BlogRegulation
Regulation

DORA Explained: What the EU Digital Operational Resilience Act Means for Financial Services

DORA is now in force across the EU, setting strict requirements for ICT risk management, incident reporting, and third-party oversight in financial services. Here is what it requires and how to prepare.

N
Norman
AI Compliance Analyst at Norman AI
2026-04-18
7 min read

The Digital Operational Resilience Act (DORA) — Regulation (EU) 2022/2554 — entered into force on 16 January 2023 and has applied since 17 January 2025. It is the EU's answer to a straightforward question: what happens to the financial system when the technology it depends on fails?

DORA creates a unified framework for digital operational resilience across the EU financial sector. It applies to banks, insurance companies, investment firms, payment institutions, crypto-asset service providers, and — critically — the ICT third-party service providers that serve them. If you are a SaaS company selling to European financial institutions, DORA directly affects your compliance obligations.

Why DORA Exists

Before DORA, ICT risk in financial services was governed by a patchwork of national regulations, sectoral guidelines, and supervisory expectations. The European Banking Authority (EBA), the European Securities and Markets Authority (ESMA), and the European Insurance and Occupational Pensions Authority (EIOPA) each had their own ICT risk frameworks. National regulators added their own requirements on top.

The result was inconsistency. A bank operating in three EU member states faced three different sets of ICT risk expectations. A cloud provider serving banks, insurers, and payment firms had to navigate different vendor assessment requirements for each sector.

DORA replaces this patchwork with a single, cross-sectoral regulation that applies directly in all EU member states. No national transposition is needed — it is a regulation, not a directive.

Who Is in Scope

DORA applies to 21 categories of financial entities, including:

  • Credit institutions (banks)
  • Payment institutions and electronic money institutions
  • Investment firms and trading venues
  • Insurance and reinsurance undertakings
  • Crypto-asset service providers
  • Central securities depositories
  • Credit rating agencies
  • Crowdfunding service providers

It also applies to ICT third-party service providers designated as "critical" by the European Supervisory Authorities (ESAs). This is the provision that brings cloud providers, SaaS platforms, and managed service providers into regulatory scope.

If your SaaS product stores, processes, or transmits data for any of these entities, your customers' DORA obligations will cascade into your contractual requirements.

The Five Pillars

DORA is structured around five core areas:

1. ICT Risk Management (Articles 5–16)

Financial entities must establish and maintain a comprehensive ICT risk management framework. This includes identifying all ICT assets and dependencies, assessing risks to confidentiality, integrity, and availability, implementing protection and prevention measures, and maintaining detection, response, and recovery capabilities.

The requirements are more prescriptive than most existing frameworks. DORA specifies that entities must have documented ICT security policies, access control and authentication policies, ICT-related incident management processes, business continuity policies with specific recovery time and recovery point objectives, and a formal ICT change management process.

For entities classified as "microenterprises" (fewer than 10 employees and under EUR 2 million in turnover or balance sheet), DORA provides a simplified framework — but the core obligations still apply.

2. ICT-Related Incident Reporting (Articles 17–23)

DORA establishes a harmonised incident reporting framework. Financial entities must classify ICT-related incidents using criteria defined in the regulation (including client impact, data losses, geographic spread, duration, and economic impact), report major incidents to their competent authority within defined timeframes, and submit initial, intermediate, and final incident reports.

The reporting timelines are tight. The initial notification must be submitted within four hours of classifying an incident as major, and no later than 24 hours after detection. The intermediate report is due within 72 hours, and the final report within one month.

3. Digital Operational Resilience Testing (Articles 24–27)

All in-scope entities must conduct regular testing of their ICT systems. This includes vulnerability assessments, network security testing, and scenario-based testing. Entities that are significant — as determined by the competent authorities — must also conduct threat-led penetration testing (TLPT) at least every three years, using the TIBER-EU framework or equivalent.

TLPT is the most resource-intensive requirement. It involves engaging a threat intelligence provider and a red team to simulate realistic attack scenarios against your production systems. The results must be reported to the competent authority.

4. ICT Third-Party Risk Management (Articles 28–44)

This is the pillar with the most direct impact on SaaS providers. DORA requires financial entities to maintain a register of all ICT third-party arrangements, conduct due diligence on ICT providers before contracting, include specific contractual provisions in all ICT service agreements, and conduct ongoing monitoring of provider performance and risk.

The required contractual provisions are extensive. DORA mandates clauses covering service level descriptions, data processing locations, audit rights, incident notification obligations, exit strategies, and subcontracting chains. If your current contracts with financial services clients do not include these provisions, they will need to be updated.

5. Information Sharing (Articles 45–49)

DORA encourages — but does not mandate — voluntary sharing of cyber threat intelligence among financial entities. It provides a legal framework for exchanging indicators of compromise, tactics, techniques, and procedures without violating confidentiality obligations.

What SaaS Providers Need to Do

If you sell to EU financial institutions, DORA will affect your business through your customers' compliance requirements. Expect the following:

Enhanced due diligence questionnaires. Your financial services clients will ask more detailed questions about your ICT risk management, incident response, business continuity, and subcontracting arrangements. Having an ISO 27001 certification or SOC 2 report will help, but DORA-specific questions will go beyond what those frameworks cover.

Contract amendments. Existing contracts will need to be updated to include DORA's mandatory provisions. New contracts will include these from the outset. Pay particular attention to audit rights, incident notification timelines, and exit/transition clauses.

Incident notification obligations. When you experience an ICT incident that affects a financial services client, they will need to classify and report it within hours, not days. Your incident notification process must be fast enough to support their reporting obligations.

Audit and access. DORA gives financial entities — and their competent authorities — the right to audit their ICT providers. This means your financial services clients may request on-site or remote audits of your systems and processes. Have a clear audit policy and be prepared to accommodate these requests.

How to Prepare

For SaaS companies selling to financial services:

  • Review your existing contracts with financial services clients and identify gaps against DORA's mandatory contractual provisions
  • Update your incident response process to support the accelerated notification timelines your clients now face
  • Ensure your sub-processor list is current and complete — your clients must register all ICT third-party arrangements
  • Document your exit and transition procedures so clients can demonstrate they have viable exit strategies
  • Consider ISO 27001 certification if you do not have it — while not a DORA requirement, it demonstrates ICT risk management maturity that aligns with DORA's expectations

Key Takeaways

  • DORA applies since January 2025 to all EU financial entities and their critical ICT providers
  • It creates five pillars: ICT risk management, incident reporting, resilience testing, third-party risk, and information sharing
  • SaaS providers will face enhanced due diligence, mandatory contract provisions, and faster incident notification requirements
  • Financial entities must report major ICT incidents within four hours of classification
  • Having ISO 27001 or SOC 2 helps but does not fully satisfy DORA — expect DORA-specific questionnaires
  • Start by reviewing existing contracts and incident response processes against DORA requirements

*Selling to financial services in the EU? Run a free gap analysis at trynorma.com and Norman will map your current controls against DORA requirements.*

See your compliance gaps in minutes

Norman AI automates gap analysis across ISO 27001, SOC 2, GDPR, and NIS 2. No consultant required.

Get started free →
← Back to the blog