DORA Regulation: The Complete Guide

By Rodrigo Lamadrid 13 August, 2026
DORA regulation

The DORA regulation is the European Union’s answer to a gap that had existed in financial regulation for years: rules that told banks and insurers how much capital to set aside for risk, but said almost nothing about how resilient their technology actually needed to be.

In this article, we’ll explain what this regulation is, who it applies to, the five pillars of the DORA framework, what DORA compliance actually means, the penalties for non-compliance, and how Mindsec helps you meet its requirements.

What Is the DORA Regulation?

The Digital Operational Resilience Act (DORA) is Regulation (EU) 2022/2554, published in the Official Journal of the European Union on December 27, 2022. Some sources informally call it the DORA law, though technically it’s a regulation, not a national statute. Unlike a directive, a regulation applies directly and identically across every EU member state, with no national transposition needed.

DORA entered into force on January 16, 2023, and became applicable on January 17, 2025, after a two-year transition period.

At its core, this DORA EU regulation requires financial entities to demonstrate they can withstand, respond to, and recover from any disruption involving information and communication technology (ICT), not just absorb the financial losses that follow one.

Who Does DORA Apply To?

The DORA regulation applies to a wide range of financial entities: banks, investment firms, insurers, payment institutions, crypto-asset service providers, trading venues, credit rating agencies, and the ICT third-party providers that support them. Over 22,000 entities across the EU fall within its scope.

This is narrower than NIS2 (Directive (EU) 2022/2555), the EU’s broader cybersecurity directive covering 18 sectors. The two regulations were adopted the same day and are closely related; DORA acts as lex specialis for the financial sector, meaning its rules take precedence over NIS2’s for entities it covers. We break this relationship down in detail in our DORA vs NIS2 comparison.

The DORA Framework: 5 Pillars

DORA requirements rest on five pillars, jointly overseen by the three European Supervisory Authorities: the European Banking Authority (EBA), the European Securities and Markets Authority (ESMA), and the European Insurance and Occupational Pensions Authority (EIOPA).

ICT risk management. A formal framework to identify, protect against, detect, respond to, and recover from ICT-related risks, with clear accountability at the management body level. This is the backbone of DORA cyber security requirements.

ICT-related incident management. Processes to detect, manage, and classify incidents, with major incidents reported to regulators on a strict timeline.

Digital operational resilience testing. This is where the DORA regulation gets hands-on: regular testing of ICT systems, including advanced threat-led penetration testing for larger entities.

ICT third-party risk management. A mandatory register of all contractual arrangements with ICT providers, plus specific contractual requirements for those providers.

Information sharing. Voluntary arrangements to exchange cyber threat intelligence among financial entities.

What Is DORA Compliance?

What is DORA compliance? It’s worth being precise here, because the market often talks about “DORA certification” as if it were an accredited credential like ISO 27001. It isn’t. There’s no independent body that certifies an organization as “DORA compliant.”

DORA compliance means demonstrating, through documentation, testing, and audit evidence, that your organization meets the requirements across all five pillars. National competent authorities supervise this, not a certification body.

DORA Requirements: What Organizations Need to Do

Meeting DORA requirements generally means:

  1. Map your ICT risk management framework. Document how you identify, assess, and mitigate ICT risk, with board-level sign-off.
  2. Build your incident classification and reporting process. You need to classify incidents by severity and report major ones within DORA’s timelines: initial notification within 4 hours of classification, an intermediate report within 72 hours, and a final report within a month.
  3. Establish a testing program. Basic resilience testing is required annually; larger entities need advanced threat-led penetration testing every three years.
  4. Build your ICT third-party register. Every contractual relationship with an ICT provider needs to be documented and kept current, a core piece of the DORA regulation third-party pillar.
  5. Prepare for oversight of critical providers. If you rely on ICT providers the ESAs designate as critical, expect additional scrutiny of that relationship.

DORA Regulation Penalties and Enforcement

DORA doesn’t set a single harmonized penalty cap for financial entities themselves. Instead, each EU member state’s national competent authority defines and enforces its own sanctions regime for entities under its supervision, similar in spirit to how GDPR enforcement works at the national level.

Critical ICT third-party providers (CTPPs) designated at the EU level are the exception. Under Article 35 of DORA, the ESAs can impose penalties directly on CTPPs of up to 1% of their average daily worldwide turnover, for a maximum of six consecutive months.

DORA Regulation Timeline

December 14, 2022. The DORA legislation and NIS2 are both adopted by the European Parliament and Council on the same day.

December 27, 2022. DORA is published in the Official Journal of the EU as Regulation (EU) 2022/2554.

January 16, 2023. DORA formally enters into force.

2023-2024. The ESAs publish technical standards in two batches, covering ICT risk management, incident reporting, testing, and third-party oversight.

January 17, 2025. DORA becomes fully applicable across the EU.

For how this timeline connects to NIS2’s own rollout, see our guide to the NIS2 directive.

Frequently Asked Questions About the DORA Regulation

DORA regulation summary: what’s the one-sentence version?

DORA is an EU regulation requiring financial entities and their critical ICT providers to prove they can withstand, respond to, and recover from technology-related disruptions, enforced by national authorities and the ESAs.

What are the DORA standards financial entities need to meet?

The five pillars: ICT risk management, incident management, resilience testing, third-party risk management, and information sharing, each detailed further in technical standards published by the EBA, ESMA, and EIOPA.

Does DORA overlap with GDPR?

It can. GDPR governs personal data protection; DORA governs operational and technological resilience. A bank handling customer data typically needs to satisfy both, since they address different regulatory objectives.

Is DORA a law or a regulation?

It’s an EU regulation, which functions differently from a national law. It applies directly in every member state without needing to be transposed into domestic legislation first.

Mindsec Makes DORA Compliance Easy

Meeting DORA requirements manually, across five pillars and dozens of technical standards, is exactly the kind of work that turns into a spreadsheet nightmare fast.

Mindsec centralizes your DORA compliance from end to end.

With Mindsec, you can:

  • Map your ICT risk management framework against DORA’s five pillars, without guessing what applies to you.
  • Automate incident classification and reporting, aligned to DORA’s strict notification deadlines.
  • Maintain your ICT third-party register in one place, always audit-ready.
  • Plan and track your resilience testing program, from annual testing to advanced threat-led exercises.
  • Manage your compliance with other frameworks like ISO 27001, SOC 2, and GDPR, all from one platform.

Don’t wait for a supervisory review to find your gaps. Book a 15-minute demo and see how Mindsec simplifies DORA compliance from A to Z.

Rodrigo Lamadrid

Mindsec staff

Why Stall? Book A Call

Need help complying with the DORA regulation? Book a call with our team and learn how we streamline this for you.

See Mindsec In Action