Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.
In this guide
- Key takeaways
- What is DORA?
- Who must comply with DORA?
- What are the five pillars of DORA obligations?
- How is DORA enforced?
- What technical standards support DORA?
- How does proportionality affect compliance?
- Practical steps to start DORA compliance
- Why should financial firms care now?
- How does DORA relate to broader compliance frameworks?
Key takeaways
- DORA (Digital Operational Resilience Act) is an EU regulation that applies to ~20 types of financial entities and their ICT service providers.
- It becomes enforceable on 17 January 2025; penalties can reach 2 % of global turnover or €10 million.
- The law is built on five pillars: ICT risk - management, incident reporting, resilience testing, third - party risk management, and information - sharing.
- Requirements are proportional - smaller firms get simplified obligations.
- Compliance means documented governance, regular testing (including TLPT for large firms), and continuous monitoring of vendors.
What is DORA?
DORA stands for Digital Operational Resilience Act, an EU regulation (Regulation (EU) 2022/2554) that creates a binding framework for the digital - operational resilience of financial entities and their ICT service providers. It was published on 27 December 2022 and becomes applicable on 17 January 2025.
Who must comply with DORA?
The regulation covers around twenty categories of financial institutions - banks, insurers, investment firms, payment - service providers, crypto - asset service providers and more - as well as the ICT third - party providers that serve them. Both the primary entity and the ICT provider are subject to the same set of obligations.
What are the five pillars of DORA obligations?
- ICT risk - management framework - Organizations must identify, protect, detect, respond to and recover from ICT risks, with governance resting on the management body (Art 5 - 16).
- Incident reporting - Major ICT incidents must be classified and reported to the national competent authority within 4 - 24 hours for the initial notice, followed by intermediate and final reports.
- Digital - operational - resilience testing - Regular vulnerability assessments and penetration tests are required; “significant” entities must also perform Threat - Led Penetration Testing (TLPT) at least every three years.
- ICT third - party risk management - Continuous monitoring of ICT providers, contractual audit rights, exit strategies, and maintenance of a Register of Information (RoI) are mandated.
- Information - sharing - Entities are encouraged to voluntarily join sector - wide threat - intelligence sharing arrangements (Art 45).
How is DORA enforced?
National competent authorities (NCAs) supervise entities in each Member State, while the European Supervisory Authorities (EBA, ESMA, EIOPA) coordinate EU - wide oversight, especially for Critical Third - Party Providers (CTPPs). Penalties can reach 2 % of worldwide turnover or €10 million (whichever is higher) for serious breaches, daily penalties up to 1 % of average daily worldwide turnover for CTPPs, and personal fines up to €1 million for senior managers.
What technical standards support DORA?
The European Supervisory Authorities and ENISA have published Regulatory Technical Standards (RTS) that define ICT risk - management tools, incident - classification categories, reporting processes, TLPT methodology, third - party policy, subcontracting requirements and the Register of Information. These RTS documents provide the detailed technical specifications that organizations must follow.
How does proportionality affect compliance?
DORA scales obligations to an entity’s size, risk profile and complexity (Art 4). Micro - enterprises may use a simplified ICT risk - management framework (Art 16) and have reduced testing obligations, while larger firms must meet the full set of requirements.
Practical steps to start DORA compliance
- Map scope - Identify all financial activities and ICT service providers that fall under DORA.
- Establish governance - Assign responsibility to the senior management body and create an ICT risk - management policy.
- Implement a risk register - Document identified ICT risks, mitigation measures and ownership.
- Set up incident reporting - Define classification criteria, create an incident response playbook, and configure notification timelines (initial notice within 4 - 24 h).
- Schedule testing - Plan regular vulnerability scans and penetration tests; for significant entities, schedule TLPT every three years.
- Audit third - party contracts - Add clauses for audit rights, exit strategies and maintain an up - to - date Register of Information.
- Join information - sharing forums - Participate in industry threat - intelligence groups to meet the voluntary information - sharing pillar.
Why should financial firms care now?
Non - compliance can lead to multi - million - euro fines, reputational damage and operational disruption. Moreover, the regulation drives a higher baseline of cyber - resilience across the financial sector, reducing systemic risk. Early preparation lets firms spread the effort, avoid rush - hour compliance costs and demonstrate to regulators a proactive security posture.
How does DORA relate to broader compliance frameworks?
DORA’s control set overlaps with many existing standards - ISO 27001, NIST CSF, and the upcoming NIS2 directive - but it adds sector - specific requirements for incident reporting timelines, TLPT and third - party monitoring. Mapping DORA obligations to these frameworks can simplify audit preparation and reduce duplicate work.
Related guides
What is NIST in cybersecurity and why should you care?
NIST is the U.S. agency that creates the Cybersecurity Framework and a suite of standards like SP 800 - 53 that guide risk management for both government and private organizations.
Which NIST Cybersecurity Standards Should My Organization Adopt in 2024 - 2025?
Learn the core NIST publications that form a practical, layered security program, how they map together, and concrete steps to start using them today.
Does the EU AI Act apply to U.S. companies?
Yes - the EU AI Act has extraterritorial reach and can bind U.S. AI providers, deployers, importers or distributors whenever their systems are placed on the EU market, used by an EU entity, or produce output that is used in the Union.