DORA is not a guideline — it is a binding EU regulation with real enforcement teeth. As supervisory authorities move into active enforcement in 2026, understanding the penalty framework is essential for board members, CISOs, and compliance officers.

Penalties for Financial Institutions

National competent authorities can impose administrative penalties including:

  • Administrative fines set by national law. This is the part most summaries get wrong: DORA does not fix a European ceiling for financial entities. Article 50 requires each Member State to give its competent authorities the power to penalise, and leaves the amount to national transposition — so the maximum you face depends on which supervisor you answer to, not on the Regulation.
  • Cease and desist orders requiring immediate remediation
  • Public disclosure of the identity of the entity and the nature of the breach
  • Temporary suspension of business activities
  • Withdrawal of authorisation in the most serious cases

Where does "2% of turnover" come from, then? Not from DORA. NIS2 is the likely source, and the wording matters: Article 34(4) requires Member States to provide for administrative fines with "a maximum of at least EUR 10 000 000 or of a maximum of at least 2 % of the total worldwide annual turnover" for essential entities. That is a floor on the national maximum, not an EU-wide ceiling — and it is calculated on ANNUAL turnover, where DORA’s only percentage (Art. 35(8), CTPPs) runs on average DAILY turnover. Same neighbourhood, different regime, different base. DORA contains exactly one turnover-based percentage of its own, and it does not apply to financial entities at all: designated critical ICT third-party providers face periodic penalty payments of 1% of average daily worldwide turnover under Article 35. Member States may additionally provide for criminal penalties under Article 52.

Penalties for Critical ICT Third-Party Providers

For designated Critical Third-Party Providers (CTPPs), the penalty framework is even more stringent:

  • Amounts set by the supervising Member State (Article 50)
  • Daily penalty payments of up to 1% of average daily global turnover for continued non-compliance, for up to six months
  • Mandatory adoption of specific measures dictated by the Lead Overseer
  • Requests to terminate contracts with non-compliant sub-contractors

Beyond Financial Penalties

The reputational damage from DORA enforcement may be more costly than the fines themselves:

  • Public statements: Regulators can publish the identity of the non-compliant entity
  • Client trust erosion: Institutional clients increasingly require DORA compliance as a procurement criterion
  • Audit escalation: Non-compliance triggers enhanced supervisory scrutiny
  • Insurance implications: Cyber insurance premiums may increase or coverage may be denied

Aggravating and Mitigating Factors

Regulators consider several factors when determining penalty severity:

Aggravating

  • Repeated non-compliance
  • Failure to cooperate with supervisory authorities
  • Deliberate concealment of incidents
  • Breaches affecting critical services across multiple Member States

Mitigating

  • Prompt self-reporting of breaches
  • Active cooperation with authorities
  • Demonstrable remediation efforts
  • First-time infringement with good compliance history

Board-Level Accountability

DORA explicitly places responsibility on the management body (board of directors) for ICT risk management. Board members can be held personally liable for systemic failures in digital operational resilience. This makes DORA compliance a C-suite priority, not just an IT concern.