Skip to content
The blog

The EU DORA regulation: how it comes into force

11 March 2024 · 2 min

DORA has been in force since January 2023. Penalties, however, only start in January 2025. The European Digital Operational Resilience Act was adopted in December 2022 to strengthen the operational IT resilience of banking and financial players.

The scope of the DORA regulation

DORA covers 20,000 banking and financial entities — banks, investment funds, virtual currency operators and others. Add to those 15,000 IT suppliers, bankers and insurers. That makes 35,000 entities in scope.

DORA requires ‘European’ financial and banking entities to prepare for cyberattacks. They will have to prove that they can defend themselves against cyberattacks, but also respond and recover afterwards.

Who does the DORA regulation apply to?

On cybersecurity, DORA requires entities to:

  • Identify and map their information systems.
  • Assess their cybersecurity risks.
  • Put adequate resilience measures in place.
  • Coordinate with suppliers and customers in the event of an incident.
  • Run resilience tests regularly.
  • Monitor data leaks in open sources (OSINT).

DORA coming into force will not have the same consequences for every company size. Obligations differ by size. There is a simplified DORA for small and micro-enterprises², with simplified risk management. For every other company, tests must be run at least once a year.

DORA also requires open source intelligence on your own data (RIFI within OSINT). That is what allows you to map the data and, from there, identify the risks.

Resilience tests under the EU DORA regulation

Contact us to find out more about OSINT compliance.

DORA: timescales and entry into force

DORA coming into force is a major change for the financial sector. The entities concerned — banks, insurers, payment service providers and market infrastructures — will have to comply with a fairly broad set of requirements. What about the timescales?

As we mentioned, DORA comes into force and applies from January 2025, less than a year from now. The European authorities allowed a 24-month implementation period. From January 2025, entities that are not compliant may face penalties.

What are the penalties for non-compliance with DORA?

Failing to meet DORA’s requirements can lead to substantial penalties, of up to 5% of the entity’s worldwide annual turnover.

In cases of outright negligence, the ultimate penalty could go as far as withdrawal of the operating licence — meaning the business can no longer trade at all.

Read the article ‘DORA — IT resilience in the banking and financial sector’

DORA coming into force is an important step for the operational resilience of the European financial sector at large. By meeting DORA’s requirements, financial players will help protect customer data, strengthen trust in the banking and financial system, and secure the stability of the European financial sector.

Join our webinar ‘Data: the new stake in the EU NIS2 and DORA regulations’

See what the dark web says about you

Thirty minutes with an analyst, on your own data.

Book a demo