How to Comply with DORA?
Table of Contents
# 1. Introduction: DORA in Brief
The Digital Operational Resilience Act (DORA) is a European regulation that imposes new obligations regarding cybersecurity, digital resilience, ICT service provider management and incident notification for the entire financial sector. It comes into application on 17 January 2025.
Its objective: to ensure that all financial entities and their IT service providers can withstand, respond to and recover from a cyber incident or digital failure.
2. Why comply with DORA?
- Legal obligation: DORA is a European regulation, therefore directly applicable.
- Cyber risk reduction: anticipation of major incidents.
- Increased trust from customers, partners and authorities.
- Avoiding penalties: penalty of 1% of global turnover per day for non-compliant service providers.
- Complementarity with GDPR, NIS 2, ISO 27001: DORA strengthens your overall compliance posture.
3. Which companies are concerned by DORA?
DORA concerns all European financial entities, including:
- Banks, insurers, mutual insurance companies
- Asset management companies
- Crypto-asset platforms
- Pension institutions, crowdfunding platforms
- ICT service providers (hosting providers, software publishers, SaaS, managed service providers, etc.)
In total, more than 22,000 entities in Europe are concerned.
4. The 6 main pillars of the DORA regulation
- ICT Governance and Cybersecurity
- Information and Communication Technology Risk Management
- Incident Detection, Classification and Notification
- Resilience Testing (including TLPT Penetration Testing)
- ICT Service Provider Oversight (contracts, audit, exit strategy)
- Information Sharing between Financial Actors and Authorities
5. Key steps to achieve compliance with DORA
- Identify critical functions
Map your critical business and IT processes. Classify them according to their impact on operations. - Assess your ICT risks
Implement a risk management methodology: vulnerabilities, obsolescence, dependencies, attack scenarios… - Update your contracts with ICT service providers
Add the clauses required by DORA (audit, reversibility, penetration testing, incident reporting, SLA, exit plan…). - Structure your cybersecurity governance
Define roles, committees, security policies, internal training. Implement a business continuity plan (BCP). - Implement a testing and audit plan
Schedule your internal audits, vulnerability scans, restoration tests, threat-led penetration tests (TLPT). - Document and track all your actions
Use a cybercompliance solution that ensures traceability, versioning, reports, audit evidence.
6. What are the risks in case of non-compliance?
- Financial sanctions: up to 1% of global turnover per day for 6 months for critical service providers.
- Contract termination imposed by the regulator (AMF, ACPR, AES).
- Direct liability of the financial entity even in case of subcontractor failure.
- Loss of trust from clients, partners and investors.
- Exclusion from calls for tender or regulated markets.