DORA Implementation Scenarios
Illustrative implementation scenarios for European financial entities. What a typical DORA programme covers, sector by sector.
Illustrative implementation scenarios for European financial entities. What a typical DORA programme covers, sector by sector.
How to read this page. Every scenario below is illustrative: it describes what an implementation programme under the Digital Operational Resilience Act (DORA, Regulation (EU) 2022/2554) typically covers for a given type of financial entity. These are not client engagements, and no real institution is described. Timelines are indicative planning ranges, not measured results.
A retail banking group operating in several Member States, with a large ICT estate spread across subsidiaries. The core challenge is harmonising one ICT risk management framework across entities that report to different competent authorities.
A payment service provider whose processing platform is a critical or important function (CIF) by definition: when it stops, merchants stop. Resilience testing and recovery objectives dominate the programme.
An asset manager whose portfolio management, order management and market data systems are almost entirely bought, not built. Most of its DORA exposure sits with ICT third-party service providers.
An insurance group with a long tail of ICT third-party service providers and legacy policy systems. The vendor ecosystem, not the technology, is where the programme spends most of its time.
Several mid-sized investment firms that cannot each justify a full threat intelligence capability. DORA explicitly allows them to share: Article 45 covers information-sharing arrangements between financial entities.
A crypto exchange authorised under MiCA, which brings it into DORA scope as a financial entity. Custody infrastructure and always-on trading make the ICT risk framework the centre of the programme.
A small digital-only bank with a cloud-native stack and a compliance team of one or two people. The full framework applies, but the proportionality principle shapes how deep each control needs to go.
A national payment system operator connected to European settlement infrastructure. Entities at this level of criticality are the natural candidates for threat-led penetration testing, run in coordination with their competent authority.
A mid-sized cooperative bank running a legacy core banking system across a wide branch network. The programme has to raise resilience without interrupting day-to-day banking in the communities it serves.
An e-money institution offering wallets and international transfers across many Member States. Incident reporting is the hard part: one outage can trigger notification duties in several jurisdictions at once.
A life insurer whose policy administration and actuarial systems hold decades of policyholder data. Disaster recovery for long-lived systems, and alignment with existing Solvency II reporting, drive the programme.
A retail trading platform where availability during market stress is the whole business. Testing has to cover the scenarios that matter: peak load, market data loss and degraded execution.
A crowdfunding service provider in DORA scope with a small technology footprint of its own: payments, KYC and hosting are all outsourced. Its resilience is largely its providers' resilience.
A mortgage bank whose origination, servicing and valuation chain runs on a mix of in-house systems and specialist providers. Outsourced links in the chain are where the resilience gaps usually hide.
An online broker running 24/7 trading across forex, commodities and CFDs. Incidents do not wait for office hours, so incident management has to work overnight and across jurisdictions.
Your Trusted Partner in DORA Compliance & Cybersecurity
Helping Financial Institutions Achieve Operational Resilience
Independent DORA Specialists Since 2023
Take our free compliance assessment and get personalized recommendations
Workbooks, playbooks and certifications built for EU financial entities. Add several to your cart: volume discounts apply automatically.
Take our free 5-minute assessment and get an instant DORA compliance score with personalised recommendations.