Cibernetica.io

Compliance

DORA

Operational resilience requirements for financial entities and the firms that serve them.

The Digital Operational Resilience Act is an EU regulation covering ICT risk in the financial sector. Unlike a directive, it applies directly across member states without national transposition, which makes its scope unusually consistent. It reaches both financial entities and the ICT providers that serve them.

The five pillars, and who is caught by them

DORA is organised around ICT risk management, incident reporting, digital operational resilience testing, ICT third-party risk management, and information sharing. Scope covers a wide range of financial entities — credit institutions, payment and e-money institutions, investment firms, insurers and intermediaries, crypto-asset service providers, and others — with proportionality provisions for smaller entities. The part that catches technology companies is third-party scope. Financial entities must maintain a register of information on ICT third-party arrangements, include specific contractual provisions, and manage concentration risk. Providers designated as critical ICT third-party service providers come under direct oversight. Providers not so designated still feel DORA through their customers' contractual requirements, which is how most technology suppliers first encounter it. Resilience testing obligations are risk-based, with threat-led penetration testing required of certain entities on a defined cycle. Working out which testing regime applies to you is part of scoping rather than something to assume.

Who needs it

  • Financial entities operating in the EU across banking, payments, investment, insurance, or crypto-asset services
  • Technology and ICT providers serving EU financial entities, receiving DORA contract requirements
  • Firms needing to build or improve their register of ICT third-party arrangements
  • Organisations working out which resilience testing regime applies to them

What you get

Scope and proportionality assessed

Whether DORA applies to you as a financial entity, as an ICT provider, or contractually — and what the proportionality provisions mean for an organisation your size.

Third-party register and contract review

The register of information and required contractual provisions are among the more mechanical obligations, and among the most commonly incomplete.

Testing scoped to the right regime

Resilience testing obligations vary by entity type and risk. Matching to testers who understand threat-led testing where that regime applies.

Frequently asked questions

Does DORA apply to us if we are a technology supplier rather than a financial firm?

Possibly, through two routes. Providers designated as critical ICT third-party service providers fall under a direct oversight framework. Everyone else supplying EU financial entities encounters DORA through their customers, who are required to include specific provisions in contracts and to assess their providers. Most technology companies meet DORA first as a contractual demand rather than a regulatory one.

How does DORA relate to UK operational resilience rules?

They address the same underlying concern and overlap substantially in substance, but they are separate regimes with separate requirements. The UK has its own operational resilience framework under the FCA and PRA. A firm operating in both the UK and EU needs to satisfy both rather than treating one as covering the other, though a single control environment can usually serve both with careful mapping.

What is the register of information?

A structured record of your ICT third-party arrangements — who your providers are, what functions they support, whether those functions are critical or important, and where the contractual terms sit. It has a prescribed format and must be maintained rather than compiled once. Firms that have never centralised supplier data typically find this the most laborious single obligation.

Do we need threat-led penetration testing?

Only certain entities, identified on a risk basis, are required to conduct advanced threat-led testing on a defined cycle. Others have proportionate testing obligations that are considerably less demanding. Establishing which category you fall into is a scoping question worth settling early, because the two regimes differ substantially in cost.