Insights

EU financial institution protected from cyber threats, explaining what is DORA, the Digital Operational Resilience Act.
What is DORA (The Digital Operational Resilience Act)?

You will likely have seen and heard plenty of chatter about DORA, an EU Act that has been making its way down the track for a couple of years and, as of 17 January 2025, is now in force.

Many of the clients we speak to are curious about whether it affects them, and there remains a genuine degree of uncertainty among UK organisations with EU operations as to whether they fall in scope. So, let’s go through it at a high level.

The regulation in a nutshell

So what is The Digital Operational Resilience Act, DORA, is a comprehensive set of rules establishing clear, uniform requirements for the operational resilience of financial entities operating in the EU, and of the critical ICT providers that serve them, wherever those providers happen to be based.

Its purpose is to harmonise operational resilience rules across the financial sector. The logic behind it is, frankly, sobering: the European Systemic Risk Board warned in 2020 that the financial sector’s deeply interconnected ICT systems represent a systemic vulnerability; a localised cyber incident could, in principle, cascade rapidly across the roughly 22,000 financial entities in the EU and into the wider financial system.

DORA is the regulatory response. Rather than each Member State (or each firm) deciding for itself what “resilient” means, everyone should now be working to the same standard (excluding, of course, matters of national security).

Who is in scope?

DORA applies to twenty types of financial entities such as banks, insurers, investment firms, payment institutions, crypto-asset service providers and more – plus the ICT third parties that provide them with critical services. On that last point, it is worth noting that direct EU oversight of ICT providers currently focuses on those formally designated as critical in practice, the large multinational providers.

That third-party dimension deserves emphasis, because it is where UK organisations could get caught. You do not need to be a financial entity, or based in the EU, to feel DORA’s reach.

An example: Acme Banking Organisation is headquartered in Spain, with turnover just shy of €50 million, bringing it into scope as a medium-sized enterprise. Acme has a long-term contract with a UK-based multinational ICT provider that looks after access management, backups and cloud infrastructure for its investment platform. Those are critical services, which means the UK provider must also align with DORA’s requirements, otherwise Acme cannot be compliant. The regulation flows down the supply chain.

For completeness, here are the entities in scope, per Article 2(1) of DORA:

  1. Credit institutions
  2. Payment institutions, including those exempted pursuant to Directive (EU) 2015/2366
  3. Account information service providers
  4. Electronic money institutions, including those exempted pursuant to Directive 2009/110/EC
  5. Investment firms
  6. Crypto-asset service providers and issuers of asset-referenced tokens
  7. Central securities depositories
  8. Central counterparties
  9. Trading venues
  10. Trade repositories
  11. Managers of alternative investment funds
  12. Management companies
  13. Data reporting service providers
  14. Insurance and reinsurance undertakings
  15. Insurance intermediaries, reinsurance intermediaries and ancillary insurance intermediaries
  16. Institutions for occupational retirement provision
  17. Credit rating agencies
  18. Administrators of critical benchmarks
  19. Crowdfunding service providers
  20. Securitisation repositories
  21. ICT third-party service providers

Closer to home, the UK is following suit: the Cyber Security and Resilience Bill has now cleared the House of Commons and is before the House of Lords, with Royal Assent expected later this year. It will bring data centres, managed service providers, critical national infrastructure suppliers and adjacent providers, such as operators controlling large energy loads, including EV charging networks, into a strengthened UK regime. We will go into the Bill in another post, but a quick tip for now: if you align with DORA, you stand a good chance of being well on the way to aligning with the Cyber Security and Resilience Bill too.

Who is out?

DORA carves out certain organisations that are either already lightly regulated or exempt under other EU financial rules: some alternative investment fund managers, certain insurance and reinsurance firms, pension schemes with 15 or fewer members, and insurance, reinsurance and ancillary insurance intermediaries that qualify as micro, small or medium-sized enterprises.

Proportionality: organisation size still matters

Being in scope does not mean every organisation faces the same burden. DORA categorises financial entities by size: microenterprises (fewer than 10 employees and turnover or balance sheet of €2 million or less), small enterprises (10 to 49 employees, €2–10 million) and medium-sized enterprises (fewer than 250 employees, turnover up to €50 million or balance sheet up to €43 million). Entities above these thresholds are considered large and will be expected to commit resources to dedicated governance structures – the regulation recognises that larger entities have deeper pockets for exactly that.

Microenterprises in scope, by contrast, are not expected to maintain elaborate governance, risk and compliance machinery; they simply need to be able to demonstrate how they comply.

The five pillars of DORA

DORA’s requirements are organised around five key areas, and they are prescriptive, not aspirational.

  • ICT risk management. Organisations must implement a robust framework to proactively identify, monitor and mitigate ICT risks, from cyberattacks to plain system failures, before they become disruptions. This is not a once-a-year risk register review; it is a living capability, owned at management body level.
  • Incident reporting. Major ICT-related incidents must be classified, managed and reported to regulators within defined timeframes. The days of quietly fixing an outage and moving on are over.
  • Digital operational resilience testing. Entities must regularly test their defences, up to and including threat-led penetration testing for larger firms. It is one thing to believe your systems are resilient; DORA expects you to prove it.
  • ICT third-party risk management. Contracts with ICT providers must contain specific provisions, critical dependencies must be mapped and monitored, and concentration risk considered. As the Acme example shows, your resilience is only as strong as your supply chain’s.
  • Information sharing. DORA encourages financial entities to share cyber threat intelligence with one another, recognition that in the face of systemic risk, collective defence beats going it alone.

What should you do now?

If you are a financial entity with EU operations, or an ICT provider serving one, DORA is no longer on the horizon; it is here. The sensible first steps are to establish whether and how you fall in scope, assess your current arrangements against the five pillars, and prioritise closing the gaps.

If you would like help doing exactly that, get in touch with us today. Our experts would be glad to help you build resilience that satisfies the regulator and serves the business.

About the author

Prism Social Icon
Prism Infosec
Prism Infosec’s innovative approach to the delivery of PCI projects and technical security testing was recognised with a PCI Award for Technical Excellence in January 2020. The award was presented for the delivery of a client project that was considered by the review panel to be an outstanding example of best practice.
the-cyber-scheme
pci
Crest
cbest
CHECK Penetration Testing (Dark Logo)
Cyber Incident Exercising
Cyber Incident Response Standard Level logo
Untitled design (1)
4b30d27e-0b52-4807-9ef9-9d88954e3e1c

Experiencing a security breach?
Contact the cyber security experts now