DORA Is Live. Here's What EU Financial Firms Must Do Right Now
The Digital Operational Resilience Act — DORA — entered into force across the EU on 17 January 2025. For banks, investment firms, insurance companies, payment institutions, crypto-asset service providers, and their critical ICT third-party providers, this is not a regulation to prepare for. It is a regulation to be compliant with today.
This guide covers what DORA requires, who it applies to, what regulators are looking for in 2025, and how to build an ICT risk management framework that meets the standard.
Who DORA Applies To
DORA applies to a broad range of financial entities regulated under EU law. This includes credit institutions, payment institutions, electronic money institutions, investment firms, crypto-asset service providers under MiCA, central securities depositories, central counterparties, trading venues, insurance and reinsurance undertakings, and management companies.
Critically, DORA also applies to ICT third-party service providers designated as critical by the European Supervisory Authorities (ESAs). Cloud providers, data analytics firms, and software vendors serving the financial sector are therefore within DORA's scope — even if they are not themselves financial entities.
If your firm operates in the EU financial sector or provides ICT services to entities that do, DORA applies to you.
The Five Pillars of DORA
Pillar 1: ICT Risk Management
Financial entities must establish a comprehensive ICT risk management framework as an integral part of their overall risk management system. This framework must include policies, procedures, protocols, and tools to protect all ICT assets and detect anomalous activity. The management body — board or equivalent — bears ultimate responsibility for ICT risk and must approve, oversee, and review the framework annually.
The framework must cover: ICT risk identification and classification, protection and prevention measures, detection mechanisms, response and recovery capabilities, and learning and evolving processes post-incident.
Pillar 2: ICT Incident Management and Reporting
Financial entities must implement a dedicated process for monitoring, managing, and reporting ICT-related incidents. Major incidents must be reported to competent authorities within strict timeframes: an initial notification within 4 hours of classification (no later than 24 hours after detection), an intermediate report within 72 hours, and a final report within one month.
The classification of what constitutes a major incident follows criteria set by the ESAs, including impact on clients, data loss, service downtime, and geographic spread. Firms must have the systems and processes in place to detect, classify, and escalate incidents within these windows.
Pillar 3: Digital Operational Resilience Testing
Financial entities must conduct regular ICT resilience testing. Basic testing — vulnerability assessments, network security assessments, gap analyses — must be conducted annually by all in-scope firms. Significant financial entities must additionally conduct Threat-Led Penetration Testing (TLPT) at least every three years.
TLPT is a sophisticated exercise simulating a real-world advanced persistent threat attack on the firm's live production systems. It requires coordination with competent authorities and must be conducted by certified external testers. The results must feed directly into remediation planning.
Pillar 4: ICT Third-Party Risk Management
Financial entities must manage ICT third-party risk as part of their ICT risk management framework. This includes pre-contractual due diligence, mandatory contract provisions, continuous monitoring, and exit strategy requirements.
All contracts with ICT third-party providers must include provisions on service levels, audit rights, incident notification obligations, data location and portability, and termination rights. Firms must maintain a register of all ICT third-party arrangements and report this to competent authorities on request.
Pillar 5: Information Sharing
DORA encourages — and in some cases requires — financial entities to share cyber threat intelligence with each other and with competent authorities. Voluntary arrangements for sharing information and intelligence on cyber threats are explicitly supported by the regulation.
What Regulators Are Looking For in 2025
National competent authorities across the EU began supervisory engagement on DORA compliance from January 2025. Based on early enforcement signals, four themes are emerging.
First, governance substance. Regulators want to see genuine board-level ownership of ICT risk — not just a policy signed by the board, but evidence that the board receives regular, meaningful reporting on ICT risks, incidents, and testing results. Board minutes and committee structures are being reviewed.
Second, third-party register completeness. The ICT third-party register is one of the first things supervisors will ask for. Firms with incomplete or poorly maintained registers — missing critical vendors, lacking contract detail, unable to evidence due diligence — are being flagged.
Third, incident classification capability. Supervisors are probing whether firms have the systems and trained personnel to classify an incident as major within the required timeframes. Tabletop exercises and incident response walkthroughs are being requested.
Fourth, testing programme maturity. Firms without an established, documented testing programme — covering both basic and advanced testing where applicable — are being required to develop and submit one.
Building Your DORA Compliance Program
A DORA compliance program is not a one-time project. It is an ongoing operational discipline. The firms navigating DORA successfully treat it as a permanent part of their risk management infrastructure.
Start with a scoping and gap assessment. Map your firm against DORA's requirements across all five pillars. Identify where you currently meet requirements, where gaps exist, and prioritise remediation by regulatory risk and remediation complexity.
Build your ICT risk management framework documentation. This is the foundation of DORA compliance — policy documents, procedural guides, system inventories, risk registers, and governance structures. Each must be current, version-controlled, and accessible for supervisory review.
Establish your incident management workflow. Define classification criteria, escalation paths, reporting templates, and the systems through which incidents are tracked. Run tabletop exercises to test the workflow before a real incident occurs.
Build your third-party register. List every ICT vendor, review your contracts against DORA's mandatory provisions, and document your due diligence process for each. This is an ongoing exercise as vendors are added, changed, or removed.
Develop your testing programme. Schedule basic testing annually. If you are a significant financial entity, begin the TLPT scoping process — identifying scope, coordinating with your NCA, and procuring certified testers takes time.
How RegentComply Supports DORA Readiness
RegentComply.ai provides a structured DORA readiness environment built around the regulation's five pillars. You can run a full gap assessment, assign remediation tasks to team members, store evidence against each requirement, and track your programme against your compliance timeline — all in one platform.
The platform is free to start. You pay only for AI features — document drafting, gap analysis, policy generation — when you need them. No procurement process, no IT approval, no implementation delay.
Want to see how RegentComply maps to your DORA obligations? Book a demo today.
👉 Request a Demo: https://regentcomply.ai/request-demo
The Supervisory Risk of Non-Compliance
DORA's enforcement regime is significant. Competent authorities can impose periodic penalty payments on financial entities that fail to remedy non-compliance — up to 1% of average daily worldwide turnover for each day of non-compliance, for up to six months. For critical ICT third-party providers, the ESAs can impose fines up to 1% of average daily worldwide turnover per day, for up to six months.
Beyond financial penalties, supervisory intervention can include public censure, temporary restriction of activities, and — in extreme cases — withdrawal of authorisation.
Act Now
DORA is in force. Supervisory engagement is active. The firms that treat DORA as a live compliance obligation — building robust frameworks, maintaining complete registers, running regular testing, and engaging proactively with their NCA — will navigate 2025 successfully.
Those that treat it as a future problem will not.
RegentComply.ai helps regulated firms across the EU build and manage their DORA compliance programs from day one — free to start, with AI-powered tools available on demand.
👉 Book your demo: https://regentcomply.ai/request-demo