Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Digital Operational Resilience Act (DORA): Who It Covers and What It Requires

DORA is the EU’s digital resilience framework for covered financial entities. Understand its scope, governance, incident, testing and ICT supplier requirements.
From TheFinanceBase Team4 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The Digital Operational Resilience Act (DORA), Regulation (EU) 2022/2554, sets EU-wide requirements for protecting the network and information systems that support financial entities’ business processes. It has applied since 17 January 2025. Covered firms must manage ICT risk, report major ICT incidents, test resilience and oversee ICT suppliers; separate EU-level oversight applies to providers designated as critical.

Who does DORA apply to?

DORA applies to the financial entities enumerated in the regulation, across areas including banking, payments, investment, insurance and financial markets. Its scope also includes certain other kinds of financial-sector entities. The exact answer for a particular organization depends on the regulation’s definitions, scope provisions and exceptions; being a financial business or supplying one does not, by itself, settle the question.

Some covered entities have proportional or simplified requirements in specified circumstances. Those provisions are not a basis for assuming that every smaller organization is outside DORA. Check the relevant provisions and applicable supervisory guidance to determine whether an entity is covered and which requirements apply to it.

What are the main DORA requirements?

DORA organizes digital operational resilience around governance and ICT risk management, incident handling, resilience testing, and ICT third-party risk. It requires documented arrangements rather than treating cybersecurity as a one-time technical project.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Govern ICT risk

A covered entity needs an ICT risk-management framework and governance arrangements that make responsibility clear. The management body is responsible for the framework. Policies, procedures, protocols and tools must support the entity’s approach to managing ICT risk, with proportionality and specified simplified requirements taken into account where applicable.

Identify, classify and report incidents

Entities must have processes for identifying and managing ICT-related incidents. DORA provides for classification of major ICT incidents and reporting of those incidents. Classification criteria, reporting channels and procedural details are set out in the applicable legal and implementing measures, so a general overview cannot establish the reporting steps or deadlines for a particular firm.

Test resilience

Covered entities need a digital operational resilience testing programme. The baseline testing cadence and the more specialized threat-led penetration testing requirement are distinct:

Testing requirement Who it applies to Cadence
Testing of ICT systems supporting critical or important functions Entities other than microenterprises At least yearly
Threat-led penetration testing Entities designated to conduct this testing under DORA At least every three years

These are legal minimum cadences, not a complete testing plan. DORA and its associated measures govern the scope and conduct of testing; the yearly requirement should not be mistaken for a rule that every system must undergo the same test once a year.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What does DORA require when a firm uses ICT suppliers?

A financial entity remains responsible for managing the ICT risks arising from its use of third-party services. Its duties include oversight of relevant supplier arrangements and the contracts supporting them. Outsourcing or relying on a technology provider does not transfer the entity’s responsibility for its own resilience obligations.

DORA also establishes a separate EU oversight framework for ICT providers designated as critical. That framework concerns oversight of the designated provider; it does not replace the financial entity’s own supplier-risk management.

Question Financial entity’s responsibility EU oversight of a designated critical provider
Who is the primary subject? The covered financial entity and its management arrangements The ICT provider designated as critical
What is being addressed? The entity’s ICT risk, including risk connected with relevant third-party services and contracts Oversight of the designated provider under DORA’s separate framework
Does one remove the other? No. The entity remains responsible for managing its ICT third-party risk. No. Provider oversight does not discharge the entity’s duties.

How does DORA relate to NIS2?

The European Commission describes DORA as sector-specific legislation for covered financial entities in relevant subject areas. That relationship should not be read as a blanket exemption from every NIS2 obligation. Whether a particular organization has obligations under either framework depends on its status, the relevant provisions and how the rules apply to its activities.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How should a financial entity assess its DORA position?

  1. Confirm scope. Compare the organization’s legal form and activities with DORA’s covered-entity definitions, scope provisions and exceptions. Do not rely only on its industry label, size or a supplier’s description.
  2. Map responsibilities. Identify who in the management structure oversees ICT risk, which policies and processes govern it, and how those arrangements are documented.
  3. Review incident procedures. Check how the organization identifies, classifies and escalates ICT incidents, and determine which reporting procedures apply to it.
  4. Set the testing programme. Establish which systems support critical or important functions, which testing cadence applies, and whether the entity is among those required to conduct threat-led penetration testing.
  5. Assess ICT supplier arrangements. Inventory relevant services and contracts, evaluate associated risk, and distinguish the firm’s own duties from any EU-level oversight of a provider designated as critical.
  6. Verify details with the competent authority. Consult the regulation, applicable implementing measures and the authority responsible for the entity. A high-level summary cannot determine a firm’s precise legal status or resolve detailed thresholds, classifications or procedures.

DORA is an active regulatory regime, not a proposed framework. The requirements and cadences described here are legal obligations, not evidence of a measured compliance rate or a quantified reduction in cyber incidents.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.