top of page

DORA: The Complete Guide to the Digital Operational Resilience Act

  • 1 day ago
  • 4 min read

DORA — the Digital Operational Resilience Act — is the European regulation that harmonises information and communication technology (ICT) risk management requirements across the entire financial sector. Applicable since 17 January 2025, it directly concerns insurers and reinsurers, alongside banks, investment firms and crypto-asset service providers. For a risk function or an IT department, DORA is not one more regulatory layer sitting beside Solvency II: it is a cross-cutting framework that now structures the governance of the whole technology chain, third-party providers included.

This guide sets out the overall picture: the origin of the regulation, its scope, its five pillars and its timeline.

Why DORA: harmonising a fragmented regulatory landscape

Before DORA, each Member State and each sectoral regulator — banking, insurance, markets — applied its own ICT risk management requirements, with heterogeneous levels of demand and reporting formats. That fragmentation complicated the supervision of a risk that is inherently cross-cutting: a cyberattack or a major IT outage stops neither at sectoral nor at national borders.

Regulation (EU) 2022/2554, adopted in late 2022 and applicable since 17 January 2025 after a 24-month implementation period, replaces that fragmented approach with a single body of rules for managing ICT risk, directly applicable in every Member State without further national transposition. It articulates with the broader NIS2 directive, providing the financial sector with a specific and more demanding framework.

A scope extended to ICT providers

What distinguishes DORA from earlier prudential regimes is that it extends supervision beyond financial entities themselves. The regulation covers:

  • financial entities: credit institutions, insurance and reinsurance undertakings, investment firms, asset managers, payment institutions and crypto-asset service providers, among others;

  • critical third-party ICT service providers — cloud providers in particular — which, above a certain threshold of systemic criticality, become subject to direct oversight by the European authorities, a genuine novelty relative to earlier regimes.

The proportionality principle nonetheless applies: requirements are modulated according to the size, risk profile and nature of the entity's activities, with a lighter regime for the smallest structures.

The five pillars of DORA

DORA structures its requirements around five complementary pillars.

1. ICT risk management

Every entity must maintain an ICT risk governance and management framework, under the direct responsibility of the management body: mapping of IT assets and dependencies, security policies, business continuity and disaster recovery plans, and backup and restoration arrangements tested on a regular basis.

2. Incident management, classification and reporting

Entities must establish a process for detecting, managing and classifying ICT-related incidents, and must report major incidents to their competent authority within harmonised deadlines and formats at European level — a significant change for organisations that until now handled their notification obligations in a fragmented way across sectoral or national regimes.

3. Digital operational resilience testing

Entities must test the resilience of their systems regularly, with a reinforced arrangement for the most significant entities: threat-led penetration testing (TLPT), conducted under a common European framework, simulates realistic attacks against critical systems.

4. ICT third-party risk management

DORA imposes reinforced governance of IT outsourcing: maintenance of a register of contractual arrangements with ICT providers, mandatory minimum contractual clauses (audit rights, exit plans, data location), and particular attention to concentration risk where several critical functions rely on the same provider.

5. Information sharing on cyber threats

The regulation encourages — on a voluntary and framed basis — the sharing of information and intelligence on cyber threats between financial entities, in order to strengthen collective detection and response capability.

The role of the European Supervisory Authorities

The three European Supervisory Authorities (ESAs) — EIOPA for insurance, EBA for banking, ESMA for markets — jointly develop the regulatory technical standards (RTS) and implementing technical standards (ITS) that specify how DORA applies: the content of the provider register, the incident reporting format, the TLPT methodology. These standards continue to evolve after the regulation became applicable, so their version in force should be verified systematically before any operational compliance work.

DORA and Solvency II: two complementary frameworks

DORA neither replaces nor amends the risk governance requirements of Solvency II — it complements them on the specifically technological dimension. Pillar 2 of Solvency II already requires a system of governance and proportionate risk management (see our complete guide to Solvency II); DORA specifies and tightens the requirements applicable to the ICT component of that governance system, with its own formalism and reporting obligations.

Summary of the five pillars

Pillar

Main content

1. ICT risk management

Governance, asset mapping, security policies, business continuity

2. Incident management

Classification, harmonised reporting to competent authorities

3. Resilience testing

Regular testing, TLPT for the most significant entities

4. ICT third-party risk

Register of contracts, mandatory clauses, concentration risk

5. Information sharing

Voluntary exchange of cyber threat intelligence

Finengy Advisory supports your DORA compliance

Mapping your ICT dependencies, structuring the provider register, articulating all of it with your Solvency II risk governance.

Frequently asked questions

Since when has DORA applied? Since 17 January 2025, after a 24-month implementation period following the entry into force of Regulation (EU) 2022/2554.

Does DORA apply to all insurers? Yes, with proportionate modulation according to the size and risk profile of the undertaking. Insurance and reinsurance undertakings fall explicitly within the scope of the regulation.

What is a TLPT? A threat-led penetration test, which simulates realistic attacks against an entity's critical systems under a methodological framework harmonised at European level. It concerns only the most significant entities.

Does DORA concern an insurer's external IT providers? Yes. Critical third-party ICT service providers — cloud providers in particular — may be placed under the direct oversight of the European authorities above a certain threshold of systemic criticality.

Sources: Regulation (EU) 2022/2554 of the European Parliament and of the Council (DORA); regulatory and implementing technical standards of the European Supervisory Authorities (EIOPA, EBA, ESMA); ACPR publications on DORA implementation. Informational content; the technical standards specifying how the regulation applies continue to evolve — verify the version in force before any compliance decision.

 
 
bottom of page