Everything you need to know about DORA
The Digital Operational Resilience Act (DORA) is the European regulation on digital operational resilience for the financial sector. Effective since January 17, 2025, it strengthens IT risk management, incident reporting and oversight of critical providers.
Jan 17, 2025
Effective date
22,000
Financial entities in the EU
5 pillars
Risk, incidents, tests, third parties, info sharing
1% revenue
Daily fine for non-compliance
What is DORA?
DORA (Digital Operational Resilience Act) is the European regulation on digital operational resilience of the financial sector. Effective since January 17, 2025, it aims to standardise the rules on financial cyber risk across the EU.
Who is concerned?
DORA concerns over 22,000 financial entities and their critical IT providers across the EU.
Banks and credit institutions
Insurance and reinsurance companies
Asset managers and investment firms
Payment and electronic money institutions
Crypto-asset service providers
Critical ICT third-party service providers
The 5 pillars of DORA
DORA structures its obligations around 5 key pillars.
ICT risk management: governance, framework, business continuity
Incident management & reporting: detection, classification, notification
Digital operational resilience testing: regular tests, TLPT for critical entities
Third-party risk management: contracts, oversight, exit strategy
Information sharing: voluntary cyber threat intelligence sharing
Simplifiez votre conformité DORA avec Data Comply One
DORA + NIS2 software
ICT register, risk analysis, incident management, ICT supply chain.
Discover the softwareOutsourced CISO DORA
Financial cyber expert who manages your DORA compliance.
Schedule a chatDORA training
Train your finance teams on DORA fundamentals.
View the programDORA audit
Assess your readiness for the regulation.
Request an auditFAQ DORA
Prêt à piloter votre conformité DORA ?
30 minutes pour évaluer vos enjeux, sans engagement.
Ils nous font confiance
Plus de 1 000 entreprises et organisations nous font confiance








































































































































































Découvrir les autres réglementations européennes
Construisez une vision globale de votre conformité multi-réglementaire.
RGPD
Protection des données personnelles UE.
DécouvrirNIS 2
Cybersécurité européenne · entités essentielles & importantes.
DécouvrirAI Act
Gouvernance des systèmes d'intelligence artificielle.
DécouvrirData Act
Partage et accès aux données B2B / B2G.
DécouvrirnLPD
Loi suisse sur la protection des données.
DécouvrirDécouvrir les autres solutions DCO
Combinez plusieurs solutions pour une approche globale de votre conformité.
DPO externalisé
Un DPO désigné CNIL pour piloter votre RGPD.
DécouvrirRSSI externalisé
Un RSSI dédié pour la cybersécurité (NIS 2 · DORA).
DécouvrirPlateforme logicielle
Le logiciel tout-en-un de pilotage de la conformité.
DécouvrirFormation e-learning
Sensibilisez vos équipes avec Daia (RGPD · IA · Cyber).
Découvrir