monitoring and reporting ICT incidents, promptly notifying regulators and affected parties. Structured reporting, with initial alerts, updates, and root cause analysis, is supported by documented procedures and templates to ensure transparency.
Organizations are obligated to demonstrate effective testing of ICT systems, including regular resilience checks and threat-led penetration testing. Results and remediation actions are provided to regulators as part of the compliance process.
Firms must manage ICT third-party risks with documented exit strategies, audit rights, and performance objectives, reviewed regularly. Evidence of contractual terms and risk assessments ensures a transparent approach overseen by authorities.
DORA expects organizations to join threat intelligence sharing initiatives, complying with GDPR and other guidelines. Each company is expected to actively record their involvement and the insights gained, thereby demonstrating their commitment to bolstering resilience across the entire sector.
First, a quick DORA (Digital Operational Resilience Act) summary. DORA is a comprehensive European union (EU) regulation designed to:
The DORA regulatory legislation defines technical standards, capabilities, and outcomes to ensure all organizations under its jurisdiction follow a unified set of practices to maintain their security and continuous operations during incidents that threaten their ICT systems.
The DORA regulation applies to financial entities within the EU and the critical third-party ICT providers that serve them. These financial entities have undergone rapid digitalization. They are common targets for cyberattacks, and the fallout from suffering an incident impacts every other organization that depends on the financial entity’s core services.
Authorities within the EU drafted DORA to help financial organizations and their providers understand and manage risks, and ensure their services are operational at all times.
The following Digital Operational Resilience Act timeline summarizes the key moments in this legislation’s history.
DORA went into effect on January 17, 2025. By that date and since, all entities and providers under its purview were required to be in full compliance with its requirements, or they are at risk for fines and penalties.
CTPPS (Critical Third-Party Providers)
The DORA regulation sets requirements for both financial entities and the third-party ICT providers that serve them. However, DORA only applies to what it defines as “critical” providers, and the legislation often refers to them as critical third-party providers, or CTPPS.
The legislation is somewhat ambiguous about what is considered a “critical” provider, though it relates to how integrated and important a service is for a financial entity’s operations. These providers are directly impacted by DORA and its authorities.
NISD (Network and Information Security Directive)
The Network and Information Security Directive (NISD) is a broader directive to improve the security and resilience of organizations and infrastructure within the EU. NISD applies to operators of essential services and relevant digital service providers, and imposes similar requirements to DORA.
NISD went live in October 2024, a few months before DORA. Together, the two regulations make it clear that cybersecurity and resilience are core concerns for the EU, and additional legislation for other industries is likely to follow.
An independent EU organization “whose purpose is to improve investor protection and promote stable, orderly financial markets.” (EU)
A part of the European system of financial supervision that provides “advice to the European Commission, the European Parliament and the Council of the European Union.” (EU)
An agency “tasked with implementing a standard set of rules to regulate and supervise banking across all EU countries.” (EU)
An independent EU organization “whose purpose is to improve investor protection and promote stable, orderly financial markets.” (EU)
A part of the European system of financial supervision that provides “advice to the European Commission, the European Parliament and the Council of the European Union.” (EU)
An agency “tasked with implementing a standard set of rules to regulate and supervise banking across all EU countries.” (EU)
DORA authorities, including the ESAs, will evaluate compliance with the legislation’s requirements. They will perform direct oversight for both financial entities, and for third parties deemed critical ICT providers and under their jurisdiction.
These authorities will also collaborate with entities and providers, receive their reports of incidents and notifications of threats, and offer guidance and best practices for maintaining compliance.
Certain forms of oversight will be performed by entities and providers themselves. Entities are required to maintain oversight over their third-party ICT providers, and both groups are required to maintain awareness of their own risks.
Entities and providers will be required to prove compliance with DORA’s requirements, which include vulnerability scans and assessments, annual recovery testing, physically and logically segregated data vaults, and rapid event reporting.
ESAs will also be empowered to perform audits, request information and documentation, and levy penalties. These can include financial penalties, denying approval for providers to work with DORA EU financial entities, and forcing an organization to cease to operations.
DORA classifies 21 categories of financial activities that fall under its scope, which means the legislation applies to a wide range of financial entities and service providers. These include:
DORA sets requirements for “critical” third-party ICT providers that do business with financial institutions within the EU, even if those providers are not headquartered in the EU. DORA includes third-party ICT providers that appear location-agnostic, including cloud service providers, data center providers, and data analytics providers.
These new technical requirements will be written into contracts between financial entities and third-party ICT providers. At the moment, these contract requirements will be defined by the entities themselves, but it is possible that DORA will include standardized contracts or terms that must be used by providers and entities.
This would place third-party ICT providers under greater oversight and scrutiny from both the financial entities they support and EU financial authorities. Third-party ICT providers may also need to have a legal subsidiary within the EU to offer their services to financial entities within the EU.
DORA regulations broadly define which third-party ICT providers are deemed “critical” as any provider that offers important functions to financial entities, and whose services may impact a financial entity’s business stability and continuity.
DORA regulation offers limited exemptions for smaller financial entities that employ less than 10 people and have annual turnover and/or balance sheet totals under two million Euros. It also does not apply to certain entities exempt from related legislation. For them, DORA requires a simplified version of its ICT risk management framework.
In terms of third-party ICT providers, DORA sets requirements for providers deemed “critical,” as outlined above. However this remains a broad term, and it is unclear whether DORA will effectively apply to all providers that service financial entities.
Overall, DORA requirements follow the principle of proportionality. They are designed for financial entities that align with a specific size, risk profile, nature, scope, and complexity of services, activities, and operations. Under DORA, financial entities that meet these criteria will need to meet all of the act’s requirements.
Under DORA, financial entities that violate the act can be fined a periodic penalty of up to one percent of their average daily global turnover for up to six months (or until they achieve compliance). They may also be fined up to two percent of the annual global turnover. Third-party ICT providers are subject to the same potential penalties and fines.
Individuals who violate DORA can be fined up to one million Euros.
Additional penalties will be determined by each EU member state, and by the “competent authorities” and ESAs within them. These authorities may audit or suspend an entity or provider’s operations, send cease-and-desist orders and termination notices, issue public notices, or levy administrative or criminal penalties.
While IT leaders will remain key players in ICT risk management, DORA expands the capability beyond the domain of IT leadership in two ways:
DORA regulatory legislation mandates that financial entities establish or adjust their internal governance framework to align with its requirements. Financial entities must also establish or realign their management body. Non-technical board members, executive leaders, and other senior business managers are now expected to play an active role in IT governance, and can be held accountable if their entity fails to comply with DORA.
Maintaining compliance with DORA’s risk management framework will require a cross-functional effort. The following RACI chart outlines the various themes that must be addressed, and the teams and roles responsible for them.
| Theme | Responsible | Accountable | Consulted | Informed |
|---|---|---|---|---|
| Incident management | Head of Operations, Security Operations Center (SOC)
| CIO, COO, CISO
| COO, CISO
| C-suite
|
| Business continuity management | Head of Business Continuity, Operational Resilience
| CIO, COO, CISO
| COO, CISO
| C-suite
|
| Service awareness and visibility | Head of Distributed Infrastructure Services, Head of Mainframe Infrastructure Services
| CIO, COO, CISO
| CIO, COO, CISO
| C-suite
|
| Risk management | Head of IT Risk, Mainframe Security, Outsourcing, Third Party Risk management (TPRM), Cyber Risk Management
| CIO, COO, CISO, Head of Procurement
| COO, CISO
| C-suite
|
| Governance | Head of IT Compliance, Legal, Procurement
| Head of IT Audit, Head of Compliance
| COO, CISO
| C-suite
|
Under DORA, banking entities and other financial entities must periodically test their operational resiliency plans. This includes testing to ensure they are prepared for likely disruptions, identifying and resolving deficiencies within their response plans. It also includes testing resilience against higher-level risks—such as ransomware attacks—through threat-led penetration testing (TLTP).
In addition, DORA requires financial entities to expand their incident reporting capabilities and practices. DORA demands that entities:
Managing risk from third-party ICT providers is a core element of DORA. The legislation identifies significant risk from these providers and the supply chain as a whole. It defines requirements that third-party ICT providers must follow, as well as requirements for how financial entities must engage with their providers.
Both sets of requirements are detailed in greater length below.
The DORA act is an ICT risk management framework for financial entities. It seeks to expand ICT risk management beyond previous definitions, which primarily required entities to hold enough capital to mitigate their risks, and to unify these expanded risk management practices across all entities within the EU.
DORA also highlights “ICT risk management and governance” as one of its five pillars, and defines requirements that include, but are not limited to:
DORA also defines specific ICT risk management requirements related to third-party ICT providers, as well as new governance requirements. Both are detailed below.
Third-party ICT providers that service financial entities—and are defined as “critical”—will be subject to an oversight framework imposed by DORA authorities, and will fall under direct supervision by EU financial authorities.
DORA authorities will monitor these providers to determine the risk that they bring to their customers, and to ensure they are managing their ICT risk properly. To do so, DORA authorities may request information and documentation on a provider’s risk management practices, perform investigations and inspections, recommend actions, and levy fines and penalties.
However, the DORA framework and the DORA authorities that manage it are not the only bodies responsible for third-party compliance with DORA. The legislation requires that individual financial entities reshape their relationships with these providers, as well, and take some accountability for managing their own supply chain risks.
DORA regulatory legislation will become a standard element of all relationships between financial entities within the EU, and the third-party ICT providers that serve them.
The legislation seeks to increase the sector’s resilience against supply chain attacks and operational incidents, and to ensure financial entities can maintain continuity during these events. To do so, DORA places requirements on how entities understand and manage their third-party risks, and manage their relationships with providers.
Financial entities will be required to map their dependencies on third-party ICT providers, and to document the vulnerabilities that each provider creates. Further, entities will be required to take active measures to mitigate the risks they uncover. These measures include, but are not limited to:
Financial entities will take an active role ensuring their service providers meet DORA’s requirements. Entities will be expected to write DORA compliance into their contracts with providers. These clauses will ensure technical standards are met; exit strategies, audits, and resilience targets are defined; and risk is contractually managed.
DORA authorities will support financial entities in these contract requirements. Financial entities will not be able to work with providers that are subject to DORA and do not meet its requirements, and authorities will be able to suspend or terminate contracts with providers that do not meet requirements, or fall out of compliance.
In the future, DORA will likely include standardized contractual clauses and/or contract templates to streamline this process. Service providers will also likely make DORA compliance a standard feature of their service, like they have done with General Data Protection Regulation (GDPR) and other related regulations.
DORA compliance will become non-negotiable in every relationship between financial entities doing business within the EU and third-party ICT service providers.
However, the degree of compliance and the terms that must be met will be subject to the same principle of proportionality as other elements of DORA. Financial entities will be expected to ensure a higher degree of compliance from third-party ICT providers that are more critical to their operations, and set a lower level of compliance for providers that are less critical to their operations and carry lower risk.
By setting these requirements, DORA attempts to reduce the scale and impact of third-party provider risk within financial entities—and the sector as a whole—without becoming an unnecessarily high barrier to provider-entity relationships.
Financial entities will be required to map their dependencies on third-party ICT providers, and to document the vulnerabilities that each provider creates. Further, entities will be required to take active measures to mitigate the risks they uncover. These measures include, but are not limited to:
Financial entities will take an active role ensuring their service providers meet DORA’s requirements. Entities will be expected to write DORA compliance into their contracts with providers. These clauses will ensure technical standards are met; exit strategies, audits, and resilience targets are defined; and risk is contractually managed.
DORA authorities will support financial entities in these contract requirements. Financial entities will not be able to work with providers that are subject to DORA and do not meet its requirements, and authorities will be able to suspend or terminate contracts with providers that do not meet requirements, or fall out of compliance.
In the future, DORA will likely include standardized contractual clauses and/or contract templates to streamline this process. Service providers will also likely make DORA compliance a standard feature of their service, like they have done with General Data Protection Regulation (GDPR) and other related regulations.
DORA compliance will become non-negotiable in every relationship between financial entities doing business within the EU and third-party ICT service providers.
However, the degree of compliance and the terms that must be met will be subject to the same principle of proportionality as other elements of DORA. Financial entities will be expected to ensure a higher degree of compliance from third-party ICT providers that are more critical to their operations, and set a lower level of compliance for providers that are less critical to their operations and carry lower risk.
By setting these requirements, DORA attempts to reduce the scale and impact of third-party provider risk within financial entities—and the sector as a whole—without becoming an unnecessarily high barrier to provider-entity relationships.
DORA is a complicated set of regulations with an extensive list of new requirements and technical standards to meet. Bringing it to life will be difficult for many financial entities and third-party ICT providers. The following checklist provides a simple way to get started building compliance as quickly as possible.
Assessing current ICT systems and identifying gaps
Some of DORA’s requirements are easy to assess against, others are not. For example, DORA specifically states that a financial entity’s backup data must be logically and physically segregated, and that it must be able to test its recovery plans once per year. These are concrete requirements that you either meet or need to develop.
Other DORA requirements are more ambiguous. For example, DORA states that cyberattacks need to be “promptly and quickly” resolved. While DORA states that critical functions must be recovered within two hours of the incident, there is no clear-cut timeline for when an incident must be resolved in full.
Creating a culture of cyber resilience in financial institutions
Every requirement in the DORA regulation focuses on building cyber resilience—the ability to withstand and recover from any disruptive incident. Resilience goes beyond simply developing business continuity plans and disaster recovery protocols, and creates additional systems to deal with complex, modern threats like ransomware attacks.
A culture of resilience focuses on five core competencies:
Essential collaboration between IT teams and regulatory bodies
In the past, financial entities and EU member states all followed their own protocols and standards. This created a patchwork of regulations and best practices that opened vulnerabilities and made compliance difficult to navigate. DORA seeks to standardize protocols to create a unified, secure EU financial sector.
This is a collaborative effort. The DORA law requests feedback from entities, voluntary sharing of threats, and open reporting of incidents. Maintaining open dialogue with DORA’s authorities not only makes the framework more effective, but it also keeps entities in the loop on ever-changing regulations so they can stay ahead of new requirements.
Meeting new technical standards
A financial entity’s ability to meet DORA’s technical standards largely depends on its tools and partnerships with compliant, experienced providers. The first step will be leveraging pre-existing structures, capabilities, and relationships that need to be tweaked or expanded to fill gaps in DORA’s requirements.
However, most entities will need to make additional investments. For example, while many financial entities already have a second backup data storage system in place, DORA states they must have immutable backups that are physically and logically segregated from all other sources, which typically requires investment in a third, cybervault technology.
DORA does not exist in a vacuum. It follows and closely mirrors other regulations that attempt to standardize and improve cybersecurity practices across the EU, and it will likely inform a large number of coming regulations in multiple industries.
Predicting the evolution and impact of DORA
DORA will improve cybersecurity and outline operational resilience regulations for financial entities as well as entities in many other industries. The reason for this is twofold. First, DORA sets higher standards for third-party ICT providers. Few of these providers only service the financial sector. Most of them serve organizations in every industry. By forcing third-party ICT providers to increase their security and resilience, DORA will reduce their risk for everyone who works with them—not just financial entities.
Second, DORA will likely inform broader regulations that apply to all industries, and are passed by countries outside of the EU. Financial services—and the EU—have long set the standard for cyber regulations. Just like GDPR’s requirements have become the global standard for data privacy, it is likely that the DORA requirements will be adopted by many other frameworks.
The act itself will continue to evolve, and financial entities and the providers that serve them should expect DORA updates that will further standardize practices and requirements for cybersecurity and digital resilience. The future is more regulations around these topics, not less, and IT leaders would do well to stay ahead of the curve.
The role of enterprise IT leaders in fostering a culture of resilience
DORA may be a cross-functional framework that makes cyber resilience a board-level concern, but it still lives primarily within the IT domain. IT leaders in operations, security, and risk will have the primary responsibility for meeting its requirements, as they “own” the digital systems that DORA is concerned with protecting.
This responsibility will only increase as more and more financial systems become digitized and dependent on ICT systems, whether internal or from third-party providers. DORA makes it clear that IT leaders are the present and the future of maintaining resilient operations within financial entities.
The sooner you start, the better.
The DORA law went into effect on January 17, 2025, and many organizations are still working to put requirement into place. If you think you aren't confident you're 100% covered, focus on the biggest gaps within your compliance that will require the most investment and effort to implement.
For most financial entities, that will be:
BMC Helix provides solutions and ICT services to rapidly bring these capabilities to life, in addition to a full portfolio of tools to cover every other element of operational resilience.
To learn more and request assistance in understanding DORA and achieving compliance as soon as possible, reach out today for a consultation.