Back to Guides
Guide16 September 2026

What is DORA in compliance and why does it matter for financial firms?

Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.

In this guide
  1. Key takeaways
  2. What exactly is DORA and where does it come from?
  3. Which organisations fall under DORA’s scope?
  4. What are the five core obligations DORA imposes?
  5. How does governance work under DORA?
  6. What is the Register of Information (RoI) and why does it matter?
  7. What are Critical ICT Third - Party Providers (CTPPs) and how are they supervised?
  8. What penalties can organisations face for non - compliance?
  9. How does proportionality affect smaller firms?
  10. What is the current compliance landscape in 2026?
  11. How can you start preparing for DORA compliance?

Key takeaways

What exactly is DORA and where does it come from?

DORA stands for Digital Operational Resilience Act, an EU regulation that creates a binding, sector - wide framework for the digital and ICT operational resilience of financial entities. It was adopted as Regulation (EU) 2022/2554 and entered into application on 17 January 2025, meaning all covered firms must be compliant from that day.

Which organisations fall under DORA’s scope?

DORA covers roughly 20 types of financial entities - including banks, insurers, investment firms, payment - service providers and crypto - asset service providers - as well as the ICT third - party service providers they use. If your firm offers any of these services in the EU, you are in scope.

What are the five core obligations DORA imposes?

  1. ICT risk - management framework - Identify, protect, detect, respond to and recover from ICT risks.
  2. ICT - related incident management & reporting - Classify incidents and notify competent authorities within 4 - 24 hours for major events.
  3. Digital operational - resilience testing - Conduct vulnerability scans, penetration tests, and for “significant” entities a Threat - Led Penetration Test at least every three years.
  4. ICT third - party risk management - Perform due - diligence, embed contractual clauses, monitor concentration risk and maintain a Register of Information.
  5. Information - sharing mechanisms - Participate in voluntary threat - intel sharing with regulators and industry bodies. These pillars are detailed in the regulatory technical standards (RTS) that accompany the regulation.

How does governance work under DORA?

The management body (board) must approve the ICT risk - management framework, oversee its implementation and demonstrate knowledge of ICT risks. Failure to do so can trigger personal fines of up to €1 million for senior - management members.

What is the Register of Information (RoI) and why does it matter?

Every ICT - service contract must be recorded in a continuously maintained Register of Information. The register must be made available to competent authorities on request, providing regulators with full visibility into third - party dependencies.

What are Critical ICT Third - Party Providers (CTPPs) and how are they supervised?

Providers designated as critical are subject to EU - wide supervisory oversight. Regulators can impose periodic penalty payments of up to 1 % of the provider’s average daily worldwide turnover for up to six months if they breach obligations.

What penalties can organisations face for non - compliance?

How does proportionality affect smaller firms?

Requirements are scaled to the entity’s size, risk profile and service nature. Micro - enterprises may use a simplified framework, reducing the documentation and testing burden while still meeting the core resilience goals.

What is the current compliance landscape in 2026?

National competent authorities are actively reviewing firms, and many still have gaps. A recent Deloitte survey indicated only about 25 % of respondents felt they had a “very high” maturity level for DORA compliance, highlighting the need for focused remediation.

How can you start preparing for DORA compliance?

  1. Map scope - Identify all in - scope entities and ICT third - party contracts.
  2. Establish a risk - management framework - Document processes for identification, protection, detection, response and recovery.
  3. Implement incident reporting - Set up a 24 - hour alert channel and classification matrix.
  4. Schedule testing - Plan regular vulnerability scans and, if applicable, a Threat - Led Penetration Test every three years.
  5. Create the Register of Information - Record every ICT service contract with required details.
  6. Board involvement - Ensure the board reviews and signs off the framework.
  7. Monitor updates - Follow guidance from competent authorities and the latest RTS amendments.

By following these steps you can move from a compliance gap to a documented, auditable resilience programme that satisfies DORA’s requirements.

Free security scan

See what's actually exposed on your site.

Decloak's free scan runs in about 15 seconds, no account required, and covers:

  • HTTP/TLS security posture
  • JavaScript CVEs
  • Exposed Supabase/Lovable/Base44 misconfigurations
  • AI-written executive summary