Back to Guides
Guide16 September 2026

What does DORA stand for in the EU and why should developers care?

Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.

In this guide
  1. Key takeaways
  2. What is DORA in the EU?
  3. Which organisations must follow DORA?
  4. What are the main compliance pillars of DORA?
  5. How can developers start preparing for DORA?
  6. What are the penalties for non - compliance?
  7. How does DORA relate to other EU regulations?
  8. Where can I find the official text?
  9. Final checklist for developers

Key takeaways

What is DORA in the EU?

DORA stands for the Digital Operational Resilience Act, an EU regulation that creates a binding framework for ICT risk management and operational resilience of financial entities. It entered force in January 2023 and will be fully applicable by January 2025.

Which organisations must follow DORA?

Any firm that provides financial services in the EU - banks, payment institutions, insurance companies, crypto - asset service providers, and market infrastructures - must comply. The rule also reaches third - party ICT providers that serve those firms, such as cloud platforms and SaaS vendors.

What are the main compliance pillars of DORA?

PillarWhat it requires
ICT risk managementFormal policies, periodic risk assessments, and mitigation plans for all critical systems.
Incident reportingNotify the competent authority within 24 hours of a major ICT incident, then provide a detailed follow - up within 72 hours.
Digital operational testingConduct regular vulnerability scans, penetration tests, and advanced testing like threat - led penetration testing.
Information sharingParticipate in the EU - wide cyber - information exchange platform for alerts and best practices.
Third - party oversightPerform due - diligence, continuous monitoring, and contractual clauses for all ICT service providers.

How can developers start preparing for DORA?

  1. Create an asset inventory - List every application, database, cloud service, and network component that supports financial functions.
  2. Classify critical assets - Use business impact analysis to mark systems whose failure would disrupt core services.
  3. Implement continuous monitoring - Deploy SIEM or CSPM tools that collect logs, alert on anomalies, and retain data for at least one year.
  4. Automate incident reporting - Build a template that pulls log excerpts and system status into the required 24 - hour report format.
  5. Conduct regular testing - Schedule quarterly vulnerability scans and annual threat - led penetration tests; document findings and remediation steps.
  6. Review third - party contracts - Add clauses that require providers to meet DORA - level security controls and to notify you of incidents.

What are the penalties for non - compliance?

National competent authorities can impose administrative fines up to €5 million or 2 % of the firm’s total worldwide annual turnover, whichever is higher. In addition, regulators may suspend or limit business activities until remedial actions are taken.

How does DORA relate to other EU regulations?

RegulationFocusOverlap with DORA
GDPRPersonal data protectionBoth require breach notification, but DORA is specific to ICT incidents affecting financial services.
MiFID IIMarket transparencyDORA adds operational resilience requirements that complement MiFID II’s governance rules.
NIS2Cybersecurity for essential servicesDORA adopts many NIS2 controls but is stricter for financial sector ICT risk management.

Where can I find the official text?

The full regulation is published as Regulation (EU) 2022/2554 and can be downloaded from the European Commission’s EUR - LEX portal. Guidance documents are also available from the European Banking Authority (EBA) and the European Securities and Markets Authority (ESMA).

Final checklist for developers

By following these steps, you can turn DORA from a regulatory hurdle into a roadmap for stronger digital resilience.

Free security scan

See what's actually exposed on your site.

Decloak's free scan runs in about 15 seconds, no account required, and covers:

  • HTTP/TLS security posture
  • JavaScript CVEs
  • Exposed Supabase/Lovable/Base44 misconfigurations
  • AI-written executive summary