The Digital Operational Resilience Act (DORA) became fully applicable on January 17, 2025, making it one of the most significant regulatory milestones for Europe's financial sector. DORA requires more than 22,000 financial entities and their ICT service providers to meet strict standards for ICT risk management, incident reporting, resilience testing, and third-party risk management.
This page sets out what DORA requires: its scope, the penalty framework, oversight of ICT third-party providers, the incident reporting clock, the testing rules and the timeline.
DORA Scope and Scale
DORA applies to 21 types of financial entities and their ICT third-party service providers. Unlike many financial regulations that focus on banks alone, DORA covers the full breadth of the EU financial sector.
- More than 22,000 financial entities and ICT service providers fall within DORA's scope across the EU.
- Article 2 of DORA lists the 21 types of financial entity that are covered.
Financial Entities in Scope
DORA applies to credit institutions (banks), payment institutions, electronic money institutions, investment firms, crypto-asset service providers (CASPs), central securities depositories (CSDs), central counterparties (CCPs), trading venues, trade repositories, alternative investment fund managers (AIFMs), UCITS management companies, insurance and reinsurance undertakings, insurance and reinsurance intermediaries, institutions for occupational retirement pensions, credit rating agencies, statutory auditors and audit firms, administrators of critical benchmarks, crowdfunding service providers, securitisation repositories, and data reporting service providers.
DORA Compliance Costs
The cost of DORA compliance varies with entity size and complexity. Large financial groups run multi-year programmes with dedicated staff. Smaller entities meet the same rules with their existing teams, provided the register of information and the testing evidence are complete. Threat-led penetration testing is the heaviest recurring item for the entities that fall in scope for it.
DORA's penalty framework is defined at EU level but leaves significant discretion to member states, resulting in divergent national implementations.
EU-Level Penalty Framework (DORA Article 50)
| Penalty Type |
Maximum |
| Fines for financial entities |
Up to 2% of total annual worldwide turnover |
| Fines for individuals at financial entities |
Up to EUR 1,000,000 |
| Fines for Critical ICT Third-Party Providers (CTPPs) |
Up to EUR 5,000,000 |
| Fines for individuals at CTPPs |
Up to EUR 500,000 |
| Daily penalties for CTPPs (continued non-compliance) |
Up to 1% of average daily worldwide turnover, for up to 6 months |
National Divergence in Penalty Implementation
Member states have implemented DORA's penalty provisions with significant variation:
| Country |
Turnover-Based Ceiling |
Absolute Ceiling (Entities) |
Individual Ceiling |
| Spain |
5% of turnover |
- |
- |
| Sweden |
10% of turnover |
- |
- |
| Czech Republic |
- |
EUR 2 million |
- |
| Italy |
- |
EUR 20 million |
- |
| Germany |
- |
- |
EUR 5 million |
| Finland |
- |
- |
EUR 100,000 |
Additional Enforcement Powers
Beyond financial penalties, supervisory authorities have the power to issue public disclosures of breaches, binding remedial orders, suspension or limitation of business activities, and revocation of authorization or licenses.
Criminal Liability
DORA Article 52 allows member states to impose criminal penalties. Board members may face personal civil liability and potentially criminal liability for gross negligence in failing to ensure digital operational resilience.
Critical ICT Third-Party Providers (CTPPs)
On November 18, 2025, the European Supervisory Authorities published the first-ever list of Critical ICT Third-Party Providers under DORA. These 19 providers are now subject to direct oversight by the Joint Oversight Forum.
The 19 Designated Critical ICT Third-Party Providers
| # |
Provider |
| 1 |
Accenture plc |
| 2 |
Amazon Web Services EMEA Sarl |
| 3 |
Bloomberg L.P. |
| 4 |
Capgemini SE |
| 5 |
Colt Technology Services |
| 6 |
Deutsche Telekom AG |
| 7 |
Equinix (EMEA) B.V. |
| 8 |
Fidelity National Information Services, Inc. (FIS) |
| 9 |
Google Cloud EMEA Limited |
| 10 |
International Business Machines Corporation (IBM) |
| 11 |
InterXion HeadQuarters B.V. |
| 12 |
Kyndryl Inc. |
| 13 |
LSEG Data and Risk Limited |
| 14 |
Microsoft Ireland Operations Limited |
| 15 |
NTT DATA Inc. |
| 16 |
Oracle Nederland B.V. |
| 17 |
Orange SA |
| 18 |
SAP SE |
| 19 |
Tata Consultancy Services Limited |
Register of Information
All financial entities under DORA must maintain a register of all contractual arrangements with ICT third-party service providers. Reference date: March 31, 2025. National authorities forwarded registers to the ESAs by April 30, 2025 for designation analysis.
DORA ICT Incident Reporting
DORA introduces one of the strictest incident reporting frameworks in financial regulation, with reporting timelines measured in hours rather than days.
Reporting Timelines (Commission Delegated Regulation 2025/302)
| Report |
Deadline |
| Detection to classification |
24 hours maximum |
| Initial notification |
4 hours after classification as major incident |
| Intermediate report |
72 hours after initial notification |
| Final report |
1 month after intermediate report |
Classification Criteria
An ICT incident is classified as major when critical services are adversely impacted AND either: (a) a successful malicious unauthorized access occurs that may result in data losses, OR (b) two or more materiality thresholds are reached (affected clients, financial counterparties, or transactions).
Threat-Led Penetration Testing (TLPT)
DORA mandates advanced security testing for significant financial entities, building on the TIBER-EU framework with legally binding requirements.
- TLPT is mandatory every 3 years for entities that their supervisor identifies as "significant" (DORA Article 26).
- The first TLPT deadline falls on January 17, 2028, three years after the DORA application date.
- Purple teaming is compulsory under DORA. TIBER-EU only recommended it.
- The threat intelligence provider must always be external.
- Every third test must use an external red team.
- The TLPT RTS was published on June 18, 2025 and took effect on July 8, 2025.
DORA Information Sharing (Article 45)
DORA encourages (but does not mandate) financial entities to exchange cyber threat intelligence. While information sharing itself is voluntary, entities are required to inform regulators about how they participate in information sharing arrangements.
Shared intelligence includes indicators of compromise, tactics/techniques/procedures, cybersecurity alerts, and configuration tools. Arrangements must protect sensitive information, respect business confidentiality, personal data protection, and competition law.
DORA Technical Standards
The European Supervisory Authorities (EBA, ESMA, EIOPA) developed a total of 11 regulatory products to operationalize DORA:
First Batch (January 2024, published in Official Journal June 2024): 3 RTS + 1 ITS
- RTS on ICT risk management frameworks
- RTS on criteria for classifying ICT-related incidents
- RTS on policies regarding ICT services by third parties supporting critical functions
- ITS for establishing outsourcing register templates
Second Batch (July 2024): 4 RTS + 1 ITS + 2 Guidelines
DORA Timeline
| Date |
Event |
| September 24, 2020 |
European Commission published DORA proposal |
| December 27, 2022 |
Published in Official Journal of the European Union |
| January 16, 2023 |
DORA entered into force |
| January 17, 2024 |
First batch of RTS/ITS finalized by ESAs |
| June 25, 2024 |
First batch RTS published in Official Journal |
| July 17, 2024 |
Second batch of RTS/ITS/Guidelines finalized by ESAs |
| January 17, 2025 |
DORA became fully applicable (no phase-in period) |
| March 31, 2025 |
Reference date for register of information |
| April 11, 2025 |
BaFin (Germany) deadline for register of information submission |
| April 15, 2025 |
ACPR (France) deadline for register of information submission |
| April 30, 2025 |
ESAs deadline to collect registers from national authorities |
| July 8, 2025 |
TLPT RTS became effective |
| November 18, 2025 |
First list of 19 Critical ICT Third-Party Providers published |
| January 17, 2028 |
Deadline for first round of mandatory TLPT for significant entities |
DORA's Five Pillars
DORA is structured around five pillars, each with specific requirements:
Pillar I: ICT Risk Management
Entities must establish comprehensive ICT risk management frameworks covering identification, protection, detection, response, and recovery.
Pillar II: ICT-Related Incident Management and Reporting
Major ICT incidents must be classified within 24 hours and reported to supervisory authorities within 4 hours of classification.
Pillar III: Digital Operational Resilience Testing
Regular testing of ICT systems is required, with TLPT mandatory every 3 years for significant entities.
Pillar IV: ICT Third-Party Risk Management
Entities must maintain a register of all ICT third-party arrangements and assess concentration risk. The register is the part of DORA that most entities find hardest.
Pillar V: Information Sharing
Voluntary exchange of cyber threat intelligence between financial entities, with mandatory disclosure to regulators about participation in sharing arrangements.
Frequently Asked Questions
Q: How many financial entities are affected by DORA?
A: More than 22,000 financial entities and ICT service providers fall within DORA's scope across the EU. This includes 21 types of financial entities, from banks and insurers to crypto-asset service providers and crowdfunding platforms, plus their ICT third-party service providers.
Q: What are the maximum DORA fines?
A: Financial entities face fines of up to 2% of total annual worldwide turnover. Individuals at financial entities face fines of up to EUR 1,000,000. Critical ICT Third-Party Providers face fines of up to EUR 5,000,000, with daily penalties of up to 1% of average daily turnover for continued non-compliance. Some member states have implemented higher ceilings, with Sweden allowing up to 10% of turnover.
Q: How much does DORA compliance cost?
A: Cost depends on size and complexity. Large groups run multi-year programmes with dedicated staff and external testers. Smaller entities meet the rules with their existing teams. The recurring items are threat-led penetration testing, the upkeep of the register of information, and the incident reporting process.
Q: What are the DORA incident reporting deadlines?
A: DORA requires detection-to-classification within 24 hours, initial notification within 4 hours of classification, an intermediate report within 72 hours, and a final report within 1 month.
Q: Which ICT providers have been designated as Critical under DORA?
A: On November 18, 2025, the ESAs published the first list of 19 Critical ICT Third-Party Providers. The list includes AWS, Google Cloud, Microsoft, IBM, SAP, Oracle, Accenture, Bloomberg, and others. These providers are subject to direct oversight by the Joint Oversight Forum.
This page restates DORA, the delegated regulations adopted under it, and the published decisions of the European Supervisory Authorities. It is updated as new enforcement data becomes available.
Last updated: March 2026
Related reading
Ready to act on this? Matproof runs continuous AI penetration testing and compliance monitoring. Book a demo.