• 4,000 firms
  • Independent
  • Trusted
Save up to 70% on staff

Home » Glossary » Digital Operational Resilience Act (DORA)

Digital Operational Resilience Act (DORA)

Definition

Digital Operational Resilience Act (DORA)

The Digital Operational Resilience Act (DORA) is an EU regulation binding banks, insurers, and their ICT vendors to withstand cyber shocks. It sets one binding digital-resilience floor for financial entities across the 27 EU member states, in force since January 2025.

DORA folds five pillars into one rulebook: ICT risk management, incident reporting, resilience testing, third-party risk, and information sharing. It replaces the patchwork of national guidance that left banks and their outsourcers reading different playbooks.

The regulation entered into force on 16 January 2023 and became fully applicable on 17 January 2025, giving supervisors direct oversight over critical ICT third parties — cloud providers, data centres, and shared services firms included.

For outsourcing buyers, DORA reshapes vendor selection. Every ICT contract with a bank, insurer, or investment firm now needs concrete SLAs on incident response, exit strategies, and audit rights — no more boilerplate.

Key takeaways

  • Applies across all 27 EU member states from 17 January 2025.
  • Covers banks, insurers, investment firms, crypto-asset service providers, and their critical ICT third parties.
  • Sets five pillars: ICT risk management, incident reporting, resilience testing, third-party risk, and information sharing.
  • Grants EU supervisors direct oversight of designated critical ICT third-party providers.
  • Non-compliance can trigger fines up to 1% of average daily worldwide turnover for critical providers.

How it works

DORA imposes five obligations on every in-scope financial entity and its ICT suppliers. It ties risk management, incident reporting, resilience testing, third-party governance, and threat intel into one supervisory chain that European regulators can audit end-to-end.

PillarWhat it requiresWho supervises
ICT risk managementBoard-approved framework, mapped assets, tested controlsNational competent authority
Incident reportingMajor incidents flagged within 4 hours, root cause within 1 monthESAs central hub
Resilience testingThreat-led penetration tests every 3 years for larger entitiesLead overseer
Third-party riskRegister of ICT contracts, exit strategies, concentration monitoringNational competent authority
Information sharingVoluntary cyber threat intelligence exchangeESAs coordinate

The three European Supervisory Authorities (ESAs), namely EBA, ESMA, and EIOPA, jointly run the DORA oversight framework.

Critical ICT third-party providers designated under DORA face direct EU-level supervision and fines up to 1% of average daily worldwide turnover for each day of non-compliance.

Larger banks and market infrastructures must run threat-led penetration tests every three years using external red teams. Smaller entities run scenario-based tests annually. Both tiers feed findings back into the ICT risk framework the board signed off.

The third-party register is the operational spine. Every ICT contract must be logged, categorised, and reviewed annually, with concentration risk flagged when one provider carries too many critical functions.

Examples

DORA’s reach touches every corner of EU financial services. From cloud contracts to fintech incident playbooks, the regulation forces named firms to redesign how they govern ICT, and it pulls specific vendor names into supervisory scope for the first time.

Deutsche Bank issued a public Digital Operational Resilience Act (DORA) readiness statement in January 2025 covering its Frankfurt and Dublin hubs. The bank rebuilt ICT contracts with Microsoft Azure and IBM to meet DORA’s register requirements.

ING Group tightened Philippine and Polish outsourcing arrangements in Q4 2024. The Dutch lender rewrote exit clauses with Manila back-office providers so contracts satisfy Digital Operational Resilience Act (DORA) exit-strategy and audit-rights tests.

Amazon Web Services and Microsoft were flagged early as likely ‘critical ICT third-party providers’ under the Digital Operational Resilience Act (DORA).

The European Supervisory Authorities began the formal designation process in 2025, giving Brussels direct oversight of the hyperscalers’ EU footprint.

Manila-based captives of BNP Paribas and HSBC updated 2025 contracts to meet the Digital Operational Resilience Act (DORA), tightening exit clauses with Philippine BPO providers Concentrix, TDCX, and iQor — a first for the region.

Nordea and BBVA published Digital Operational Resilience Act (DORA) compliance updates in 2025 detailing how their offshore centres in India, Poland, and the Philippines feed the incident-reporting hub.

Both banks cited timelines against the ESAs’ 4-hour major-incident classification window.

Related terms

FAQ

Who does DORA apply to?

DORA applies to almost every EU financial entity: banks, insurers, investment firms, payment institutions, crypto-asset service providers, and their critical ICT third parties. It also reaches non-EU providers serving EU financial firms.

When did DORA take effect?

DORA entered into force on 16 January 2023 and became fully applicable on 17 January 2025. National competent authorities began active enforcement immediately after that date.

What are the DORA penalties?

Financial entities face fines set by their national authority, calibrated to turnover and severity. Designated critical ICT third-party providers face EU-level fines up to 1% of average daily worldwide turnover per day of non-compliance.

How does DORA affect outsourcing contracts?

DORA rewrites every ICT contract with an EU financial entity, requiring exit strategies, audit rights, incident SLAs, and full sub-contractor transparency.

Browse the OA directory to compare vendors with the resilience credentials EU finance now demands under the Digital Operational Resilience Act (DORA).

Companies you might be interested in

Get Inside Outsourcing

An insider's view on why remote and offshore staffing is radically changing the future of work.

Order now

Start your
journey today

  • Independent
  • Secure
  • Transparent

About OA

Outsource Accelerator is the trusted source of independent information, advisory and expert implementation of Business Process Outsourcing (BPO).

The #1 outsourcing authority

Outsource Accelerator offers the world’s leading aggregator marketplace for outsourcing. It specifically provides the conduit between world-leading outsourcing suppliers and the businesses – clients – across the globe.

The Outsource Accelerator website has over 5,000 articles, 450+ podcast episodes, and a comprehensive directory with 4,700+ BPO companies… all designed to make it easier for clients to learn about – and engage with – outsourcing.

About Derek Gallimore

Derek Gallimore has been in business for 20 years, outsourcing for over eight years, and has been living in Manila (the heart of global outsourcing) since 2014. Derek is the founder and CEO of Outsource Accelerator, and is regarded as a leading expert on all things outsourcing.

“Excellent service for outsourcing advice and expertise for my business.”

Learn more
Banner Image
Get 3 Free Quotes Verified Outsourcing Suppliers
4,000 firms.Just 2 minutes to complete.
SAVE UP TO
70% ON STAFF COSTS
Learn more

Connect with over 4,000 outsourcing services providers.

Banner Image

Transform your business with skilled offshore talent.

  • 4,000 firms
  • Simple
  • Transparent
Banner Image