The Digital Operational Resilience Act (DORA) has been fully applicable since January 17, 2025. As enforcement ramps up, financial institutions and ICT service providers must understand the significant penalties they face for non-compliance.

DORA Penalty Framework Overview

DORA establishes a comprehensive penalty framework that includes both financial sanctions and non-financial measures. The regulation allows Member States to impose criminal penalties for severe violations.

Warning

DORA does reach individuals. Article 50(5) requires Member States to extend administrative penalties and remedial measures to members of the management body and to other individuals responsible under national law. The Regulation sets no EU-wide amount for them either — the ceiling is national.

Financial Penalties

For Financial Entities

Financial institutions found in breach of DORA may face:

  • An administrative fine whose ceiling is set by national law. Article 50(3) requires Member States to lay down penalties that are “effective, proportionate and dissuasive” and stops there — no amount, no percentage, no EU-wide ceiling.
  • Cease-and-desist orders and public notices naming the entity and the nature of the breach (Article 50(4)).
  • Personal exposure for management. Article 50(5) requires Member States to extend these penalties to members of the management body and to other individuals responsible under national law.

The 1% figure you may have seen does not apply here. It belongs to Article 35(8) and targets designated critical ICT third-party providers only — see the section below.

Where the “2% of turnover” figure actually comes from

It is not in DORA. Not in Article 50, not anywhere else: a full sweep of the Regulation returns only two other mentions of turnover, and neither is a penalty — Article 3 (the micro-enterprise definition) and Article 43 (oversight fees).

The figure belongs to NIS2. Article 34(4) of Directive (EU) 2022/2555 requires Member States to provide for administrative fines with “a maximum of at least EUR 10 000 000 or of a maximum of at least 2 % of the total worldwide annual turnover in the preceding financial year” for essential entities, whichever is higher; important entities sit at EUR 7 000 000 or 1.4% (Article 34(5)).

Three details are worth keeping straight, because they are what the shorthand loses:

  • NIS2 sets a floor on the national maximum (“a maximum of at least”), not an EU-wide ceiling. A Member State may go higher.
  • It is calculated on annual turnover. DORA’s only percentage runs on average daily turnover.
  • It applies to essential and important entities under NIS2 — not to financial entities under DORA.

The two texts share a vintage and a subject (Regulation 2022/2554 and Directive 2022/2555, both on digital resilience), which is almost certainly how the number migrated across.

For Critical ICT Third-Party Providers

CTPPs designated under DORA face:

  • Periodic penalty payments of up to 1% of average daily worldwide turnover in the preceding business year, charged daily until compliance and for no more than six months (Article 35(7)–(8))
  • Periodic penalty payments to compel compliance
  • Business restrictions limiting services to financial entities

For Individuals

Senior management and key function holders may face:

  • Penalties reaching responsible individuals, at amounts set by national law (Article 50(5))
  • Temporary bans from holding management positions
  • Criminal sanctions in severe cases (Member State dependent)

Types of DORA Violations

Tier 1: Most Serious Violations

These violations carry the highest penalties:

  • Failure to implement an ICT risk management framework
  • Not reporting major ICT incidents to authorities
  • Failure to conduct required resilience testing
  • No exit strategies for critical ICT providers
  • Obstruction of supervisory activities

Tier 2: Significant Violations

  • Incomplete Register of Information
  • Inadequate third-party risk management
  • Insufficient incident classification procedures
  • Non-compliant contractual arrangements with ICT providers

Tier 3: Administrative Violations

  • Late submission of required reports
  • Minor documentation gaps
  • Procedural non-compliance

Enforcement Mechanisms

Who Enforces DORA?

DORA enforcement involves multiple authorities:

Authority Role
National Competent Authorities (NCAs) Primary enforcement for financial entities
European Banking Authority (EBA) Oversight of banking sector compliance
ESMA Securities and markets supervision
EIOPA Insurance sector oversight
ESAs (Joint) Direct oversight of designated CTPPs

Enforcement Powers

Supervisory authorities have extensive powers including:

  • On-site inspections: Unannounced examinations of operations
  • Information requests: Mandatory data and document production
  • Interviews: Questioning of staff and management
  • Remediation orders: Mandatory corrective actions
  • Public warnings: Naming and shaming for violations
  • License suspension: In extreme cases, withdrawal of authorization

Aggravating and Mitigating Factors

Factors That Increase Penalties

  • Repeated violations
  • Deliberate non-compliance
  • Obstruction of investigations
  • Failure to remediate after warnings
  • Significant customer or market impact
  • Senior management involvement in violations

Factors That May Reduce Penalties

  • Self-reporting of violations
  • Full cooperation with authorities
  • Prompt remediation
  • First-time offense
  • Good faith compliance efforts
  • Minor actual impact

Criminal Penalties Under DORA

Article 52 of DORA allows Member States to impose criminal penalties for severe violations. This may include:

  • Criminal fines for individuals
  • Imprisonment in extreme cases
  • Director disqualification orders
  • Corporate criminal liability

Coordination with judicial and criminal justice authorities ensures effective enforcement at the national level.

Real-World Enforcement Scenarios

Scenario 1: Major Incident Not Reported

A bank suffers a significant cyber attack affecting 50,000 customers but fails to report within 72 hours.

Potential consequence: an administrative fine set under your national regime (Art. 50), plus a mandatory remediation programme.

Scenario 2: No TLPT Testing

A large investment firm has not conducted threat-led penetration testing as required.

Potential consequence: Significant fine plus mandatory testing within 90 days.

Scenario 3: Inadequate Third-Party Oversight

An insurance company cannot demonstrate adequate oversight of its cloud provider relationships.

Potential consequence: Remediation order, ongoing monitoring, potential fine.

How to Avoid DORA Penalties

Compliance Priorities

  1. Implement ICT risk management framework: The foundation of DORA compliance
  2. Establish incident reporting: Ensure 72-hour notification capability
  3. Conduct resilience testing: Schedule and document all required tests
  4. Manage third-party risk: Maintain Register of Information and contracts
  5. Document everything: Maintain comprehensive audit trails

Board and Management Responsibilities

To avoid personal liability, senior management must:

  • Approve and oversee the ICT risk management framework
  • Receive regular compliance reports
  • Allocate adequate resources for DORA compliance
  • Ensure proper governance structures
  • Demonstrate active engagement with ICT risk

What To Do If You Receive a Penalty Notice

  1. Respond promptly: Meet all deadlines for responses
  2. Engage legal counsel: Specialized regulatory expertise is essential
  3. Cooperate fully: Cooperation is a mitigating factor
  4. Document remediation: Show good faith efforts to address issues
  5. Consider appeals: Understand your appeal rights and deadlines

DORA Compliance Investment vs. Penalty Risk

Consider the cost-benefit analysis:

Compliance Investment Non-Compliance Risk
ICT risk framework implementation Up to 2% annual turnover fine
Incident reporting systems EUR 1M+ personal liability
TLPT and testing programs Operational restrictions
Third-party risk management Reputational damage

The cost of compliance is almost always less than the cost of non-compliance.

Start Your Compliance Journey

Don't wait for enforcement action. Download our free DORA Compliance Checklist to assess your readiness, or contact our experts for a gap analysis.