Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.
In this guide
- Key takeaways
- What exactly is DORA and where does it come from?
- Which organisations fall under DORA’s scope?
- What are the five core obligations DORA imposes?
- How does governance work under DORA?
- What is the Register of Information (RoI) and why does it matter?
- What are Critical ICT Third - Party Providers (CTPPs) and how are they supervised?
- What penalties can organisations face for non - compliance?
- How does proportionality affect smaller firms?
- What is the current compliance landscape in 2026?
- How can you start preparing for DORA compliance?
Key takeaways
- DORA is an EU regulation (Regulation (EU) 2022/2554) that applies directly in all Member States.
- It requires a formal ICT risk - management framework, incident reporting, testing, and third - party oversight.
- Full compliance is mandatory from 17 January 2025; penalties can reach 2 % of global turnover or €10 million.
- Boards must approve the framework and can be personally fined up to €1 million.
- Proportionality means smaller firms follow a simplified set of requirements.
What exactly is DORA and where does it come from?
DORA stands for Digital Operational Resilience Act, an EU regulation that creates a binding, sector - wide framework for the digital and ICT operational resilience of financial entities. It was adopted as Regulation (EU) 2022/2554 and entered into application on 17 January 2025, meaning all covered firms must be compliant from that day.
Which organisations fall under DORA’s scope?
DORA covers roughly 20 types of financial entities - including banks, insurers, investment firms, payment - service providers and crypto - asset service providers - as well as the ICT third - party service providers they use. If your firm offers any of these services in the EU, you are in scope.
What are the five core obligations DORA imposes?
- ICT risk - management framework - Identify, protect, detect, respond to and recover from ICT risks.
- ICT - related incident management & reporting - Classify incidents and notify competent authorities within 4 - 24 hours for major events.
- Digital operational - resilience testing - Conduct vulnerability scans, penetration tests, and for “significant” entities a Threat - Led Penetration Test at least every three years.
- ICT third - party risk management - Perform due - diligence, embed contractual clauses, monitor concentration risk and maintain a Register of Information.
- Information - sharing mechanisms - Participate in voluntary threat - intel sharing with regulators and industry bodies. These pillars are detailed in the regulatory technical standards (RTS) that accompany the regulation.
How does governance work under DORA?
The management body (board) must approve the ICT risk - management framework, oversee its implementation and demonstrate knowledge of ICT risks. Failure to do so can trigger personal fines of up to €1 million for senior - management members.
What is the Register of Information (RoI) and why does it matter?
Every ICT - service contract must be recorded in a continuously maintained Register of Information. The register must be made available to competent authorities on request, providing regulators with full visibility into third - party dependencies.
What are Critical ICT Third - Party Providers (CTPPs) and how are they supervised?
Providers designated as critical are subject to EU - wide supervisory oversight. Regulators can impose periodic penalty payments of up to 1 % of the provider’s average daily worldwide turnover for up to six months if they breach obligations.
What penalties can organisations face for non - compliance?
- Fines up to 2 % of total annual worldwide turnover or €10 million, whichever is higher.
- Daily penalty payments for CTPPs up to 1 % of average daily worldwide turnover (max six months).
- Personal fines for senior - management members up to €1 million.
- Non - financial measures such as remediation orders, suspension of activities or revocation of licences.
How does proportionality affect smaller firms?
Requirements are scaled to the entity’s size, risk profile and service nature. Micro - enterprises may use a simplified framework, reducing the documentation and testing burden while still meeting the core resilience goals.
What is the current compliance landscape in 2026?
National competent authorities are actively reviewing firms, and many still have gaps. A recent Deloitte survey indicated only about 25 % of respondents felt they had a “very high” maturity level for DORA compliance, highlighting the need for focused remediation.
How can you start preparing for DORA compliance?
- Map scope - Identify all in - scope entities and ICT third - party contracts.
- Establish a risk - management framework - Document processes for identification, protection, detection, response and recovery.
- Implement incident reporting - Set up a 24 - hour alert channel and classification matrix.
- Schedule testing - Plan regular vulnerability scans and, if applicable, a Threat - Led Penetration Test every three years.
- Create the Register of Information - Record every ICT service contract with required details.
- Board involvement - Ensure the board reviews and signs off the framework.
- Monitor updates - Follow guidance from competent authorities and the latest RTS amendments.
By following these steps you can move from a compliance gap to a documented, auditable resilience programme that satisfies DORA’s requirements.
Related guides
What is NIST in cybersecurity and why should you care?
NIST is the U.S. agency that creates the Cybersecurity Framework and a suite of standards like SP 800 - 53 that guide risk management for both government and private organizations.
Which NIST Cybersecurity Standards Should My Organization Adopt in 2024 - 2025?
Learn the core NIST publications that form a practical, layered security program, how they map together, and concrete steps to start using them today.
Does the EU AI Act apply to U.S. companies?
Yes - the EU AI Act has extraterritorial reach and can bind U.S. AI providers, deployers, importers or distributors whenever their systems are placed on the EU market, used by an EU entity, or produce output that is used in the Union.