How to Comply with DORA?

How to Comply with DORA?

Table of Contents

    1. Introduction: DORA in brief
    2. Why comply with DORA?
    3. Which companies are covered by DORA?
    4. The 6 main pillars of the DORA regulation
    5. Key steps to achieve DORA compliance
    6. What are the risks of non-compliance?

# 1. Introduction: DORA in Brief

The Digital Operational Resilience Act (DORA) is a European regulation that imposes new obligations regarding cybersecurity, digital resilience, ICT service provider management and incident notification for the entire financial sector. It comes into application on 17 January 2025.

Its objective: to ensure that all financial entities and their IT service providers can withstand, respond to and recover from a cyber incident or digital failure.

2. Why comply with DORA?

  • Legal obligation: DORA is a European regulation, therefore directly applicable.
  • Cyber risk reduction: anticipation of major incidents.
  • Increased trust from customers, partners and authorities.
  • Avoiding penalties: penalty of 1% of global turnover per day for non-compliant service providers.
  • Complementarity with GDPR, NIS 2, ISO 27001: DORA strengthens your overall compliance posture.

3. Which companies are concerned by DORA?

DORA concerns all European financial entities, including:

  • Banks, insurers, mutual insurance companies
  • Asset management companies
  • Crypto-asset platforms
  • Pension institutions, crowdfunding platforms
  • ICT service providers (hosting providers, software publishers, SaaS, managed service providers, etc.)

In total, more than 22,000 entities in Europe are concerned.

4. The 6 main pillars of the DORA regulation

  1. ICT Governance and Cybersecurity
  2. Information and Communication Technology Risk Management
  3. Incident Detection, Classification and Notification
  4. Resilience Testing (including TLPT Penetration Testing)
  5. ICT Service Provider Oversight (contracts, audit, exit strategy)
  6. Information Sharing between Financial Actors and Authorities

5. Key steps to achieve compliance with DORA

  1. Identify critical functions
    Map your critical business and IT processes. Classify them according to their impact on operations.
  2. Assess your ICT risks
    Implement a risk management methodology: vulnerabilities, obsolescence, dependencies, attack scenarios…
  3. Update your contracts with ICT service providers
    Add the clauses required by DORA (audit, reversibility, penetration testing, incident reporting, SLA, exit plan…).
  4. Structure your cybersecurity governance
    Define roles, committees, security policies, internal training. Implement a business continuity plan (BCP).
  5. Implement a testing and audit plan
    Schedule your internal audits, vulnerability scans, restoration tests, threat-led penetration tests (TLPT).
  6. Document and track all your actions
    Use a cybercompliance solution that ensures traceability, versioning, reports, audit evidence.

6. What are the risks in case of non-compliance?

  • Financial sanctions: up to 1% of global turnover per day for 6 months for critical service providers.
  • Contract termination imposed by the regulator (AMF, ACPR, AES).
  • Direct liability of the financial entity even in case of subcontractor failure.
  • Loss of trust from clients, partners and investors.
  • Exclusion from calls for tender or regulated markets.