Everything You Need to Know About the DORA Regulation
1. What is the DORA regulation?
The DORA regulation (Digital Operational Resilience Act) is a European regulation (EU 2022/2554) aimed at strengthening the digital operational resilience of the financial sector. It imposes strict requirements regarding cybersecurity, ICT risk management, resilience testing, and oversight of critical service providers.
2. When does DORA come into force?
The regulation came into force on January 16, 2023, but its application is mandatory from January 17, 2025. Companies must be fully compliant by that date.
3. Who is covered by the DORA regulation?
DORA applies to more than 22,000 financial entities in the EU, such as:
- Banks, insurers, payment institutions,
- Asset managers, crypto-asset platforms,
- Pension institutions, rating agencies,
- And also ICT service providers considered critical for these entities.
4. What are the main obligations imposed by DORA?
DORA's requirements cover 6 major areas:
- Strengthened cybersecurity governance,
- Structured management of ICT risks,
- Detection, classification and notification of incidents,
- Conducting resilience tests (including TLPTs),
- Management of ICT service providers, especially in cases of critical outsourcing,
- Information sharing between sector actors and authorities.
5. What types of security tests does DORA impose?
DORA notably requires threat-led penetration testing (TLPT), every 3 years, for systemic entities. These tests must simulate real cyberattacks according to the TIBER-EU method.
# 6. What should companies do with their ICT service providers?
Companies must:
- Update their contracts (clauses, reversibility, audits, SLA...)
- Assess the criticality of the outsourced ICT service,
- Require certifications, audits, security reports,
- Impose tested business continuity and contract exit plans,
- Provide for access, inspection, and security testing rights over service providers.
7. What penalties for non-compliance?
Sanctions can reach 1% of global turnover/day for 6 months for critical providers. Financial entities also risk an injunction to terminate any contract with a non-compliant provider.
8. What is the difference between DORA and NIS 2?
DORA is specific to the financial sector and constitutes a "lex specialis" of the NIS 2 directive. NIS 2 applies to a broader spectrum of essential and important organizations. For financial actors, both texts can coexist.
9. How to know if an ICT service provider is critical under DORA?
A service provider is considered critical if:
- It provides critical ICT services to numerous systemic entities,
- Its substitutability is low,
- Its failure could impact the financial stability of the EU,
- It operates a concentration of services or strong dependencies.
10. Are there tools or software to facilitate DORA compliance?
Yes, cybercompliance software allows you to:
- Centralize audits, incidents, business continuity plans,
- Manage regulatory obligations (ICT, security, contractualization),
- Monitor compliance continuously with indicators and alerts,
- Be supported by DPO or cybersecurity experts.
11. How to start your DORA compliance?
- Identify the critical functions of your information system,
- Map your ICT providers and their criticality levels,
- Update contracts according to DORA requirements,
- Assess your security posture, your tests, your audits,
- Launch a governance strategy, an action plan and a DORA audit.