
The start of 2025 marks the entry into force of the Digital Operational Resilience Act (DORA), a European regulation focused on digital operational resilience in the financial sector.
It is a major step, meant to strengthen the cybersecurity of financial institutions in Europe through specific measures protecting financial services against cyber threats. In this article we go through 10 essential points to know about the DORA regulation.
1. What is the DORA regulation?
The Digital Operational Resilience Act (DORA) is a European regulatory framework aimed at ensuring the operational resilience of financial entities and ICT service providers.
Its purpose is to reduce the risk of cyberattacks, standardise digital risk management practices, and improve companies’ resistance to attacks and service interruptions.
2. Who does DORA apply to?
As a reminder, DORA applies to 20 types of financial company, including:
- credit and payment institutions,
- electronic money institutions,
- investment firms,
- crypto-asset service providers,
- trading venues,
- management companies,
- insurance and reinsurance undertakings and their intermediaries,
- institutions for occupational retirement provision,
- credit rating agencies,
- crowdfunding service providers,
- and alternative investment fund managers.
These companies must have more than 10 employees and an annual turnover and/or balance sheet total of at least 2 million euros.
Add to that list IT providers — third-party ICT service providers — operating within the European Union.
DORA therefore reaches some ten thousand companies across Europe.

Which tests apply, by company size.
3. When does it come into force?
DORA formally applies from 17 January 2025. 2024 was the transition period, during which institutions prepared by putting measures in place to meet its new requirements.
4. DORA’s key objectives
DORA’s main objectives are to:
- Strengthen financial institutions’ resilience against cyber threats.
- Improve IT risk management across the sector.
- Harmonise risk management practices at European level.
- Encourage a coordinated response to cyber incidents, to limit systemic impact.
- Ensure financial stability and consumer protection.
5. Technology risk management requirements
DORA requires financial institutions to put risk management systems in place specifically for information technology. That includes:
- identifying, monitoring and limiting IT risks,
- implementing effective security protocols to protect data and critical infrastructure,
- identifying and monitoring OSINT data leaked outside the company’s information system.
6. Incident reporting obligations
Companies will have to report any significant digital incident affecting their services or the security of their data.
Where data leaks into open sources, the company must be equipped to detect it quickly. The report has to be filed within set deadlines, according to how the incident is classified and following DORA’s guidelines. That is what allows regulators to react quickly and assess the incident’s impact on the sector.
7. Oversight of third-party (ICT) providers
The regulation also requires financial institutions to strengthen oversight of third-party suppliers, particularly those providing critical IT services. DORA calls for robust contracts, regular audits, and an assessment of suppliers’ ability to manage cyber risk.
ICT providers hold a great deal of their customers’ confidential and strategic data, and are very often far more exposed than those customers, being less well protected. A financial institution must therefore also monitor its own data, which may have leaked into open sources after a cyberattack on an ICT provider — as the diagram below shows.

8. Operational resilience testing
DORA requires institutions to run operational resilience tests, to find the weaknesses in their systems and gauge their ability to face a cyberattack.
Those tests include simulation exercises and security audits, and must be run regularly to stay compliant with security standards.
9. Cybersecurity training and awareness
DORA also encourages continuous cybersecurity training for staff at financial institutions.
Employees must be made aware of good security practice and be able to identify cyber threats, so that the institution stays secure.
10. Penalties for non-compliance
Companies that fail to follow DORA’s rules face fines of up to 10 million euros, or 5% of their total annual turnover.
Penalties are set by each member state and must include financial sanctions, and possibly the temporary or permanent cessation of an affected activity.
National and European regulators will have the power to inspect. They will also be able to impose penalties for non-compliance, according to precise criteria that have yet to be set out.
Conclusion
Companies that fail to follow DORA’s rules face fines of up to 10 million euros, or 5% of their total annual turnover.
Penalties are set by each member state and must include financial sanctions, and possibly the temporary or permanent cessation of an affected activity.
National and European regulators will have the power to inspect and to impose penalties for non-compliance, according to precise criteria that have yet to be set out.
Read the article ‘The EU DORA regulation: what the text says’