DORA FAQ

DORA Frequently Asked Questions

Find answers to common questions about Digital Operational Resilience Act compliance

19 questions answered Scope, deadlines & penalties

What is DORA (Digital Operational Resilience Act)?

DORA is an EU regulation that establishes a comprehensive set of requirements for financial institutions to manage ICT risks, ensure digital operational resilience, and test their readiness for cyber threats. It applies to banks, insurance companies, payment institutions, and other financial service providers across the EU.

When does DORA regulation come into effect?

DORA has applied since 17 January 2025. Financial entities have had to be fully compliant from that date, and competent authorities have been assessing compliance since 2025. The Regulation applies to all regulated financial entities in the EU.

What are the 5 pillars of DORA?

The 5 pillars of DORA are: (1) Governance and Risk Management Framework, (2) Incident Management, (3) Digital Operational Resilience Testing, (4) Third-Party Risk Management, and (5) Information Sharing.

What is Threat-Led Penetration Testing (TLPT) under DORA?

TLPT is an advanced security testing requirement where financial institutions must hire external testers to conduct realistic cyber attack simulations targeting their critical systems. Large institutions must conduct TLPT annually, medium institutions every 2 years, and smaller institutions every 3 years.

What are the penalties for DORA non-compliance?

DORA does not set an EU-wide maximum fine for financial entities. Article 50 requires each Member State to give its competent authorities the power to impose administrative penalties and remedial measures, and leaves the amount to national law, so the ceiling depends on where the entity is supervised. The only turnover-based percentage set by DORA itself applies to designated critical ICT third-party providers: periodic penalty payments of 1% of average daily worldwide turnover (Article 35). Member States may also provide for criminal penalties (Article 52).

Does DORA apply to small financial institutions?

Yes, DORA applies to all financial institutions regulated under EU financial services regulations, including small entities. However, smaller institutions may benefit from proportionality principles in implementation, with extended timelines for certain requirements like TLPT.

What is the difference between RTS and ITS in DORA?

RTS (Regulatory Technical Standards) provides framework-level requirements and specifications for DORA compliance, while ITS (Implementing Technical Standards) provides detailed technical specifications and implementation procedures. Both are developed by the EBA and are mandatory.

How does DORA affect cloud services and outsourcing?

Cloud services are ICT services under DORA, so the contract rules of Article 30 apply. Every contract must carry the nine elements of Article 30(2), including the regions or countries where data is processed and stored, with advance notice of any change, and termination rights. Where the cloud service supports a critical or important function, Article 30(3) adds unrestricted access, inspection and audit rights and an exit strategy with a mandatory transition period, and Article 28(8) requires the financial entity to have an exit strategy. The largest providers can be designated as critical ICT third-party providers and overseen by an EU Lead Overseer, which does not change the clauses the contract needs.

What must be included in DORA incident reporting?

Major ICT incidents follow a three-stage reporting sequence to the competent authority: an initial notification within 4 hours of classifying the incident as major (and no later than 24 hours after becoming aware of it), an intermediate report within 72 hours, and a final report within one month. Reports must include the incident classification, impact assessment, affected systems, financial impact, client implications, and the remediation measures being taken.

How can we prepare for DORA compliance?

Begin by conducting a comprehensive gap analysis against DORA requirements, establish governance structures, inventory critical ICT systems, assess third-party dependencies, implement necessary controls, establish incident management procedures, and conduct testing to ensure readiness.

Under DORA, what type of incidents should be classified and notified?

Financial entities must classify ICT-related incidents and notify those that qualify as "major" using the criteria in RTS (EU) 2024/1772: clients/financial counterparts affected, reputational impact, duration and service downtime, geographical spread, data losses, criticality of services affected, and economic impact. An incident is major when it crosses the relevant primary and secondary thresholds. Significant cyber threats may be reported voluntarily. Major incidents trigger the 4-hour, 72-hour and 1-month reporting clock.

What are the DORA incident reporting timelines?

For a major ICT-related incident: an initial notification is due within 4 hours of classifying it as major (and no later than 24 hours after detection), an intermediate report within 72 hours, and a final report within 1 month. Reports are submitted to the competent authority using the templates in RTS/ITS (EU) 2025/301 and 2025/302.

What is the DORA Register of Information?

The Register of Information (DORA Article 28(3)) is a machine-readable register of all contractual arrangements for ICT services provided by third parties. Entities report it annually to their national competent authority in xBRL-CSV format using the 15 templates of ITS (EU) 2024/2956. The ESAs use the aggregated data to designate Critical ICT Third-Party Providers and assess concentration risk. Most 2026 national deadlines fall at the end of Q1 2026.

What is a Critical or Important Function (CIF) under DORA?

A Critical or Important Function (DORA Article 3(22)) is a function whose disruption would materially impair an entity's financial performance, the soundness or continuity of its services, or its compliance with authorisation conditions. CIF identification is the cornerstone of DORA: it drives Register of Information flagging, third-party contractual obligations, TLPT scope and incident classification.

Who must perform Threat-Led Penetration Testing (TLPT) under DORA?

TLPT applies to financial entities identified by competent authorities based on their systemic importance and ICT risk profile, not to every entity. Designated entities must run intelligence-led red-team tests on live critical systems at least every 3 years, following the TIBER-EU framework, using qualified threat-intelligence and red-team providers.

How does DORA differ from NIS2?

DORA is a lex specialis for the EU financial sector and prevails over NIS2 for the ICT risk of in-scope financial entities. NIS2 is the broader cross-sector cybersecurity directive. Where both could apply, financial entities follow DORA for ICT risk management, incident reporting and third-party oversight, while NIS2 continues to cover sectors and activities outside DORA's scope.

What contractual clauses does DORA require with ICT providers?

DORA Article 30 works in two tiers, set by the function the ICT service supports rather than by who the provider is. Article 30(2) requires nine elements in every ICT contract: a full description of the services and of any permitted subcontracting, service and data locations, data protection, access to and return of data on exit or insolvency, service level descriptions, incident assistance, cooperation with competent and resolution authorities, termination rights with minimum notice periods in line with the expectations of those authorities, and participation in security awareness and resilience training. Article 30(3) adds six elements when the service supports a critical or important function: quantified service levels, notice and reporting obligations, tested business contingency plans and security measures, participation in threat-led penetration testing, unrestricted access, inspection and audit rights, and an exit strategy with a mandatory transition period. A provider's designation as a critical ICT third-party provider does not change which clauses apply.

Is there an official DORA compliance checklist?

DORA does not publish a single official checklist, but compliance maps to its 5 pillars: ICT risk management governance, incident management and classification, digital operational resilience testing (including TLPT where applicable), ICT third-party risk and the Register of Information, and information sharing. Our free interactive checklist covers 45 control points across these pillars.

Which Critical ICT Third-Party Providers (CTPPs) have been designated?

On 18 November 2025 the European Supervisory Authorities published the first list of 19 designated critical ICT third-party service providers (CTPPs), including the major cloud hyperscalers, data centre and telecommunications operators, IT services companies, and financial data and technology providers. Each is overseen by a Lead Overseer (EBA, EIOPA or ESMA), which can request information, run investigations and inspections, and issue recommendations (Article 35). Designation does not change the Article 30 clauses a financial entity needs: those depend on whether the service supports a critical or important function. The one CTPP-specific condition for financial entities is Article 31(12): a CTPP established in a third country must set up a subsidiary in the Union within 12 months of its designation for financial entities to keep using it.

Go Deeper on These Topics

All RTS & ITS Technical Standards Incident Reporting Timelines & Templates TLPT: Complete Pillar Guide DORA Penalties & Fines Guide Third-Party Risk Management DORA Gap Analysis Tool (Free) DORA Compliance Timeline What is DORA? Full Explainer DORA vs NIS2 Explained

Need More Detailed Information?

Explore our comprehensive guides and resources for detailed DORA compliance information.

Read Our Blog Download Guides

Practitioner tools for DORA compliance teams

Workbooks, playbooks and certifications built for EU financial entities. Add several to your cart: volume discounts apply automatically.

academy-bundle

DORA Certifications Bundle

399 € excl. VAT
academy

DORA for IT & Security Teams

199 € excl. VAT
academy

DORA for ICT Providers & Vendors

199 € excl. VAT
201
certificates issued
132
certified professionals
22
programmes awarded

Browse the full library · Excel toolkits · Certifications

How Compliant Is Your Institution?

Take our free 5-minute assessment and get an instant DORA compliance score with personalised recommendations.

Get Your Free DORA Score Join the Webinar Waiting List