SEE MATPROOF ON YOUR STACK — BOOK A 30-MINUTE DEMO
DORAMar 20, 202610 min read

DORA Compliance Statistics 2026: Scope, Penalties and Enforcement

MW
Malte Wagenbach

Founder & CEO, Matproof

The Digital Operational Resilience Act (DORA) became fully applicable on January 17, 2025, making it one of the most significant regulatory milestones for Europe's financial sector. DORA requires more than 22,000 financial entities and their ICT service providers to meet strict standards for ICT risk management, incident reporting, resilience testing, and third-party risk management.

This page sets out what DORA requires: its scope, the penalty framework, oversight of ICT third-party providers, the incident reporting clock, the testing rules and the timeline.

DORA Scope and Scale

DORA applies to 21 types of financial entities and their ICT third-party service providers. Unlike many financial regulations that focus on banks alone, DORA covers the full breadth of the EU financial sector.

  • More than 22,000 financial entities and ICT service providers fall within DORA's scope across the EU.
  • Article 2 of DORA lists the 21 types of financial entity that are covered.

Financial Entities in Scope

DORA applies to credit institutions (banks), payment institutions, electronic money institutions, investment firms, crypto-asset service providers (CASPs), central securities depositories (CSDs), central counterparties (CCPs), trading venues, trade repositories, alternative investment fund managers (AIFMs), UCITS management companies, insurance and reinsurance undertakings, insurance and reinsurance intermediaries, institutions for occupational retirement pensions, credit rating agencies, statutory auditors and audit firms, administrators of critical benchmarks, crowdfunding service providers, securitisation repositories, and data reporting service providers.

DORA Compliance Costs

Curious how DORA-ready you actually are?

Take the 3-min DORA assessment

The cost of DORA compliance varies with entity size and complexity. Large financial groups run multi-year programmes with dedicated staff. Smaller entities meet the same rules with their existing teams, provided the register of information and the testing evidence are complete. Threat-led penetration testing is the heaviest recurring item for the entities that fall in scope for it.

DORA Penalties and Enforcement

DORA's penalty framework is defined at EU level but leaves significant discretion to member states, resulting in divergent national implementations.

EU-Level Penalty Framework (DORA Article 50)

Penalty Type Maximum
Fines for financial entities Up to 2% of total annual worldwide turnover
Fines for individuals at financial entities Up to EUR 1,000,000
Fines for Critical ICT Third-Party Providers (CTPPs) Up to EUR 5,000,000
Fines for individuals at CTPPs Up to EUR 500,000
Daily penalties for CTPPs (continued non-compliance) Up to 1% of average daily worldwide turnover, for up to 6 months

National Divergence in Penalty Implementation

Member states have implemented DORA's penalty provisions with significant variation:

Country Turnover-Based Ceiling Absolute Ceiling (Entities) Individual Ceiling
Spain 5% of turnover - -
Sweden 10% of turnover - -
Czech Republic - EUR 2 million -
Italy - EUR 20 million -
Germany - - EUR 5 million
Finland - - EUR 100,000

Additional Enforcement Powers

Beyond financial penalties, supervisory authorities have the power to issue public disclosures of breaches, binding remedial orders, suspension or limitation of business activities, and revocation of authorization or licenses.

Criminal Liability

DORA Article 52 allows member states to impose criminal penalties. Board members may face personal civil liability and potentially criminal liability for gross negligence in failing to ensure digital operational resilience.

Critical ICT Third-Party Providers (CTPPs)

On November 18, 2025, the European Supervisory Authorities published the first-ever list of Critical ICT Third-Party Providers under DORA. These 19 providers are now subject to direct oversight by the Joint Oversight Forum.

The 19 Designated Critical ICT Third-Party Providers

# Provider
1 Accenture plc
2 Amazon Web Services EMEA Sarl
3 Bloomberg L.P.
4 Capgemini SE
5 Colt Technology Services
6 Deutsche Telekom AG
7 Equinix (EMEA) B.V.
8 Fidelity National Information Services, Inc. (FIS)
9 Google Cloud EMEA Limited
10 International Business Machines Corporation (IBM)
11 InterXion HeadQuarters B.V.
12 Kyndryl Inc.
13 LSEG Data and Risk Limited
14 Microsoft Ireland Operations Limited
15 NTT DATA Inc.
16 Oracle Nederland B.V.
17 Orange SA
18 SAP SE
19 Tata Consultancy Services Limited

Register of Information

All financial entities under DORA must maintain a register of all contractual arrangements with ICT third-party service providers. Reference date: March 31, 2025. National authorities forwarded registers to the ESAs by April 30, 2025 for designation analysis.

DORA ICT Incident Reporting

DORA introduces one of the strictest incident reporting frameworks in financial regulation, with reporting timelines measured in hours rather than days.

Reporting Timelines (Commission Delegated Regulation 2025/302)

Report Deadline
Detection to classification 24 hours maximum
Initial notification 4 hours after classification as major incident
Intermediate report 72 hours after initial notification
Final report 1 month after intermediate report

Classification Criteria

An ICT incident is classified as major when critical services are adversely impacted AND either: (a) a successful malicious unauthorized access occurs that may result in data losses, OR (b) two or more materiality thresholds are reached (affected clients, financial counterparties, or transactions).

Threat-Led Penetration Testing (TLPT)

DORA mandates advanced security testing for significant financial entities, building on the TIBER-EU framework with legally binding requirements.

  • TLPT is mandatory every 3 years for entities that their supervisor identifies as "significant" (DORA Article 26).
  • The first TLPT deadline falls on January 17, 2028, three years after the DORA application date.
  • Purple teaming is compulsory under DORA. TIBER-EU only recommended it.
  • The threat intelligence provider must always be external.
  • Every third test must use an external red team.
  • The TLPT RTS was published on June 18, 2025 and took effect on July 8, 2025.

DORA Information Sharing (Article 45)

DORA encourages (but does not mandate) financial entities to exchange cyber threat intelligence. While information sharing itself is voluntary, entities are required to inform regulators about how they participate in information sharing arrangements.

Shared intelligence includes indicators of compromise, tactics/techniques/procedures, cybersecurity alerts, and configuration tools. Arrangements must protect sensitive information, respect business confidentiality, personal data protection, and competition law.

DORA Technical Standards

The European Supervisory Authorities (EBA, ESMA, EIOPA) developed a total of 11 regulatory products to operationalize DORA:

First Batch (January 2024, published in Official Journal June 2024): 3 RTS + 1 ITS

  • RTS on ICT risk management frameworks
  • RTS on criteria for classifying ICT-related incidents
  • RTS on policies regarding ICT services by third parties supporting critical functions
  • ITS for establishing outsourcing register templates

Second Batch (July 2024): 4 RTS + 1 ITS + 2 Guidelines

DORA Timeline

Date Event
September 24, 2020 European Commission published DORA proposal
December 27, 2022 Published in Official Journal of the European Union
January 16, 2023 DORA entered into force
January 17, 2024 First batch of RTS/ITS finalized by ESAs
June 25, 2024 First batch RTS published in Official Journal
July 17, 2024 Second batch of RTS/ITS/Guidelines finalized by ESAs
January 17, 2025 DORA became fully applicable (no phase-in period)
March 31, 2025 Reference date for register of information
April 11, 2025 BaFin (Germany) deadline for register of information submission
April 15, 2025 ACPR (France) deadline for register of information submission
April 30, 2025 ESAs deadline to collect registers from national authorities
July 8, 2025 TLPT RTS became effective
November 18, 2025 First list of 19 Critical ICT Third-Party Providers published
January 17, 2028 Deadline for first round of mandatory TLPT for significant entities

DORA's Five Pillars

DORA is structured around five pillars, each with specific requirements:

Pillar I: ICT Risk Management

Entities must establish comprehensive ICT risk management frameworks covering identification, protection, detection, response, and recovery.

Pillar II: ICT-Related Incident Management and Reporting

Major ICT incidents must be classified within 24 hours and reported to supervisory authorities within 4 hours of classification.

Pillar III: Digital Operational Resilience Testing

Regular testing of ICT systems is required, with TLPT mandatory every 3 years for significant entities.

Pillar IV: ICT Third-Party Risk Management

Entities must maintain a register of all ICT third-party arrangements and assess concentration risk. The register is the part of DORA that most entities find hardest.

Pillar V: Information Sharing

Voluntary exchange of cyber threat intelligence between financial entities, with mandatory disclosure to regulators about participation in sharing arrangements.

Frequently Asked Questions

Q: How many financial entities are affected by DORA?

A: More than 22,000 financial entities and ICT service providers fall within DORA's scope across the EU. This includes 21 types of financial entities, from banks and insurers to crypto-asset service providers and crowdfunding platforms, plus their ICT third-party service providers.

Q: What are the maximum DORA fines?

A: Financial entities face fines of up to 2% of total annual worldwide turnover. Individuals at financial entities face fines of up to EUR 1,000,000. Critical ICT Third-Party Providers face fines of up to EUR 5,000,000, with daily penalties of up to 1% of average daily turnover for continued non-compliance. Some member states have implemented higher ceilings, with Sweden allowing up to 10% of turnover.

Q: How much does DORA compliance cost?

A: Cost depends on size and complexity. Large groups run multi-year programmes with dedicated staff and external testers. Smaller entities meet the rules with their existing teams. The recurring items are threat-led penetration testing, the upkeep of the register of information, and the incident reporting process.

Q: What are the DORA incident reporting deadlines?

A: DORA requires detection-to-classification within 24 hours, initial notification within 4 hours of classification, an intermediate report within 72 hours, and a final report within 1 month.

Q: Which ICT providers have been designated as Critical under DORA?

A: On November 18, 2025, the ESAs published the first list of 19 Critical ICT Third-Party Providers. The list includes AWS, Google Cloud, Microsoft, IBM, SAP, Oracle, Accenture, Bloomberg, and others. These providers are subject to direct oversight by the Joint Oversight Forum.


This page restates DORA, the delegated regulations adopted under it, and the published decisions of the European Supervisory Authorities. It is updated as new enforcement data becomes available.

Last updated: March 2026

Related reading


Ready to act on this? Matproof runs continuous AI penetration testing and compliance monitoring. Book a demo.

DORA statisticsDORA compliance statisticsDORA finesDORA regulation statisticsDORA scopeDORA penaltiesDORA compliance costsdigital operational resilience act statistics

DORA Readiness Assessment

Check your digital operational resilience in 3 minutes

Take the free assessment

Ready to simplify compliance?

Get audit-ready in weeks, not months. See Matproof in action.

Request a demo