Digital Operational Resilience Act (DORA)
Definition
Digital Operational Resilience Act (DORA)
The Digital Operational Resilience Act (DORA) is an EU regulation binding banks, insurers, and their ICT vendors to withstand cyber shocks. It sets one binding digital-resilience floor for financial entities across the 27 EU member states, in force since January 2025.
DORA folds five pillars into one rulebook: ICT risk management, incident reporting, resilience testing, third-party risk, and information sharing. It replaces the patchwork of national guidance that left banks and their outsourcers reading different playbooks.
The regulation entered into force on 16 January 2023 and became fully applicable on 17 January 2025, giving supervisors direct oversight over critical ICT third parties — cloud providers, data centres, and shared services firms included.
For outsourcing buyers, DORA reshapes vendor selection. Every ICT contract with a bank, insurer, or investment firm now needs concrete SLAs on incident response, exit strategies, and audit rights — no more boilerplate.
Key takeaways
- Applies across all 27 EU member states from 17 January 2025.
- Covers banks, insurers, investment firms, crypto-asset service providers, and their critical ICT third parties.
- Sets five pillars: ICT risk management, incident reporting, resilience testing, third-party risk, and information sharing.
- Grants EU supervisors direct oversight of designated critical ICT third-party providers.
- Non-compliance can trigger fines up to 1% of average daily worldwide turnover for critical providers.
How it works
DORA imposes five obligations on every in-scope financial entity and its ICT suppliers. It ties risk management, incident reporting, resilience testing, third-party governance, and threat intel into one supervisory chain that European regulators can audit end-to-end.
| Pillar | What it requires | Who supervises |
|---|---|---|
| ICT risk management | Board-approved framework, mapped assets, tested controls | National competent authority |
| Incident reporting | Major incidents flagged within 4 hours, root cause within 1 month | ESAs central hub |
| Resilience testing | Threat-led penetration tests every 3 years for larger entities | Lead overseer |
| Third-party risk | Register of ICT contracts, exit strategies, concentration monitoring | National competent authority |
| Information sharing | Voluntary cyber threat intelligence exchange | ESAs coordinate |
The three European Supervisory Authorities (ESAs), namely EBA, ESMA, and EIOPA, jointly run the DORA oversight framework.
Critical ICT third-party providers designated under DORA face direct EU-level supervision and fines up to 1% of average daily worldwide turnover for each day of non-compliance.
Larger banks and market infrastructures must run threat-led penetration tests every three years using external red teams. Smaller entities run scenario-based tests annually. Both tiers feed findings back into the ICT risk framework the board signed off.
The third-party register is the operational spine. Every ICT contract must be logged, categorised, and reviewed annually, with concentration risk flagged when one provider carries too many critical functions.
Examples
DORA’s reach touches every corner of EU financial services. From cloud contracts to fintech incident playbooks, the regulation forces named firms to redesign how they govern ICT, and it pulls specific vendor names into supervisory scope for the first time.
Deutsche Bank issued a public Digital Operational Resilience Act (DORA) readiness statement in January 2025 covering its Frankfurt and Dublin hubs. The bank rebuilt ICT contracts with Microsoft Azure and IBM to meet DORA’s register requirements.
ING Group tightened Philippine and Polish outsourcing arrangements in Q4 2024. The Dutch lender rewrote exit clauses with Manila back-office providers so contracts satisfy Digital Operational Resilience Act (DORA) exit-strategy and audit-rights tests.
Amazon Web Services and Microsoft were flagged early as likely ‘critical ICT third-party providers’ under the Digital Operational Resilience Act (DORA).
The European Supervisory Authorities began the formal designation process in 2025, giving Brussels direct oversight of the hyperscalers’ EU footprint.
Manila-based captives of BNP Paribas and HSBC updated 2025 contracts to meet the Digital Operational Resilience Act (DORA), tightening exit clauses with Philippine BPO providers Concentrix, TDCX, and iQor — a first for the region.
Nordea and BBVA published Digital Operational Resilience Act (DORA) compliance updates in 2025 detailing how their offshore centres in India, Poland, and the Philippines feed the incident-reporting hub.
Both banks cited timelines against the ESAs’ 4-hour major-incident classification window.
Related terms
- Business continuity plan (BCP): the recovery playbook DORA mandates for every in-scope financial entity.
- Information security analyst: the role that runs DORA-mandated resilience testing and incident detection.
- General Data Protection Regulation (GDPR): the parallel EU regulation DORA sits alongside for financial-services data handling.
- Compliance officer: the role that maintains DORA evidence packs and audit-trail documentation.
- Outsourcing: the wider practice DORA regulates when the buyer is an EU bank, insurer, or investment firm.
FAQ
Who does DORA apply to?
DORA applies to almost every EU financial entity: banks, insurers, investment firms, payment institutions, crypto-asset service providers, and their critical ICT third parties. It also reaches non-EU providers serving EU financial firms.
When did DORA take effect?
DORA entered into force on 16 January 2023 and became fully applicable on 17 January 2025. National competent authorities began active enforcement immediately after that date.
What are the DORA penalties?
Financial entities face fines set by their national authority, calibrated to turnover and severity. Designated critical ICT third-party providers face EU-level fines up to 1% of average daily worldwide turnover per day of non-compliance.
How does DORA affect outsourcing contracts?
DORA rewrites every ICT contract with an EU financial entity, requiring exit strategies, audit rights, incident SLAs, and full sub-contractor transparency.
Browse the OA directory to compare vendors with the resilience credentials EU finance now demands under the Digital Operational Resilience Act (DORA).







Independent




