Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.
In this guide
- Key takeaways
- What is DORA in the EU?
- Which organisations must follow DORA?
- What are the main compliance pillars of DORA?
- How can developers start preparing for DORA?
- What are the penalties for non - compliance?
- How does DORA relate to other EU regulations?
- Where can I find the official text?
- Final checklist for developers
Key takeaways
- DORA = Digital Operational Resilience Act, EU Regulation (EU) 2022/2554.
- It applies to all financial institutions operating in the EU, including banks, insurers, and crypto service providers.
- Core requirements cover ICT risk management, incident reporting, digital testing, and third - party oversight.
- Non - compliance can lead to fines up to €5 million or 2 % of annual turnover, plus reputational damage.
- Developers can start compliance by mapping assets, implementing continuous monitoring, and using automated reporting tools.
What is DORA in the EU?
DORA stands for the Digital Operational Resilience Act, an EU regulation that creates a binding framework for ICT risk management and operational resilience of financial entities. It entered force in January 2023 and will be fully applicable by January 2025.
Which organisations must follow DORA?
Any firm that provides financial services in the EU - banks, payment institutions, insurance companies, crypto - asset service providers, and market infrastructures - must comply. The rule also reaches third - party ICT providers that serve those firms, such as cloud platforms and SaaS vendors.
What are the main compliance pillars of DORA?
| Pillar | What it requires |
|---|---|
| ICT risk management | Formal policies, periodic risk assessments, and mitigation plans for all critical systems. |
| Incident reporting | Notify the competent authority within 24 hours of a major ICT incident, then provide a detailed follow - up within 72 hours. |
| Digital operational testing | Conduct regular vulnerability scans, penetration tests, and advanced testing like threat - led penetration testing. |
| Information sharing | Participate in the EU - wide cyber - information exchange platform for alerts and best practices. |
| Third - party oversight | Perform due - diligence, continuous monitoring, and contractual clauses for all ICT service providers. |
How can developers start preparing for DORA?
- Create an asset inventory - List every application, database, cloud service, and network component that supports financial functions.
- Classify critical assets - Use business impact analysis to mark systems whose failure would disrupt core services.
- Implement continuous monitoring - Deploy SIEM or CSPM tools that collect logs, alert on anomalies, and retain data for at least one year.
- Automate incident reporting - Build a template that pulls log excerpts and system status into the required 24 - hour report format.
- Conduct regular testing - Schedule quarterly vulnerability scans and annual threat - led penetration tests; document findings and remediation steps.
- Review third - party contracts - Add clauses that require providers to meet DORA - level security controls and to notify you of incidents.
What are the penalties for non - compliance?
National competent authorities can impose administrative fines up to €5 million or 2 % of the firm’s total worldwide annual turnover, whichever is higher. In addition, regulators may suspend or limit business activities until remedial actions are taken.
How does DORA relate to other EU regulations?
| Regulation | Focus | Overlap with DORA |
|---|---|---|
| GDPR | Personal data protection | Both require breach notification, but DORA is specific to ICT incidents affecting financial services. |
| MiFID II | Market transparency | DORA adds operational resilience requirements that complement MiFID II’s governance rules. |
| NIS2 | Cybersecurity for essential services | DORA adopts many NIS2 controls but is stricter for financial sector ICT risk management. |
Where can I find the official text?
The full regulation is published as Regulation (EU) 2022/2554 and can be downloaded from the European Commission’s EUR - LEX portal. Guidance documents are also available from the European Banking Authority (EBA) and the European Securities and Markets Authority (ESMA).
Final checklist for developers
- Asset inventory completed and classified.
- Risk management policy documented and reviewed annually.
- Incident response playbook includes a 24 - hour reporting flow.
- Automated monitoring and logging configured for all critical systems.
- Quarterly vulnerability scans and annual threat - led testing scheduled.
- Third - party contracts contain DORA - aligned security clauses.
By following these steps, you can turn DORA from a regulatory hurdle into a roadmap for stronger digital resilience.
Related guides
What is NIST in cybersecurity and why should you care?
NIST is the U.S. agency that creates the Cybersecurity Framework and a suite of standards like SP 800 - 53 that guide risk management for both government and private organizations.
Which NIST Cybersecurity Standards Should My Organization Adopt in 2024 - 2025?
Learn the core NIST publications that form a practical, layered security program, how they map together, and concrete steps to start using them today.
Does the EU AI Act apply to U.S. companies?
Yes - the EU AI Act has extraterritorial reach and can bind U.S. AI providers, deployers, importers or distributors whenever their systems are placed on the EU market, used by an EU entity, or produce output that is used in the Union.