DORA compliance guide for financial entities

Regulation (EU) 2022/2554 in five pillars — governance, incident reporting, testing, third-party risk and information sharing — and the evidence supervisors expect.

Michael McCarroll 13 min read Updated June 2026

1. The five pillars

  • ICT risk management (Ch. II) — framework, strategy, protection, detection, response, recovery.
  • ICT-related incident management (Ch. III) — classification, reporting, root-cause analysis.
  • Digital operational resilience testing (Ch. IV) — annual basic testing plus TLPT every 3 years for significant entities.
  • ICT third-party risk (Ch. V) — register of information, contractual requirements, exit strategies.
  • Information and intelligence sharing (Ch. VI) — voluntary threat-intel arrangements.

2. A five-step implementation path

Step 1

Codify the ICT risk framework

Article 6 requires a documented, approved framework reviewed at least yearly and after every major incident. Reuse ISO/IEC 27005:2022 as the methodological base (ISO, 2022).
Step 2

Build the incident classification engine

Delegated Regulation (EU) 2024/1772 defines the criteria and thresholds — clients affected, data losses, geographical spread, reputational impact, duration (European Commission, 2024).
Step 3

Populate the Register of Information

Article 28(3) mandates a register of all contractual arrangements with ICT third-party providers. Supervisors receive it annually via the EBA reporting portal.
Step 4

Plan resilience testing

Annual vulnerability assessments and scenario-based tests are mandatory. Significant entities add TLPT — scope with your competent authority 6+ months in advance.
Step 5

Rewrite critical outsourcing contracts

Article 30 lists mandatory contract clauses (audit rights, sub-outsourcing, exit, service levels). Contracts pre-dating DORA need remediation, not just a side letter.

One workspace for DORA, NIS2 and ISO 27001

DORA's ICT risk framework, NIS2's Article 21 measures and ISO 27001 controls overlap by 70–80%. Running them in the same workspace stops the same evidence being asked for three times.

ISO-STANDARD.app ships a ready-to-adopt ISO 27001 workspace with the risk register, controls catalogue, policies and audit-ready exports already wired together — no spreadsheet sprawl, no consultant lock-in.

Free downloads for this topic

Prefer a conversation? Email hello@iso-standard.app — a real human responds within one business day.

Frequently asked questions

When did DORA apply?
Regulation (EU) 2022/2554 entered into force on 16 January 2023 and applied from 17 January 2025 (European Parliament and Council, 2022).
Who is in scope?
Nearly all EU financial entities — credit institutions, payment and e-money institutions, investment firms, insurers, MiCA crypto-asset service providers — plus critical ICT third-party providers designated by the ESAs (Art. 2).
How is DORA different from NIS2?
DORA is lex specialis for the financial sector: where DORA applies to a topic, it displaces NIS2 for that entity on that topic (European Parliament and Council, 2022, Recital 16).
What is TLPT?
Threat-Led Penetration Testing (Art. 26–27) — mandatory red-team exercises for significant financial entities, every three years, following the TIBER-EU framework (ECB, 2018).

References

  • ECB (2018) TIBER-EU Framework: How to implement the European framework for Threat Intelligence-based Ethical Red Teaming. Frankfurt: European Central Bank.
  • European Commission (2024) Commission Delegated Regulation (EU) 2024/1772 supplementing DORA with regard to the classification of major ICT-related incidents. Brussels: European Commission.
  • European Parliament and Council (2022) Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA). Official Journal of the European Union, L 333/1.
  • ISO (2022) ISO/IEC 27005:2022 Information security, cybersecurity and privacy protection — Guidance on managing information security risks. Geneva: ISO.
Related guides
Trust & security
ISO 27001 aligned
Controls mapped to Annex A
Encryption in transit & at rest
TLS 1.3 · AES-256
MFA enforced
TOTP required for all admins
GDPR & UK GDPR
DPA on request · EU/UK data
SOC 2 ready posture
Audit-grade logging
RLS-isolated tenants
Row-level data separation
← All guidesHome →