In Effect European Union Fintech, SaaS

DORA

Digital Operational Resilience Act (EU) 2022/2554

Financial entities must implement a documented ICT risk management framework, report major incidents within 4 hours, and conduct Threat-Led Penetration Testing every three years; critical ICT third-party service providers face direct EU supervisory oversight.

Effective: January 17, 2025 Verified: July 2026 Official source

What this covers

DORA covers all EU-regulated financial entities under a single unified ICT risk management framework. Unlike previous sector-specific guidance, it applies consistently to banks, payment institutions, investment firms, insurance companies, and crypto-asset service providers. It became fully applicable on January 17, 2025.

The incident reporting timeline is strict: initial notification within 4 hours of classifying an event as major, intermediate report within 72 hours, and final root-cause report within one month. An incident qualifies as major based on impact criteria – data confidentiality, service availability, or transaction volume affected – not severity alone.

Significant financial entities must conduct Threat-Led Penetration Testing at least every three years. TLPT must be performed on live production systems by certified testers coordinated with the national competent authority – not isolated test environments. Remediation evidence is required after findings are disclosed.

Third-party ICT vendors designated critical by EU supervisory authorities face direct inspections and binding recommendations. Every financial entity must maintain an ICT third-party register and ensure contracts include audit rights, exit strategies, and defined SLAs. KYC vendors selling to EU banks and fintechs should expect DORA compliance questions in procurement cycles.

Frequently asked questions

Which entities must comply with DORA?

DORA applies to all EU-regulated financial entities – banks, payment institutions, crypto-asset service providers, investment firms, and insurance companies. ICT third-party service providers designated critical by EU supervisory authorities face direct inspections and binding recommendations, regardless of where they are headquartered.

What does DORA require for ICT incident reporting?

Financial entities must send an initial notification to the competent authority within 4 hours of classifying a major ICT incident, an intermediate report within 72 hours, and a final root-cause report within one month. Incidents affecting data confidentiality, integrity, availability, or authenticity trigger the obligation.

Does DORA require penetration testing?

Yes. Significant financial entities must conduct Threat-Led Penetration Testing (TLPT) at least every three years using certified testers on live production systems – not isolated test environments. Results must be disclosed to the national competent authority and used to remediate identified control weaknesses.

How does DORA affect third-party ICT vendors?

ICT vendors designated critical by EU authorities face direct supervisory inspections and binding recommendations. Every financial entity must maintain a register of ICT third-party arrangements and ensure contracts include audit rights, minimum security standards, and documented exit strategies.