Know the Facts: Digital Operational Resilience Act (DORA)

  • Official Source Link: Read Here

  • Status & Jurisdiction: Enacted - European Union & Ireland

  • Target Organisations: Banks, Investment Firms, FinTechs, Crypto Asset Providers, Critical Cloud & ICT Vendors

  • Compliance Ranking: 🔴 Level 3 (see here)

1. Key Takeaways

  • Horizontal IT Risk Framework: Consolidates digital operational resilience rules across the entire EU financial services ecosystem.

  • Critical Vendor Oversight: Brings critical third-party ICT service providers (e.g. cloud platforms & data analytics firms) under direct European Supervisory Authority (ESA) oversight.

  • Strict Incident Reporting: Mandates initial reporting of major ICT incidents within hours to national competent authorities.

2. What is DORA?

It establishes a single operational risk management framework across the EU financial sector. It shifts regulatory focus from purely managing capital reserves to ensuring financial entities can withstand, respond to and recover from ICT disruptions.

DORA covers over 22 financial entity categories along with their external, critical ICT infrastructure providers.

3. Regulatory & Financial Impact on Businesses

  • Direct Obligations: In-scope firms must implement complete ICT risk-management frameworks, conduct annual Threat-Led Penetration Testing (TLPT), maintain incident logs and map vendor dependencies.

  • Indirect Supply Chain Pressures: Non-critical tech suppliers serving financial clients will face stringent contractual clauses, access audits and strict security requirements.

  • Penalties for Non-Compliance: Financial entities face national regulatory sanctions and administrative fines. Critical ICT vendors face oversight fees and periodic penalty payments of up to 1% of daily global turnover.

4. Implementation Timeline & Key Dates

16 January 2023 - Regulation entered into force.

17 January 2025 - Full legal application and enforcement across all EU Member States.

Previous
Previous

Know the Facts: Network and Information Security Directive (NIS2)

Next
Next

Know the Facts: Digital Markets Act (DMA)