SIS-licensed ISO clauses and controls·an add-on inside the AI clients and agents you already use
    DORA

    DORA, explained for the teams who have to comply.

    DORA — Regulation (EU) 2022/2554, the Digital Operational Resilience Act — is the EU's ICT-resilience law for the financial sector. As a regulation it is directly applicable, no national transposition needed, and it has applied since 17 January 2025. It reaches twenty types of financial entities and the ICT providers that serve them.

    Applicability

    Who is in scope

    Twenty types of financial entities, plus the ICT providers that serve them.

    Obligations

    The five pillars

    Five blocks of duties, each anchored in a specific chapter of the regulation.

    Enforcement

    Two enforcement tracks

    Financial entities answer to national authorities; critical ICT providers answer to an EU Lead Overseer.

    DORA and NIS2

    A regulation, and the sector carve-out

    Directly applicable since 17 January 2025 — and for financial entities, it displaces NIS2.

    How Ansvar helps

    From article text to cited gap analysis

    Every answer grounded in the regulation, in the AI client your team already uses.

    FAQ

    Questions teams ask about DORA

    If your question is not here, email us — every message gets a human answer.

    Does DORA apply to my company?

    DORA applies to twenty types of financial entities listed in Article 2(1)(a) to (t) — credit institutions, payment institutions, account information service providers, e-money institutions, investment firms, crypto-asset service providers and issuers of asset-referenced tokens, central securities depositories, central counterparties, trading venues, trade repositories, fund managers, data reporting service providers, insurance and reinsurance undertakings and intermediaries, occupational pension institutions, credit rating agencies, critical-benchmark administrators, crowdfunding providers, and securitisation repositories — plus, under point (u), the ICT third-party service providers that serve them. Article 2(3) carves out, among others, small occupational pension schemes (15 or fewer members) and insurance intermediaries that are micro, small or medium-sized enterprises. If you sell ICT services to banks or insurers, DORA reaches you through your customers' contracts even before any designation as critical.

    Is DORA a regulation or a directive — do I need to wait for national law?

    DORA is a regulation: Article 64 makes it binding in its entirety and directly applicable in every Member State, and it has applied since 17 January 2025. There is no transposition to wait for, unlike NIS2. Member States still play two roles: they lay down the administrative penalties under Article 50, and their competent authorities supervise. The technical detail — incident-report templates and time limits, the register-of-information template, TLPT methodology — sits in regulatory and implementing technical standards the European Supervisory Authorities drafted under the regulation.

    What are the five DORA pillars?

    The regulation groups its obligations into five blocks: ICT risk management (Articles 5 to 16 — governance, a documented risk-management framework, and a digital operational resilience strategy); ICT incident management, classification and reporting (Articles 17 to 23); digital operational resilience testing (Articles 24 to 27, up to threat-led penetration testing); ICT third-party risk management (Articles 28 to 30, plus the Union oversight framework for critical providers in Articles 31 to 44); and information-sharing arrangements on cyber threats (Article 45).

    What are the DORA incident-reporting deadlines?

    Article 19(4) sets the structure: an initial notification, an intermediate report when the incident's status changes significantly or on the authority's request, and a final report once the root-cause analysis is complete. The regulation itself does not put hour figures on those steps — Article 19(4) defers the time limits and templates to the technical standards developed under Article 20. Article 19(3) adds a client-facing duty: where a major incident affects clients' financial interests, you inform them without undue delay, together with the measures taken. Significant cyber threats may be notified voluntarily under Article 19(2).

    Who has to run threat-led penetration testing (TLPT)?

    Not everyone. Every financial entity other than a microenterprise runs a risk-based resilience testing programme, and tests all systems supporting critical or important functions at least yearly (Article 24). On top of that, the competent authority identifies specific entities — weighing sector impact, financial-stability concerns and ICT risk profile — that must run TLPT at least every three years on live production systems (Article 26). Internal testers are allowed, but every third test needs an external one, and significant credit institutions must always use external testers. The RTS follows the TIBER-EU framework.

    What must our ICT contracts contain under DORA?

    Article 30(2) sets the minimum content of every ICT-service contract — among it: a full description of the services with the conditions for any subcontracting of critical functions, data-processing locations with advance notice of changes, data-protection provisions, access and recovery of data on exit or insolvency, service levels, incident assistance at a pre-agreed cost, cooperation with authorities, termination rights with minimum notice, and conditions for the provider's participation in your security-awareness training. Contracts supporting critical or important functions add Article 30(3): precise quantitative service-level targets, notice duties, contingency-plan testing, participation in your TLPT, unrestricted audit and inspection rights, and a mandatory transition period on exit. Article 28(3) requires you to maintain a register of information covering all ICT contracts, report yearly on new arrangements, and hand over the full register when your authority asks.

    What are the DORA fines?

    For financial entities, DORA sets no EU-wide fine ceiling. Article 50 leaves administrative penalties to Member State law, requiring them to be effective, proportionate and dissuasive, and lets authorities apply penalties to members of the management body personally. So the exposure depends on where you are supervised. The one figure in the regulation targets critical ICT third-party service providers: a Lead Overseer can impose a periodic penalty payment of up to 1% of average daily worldwide turnover, charged daily for up to six months, to compel compliance (Article 35(6) to (8)).

    We already comply with NIS2 — does DORA still apply?

    For financial entities, DORA takes priority. NIS2's Article 4 treats DORA as sector-specific Union law: where DORA's requirements are at least equivalent, the matching NIS2 provisions do not apply to those entities. In practice a bank or insurer builds to DORA, not NIS2 — while a fintech that is not one of the Article 2 entity types may still land in NIS2 as a digital provider. The two laws share DNA (risk measures, staged incident reporting, management accountability), but DORA is stricter on testing, third-party contracts and the register of information.

    See where you stand on DORA

    A free-tier run produces a cited DORA gap analysis of a system you describe — one row per obligation, each anchored to its article. Start there, then bring your own documents on a paid plan.