DORA Compliance in Paris

Paris is the Eurozone's second-largest financial centre, home to five of the world's 30 globally systemically important banks (G-SIBs): BNP Paribas, Crédit Agricole, Société Générale, Groupe BPCE, and Crédit Mutuel. La Défense — Europe's largest purpose-built business district — houses the headquarters of most major French financial institutions. Euronext Paris is the continent's largest stock exchange by market capitalisation. As France's primary financial supervisory hub, Paris institutions face dual oversight from ACPR (Autorité de contrôle prudentiel et de résolution) and AMF (Autorité des marchés financiers), on top of ECB supervision for the largest groups.

Request a demo
5
G-SIBs headquartered
€2.7T
BNP Paribas total assets
€7T+
Euronext market cap
200,000+
Financial sector employees

Why DORA matters in Paris

The Digital Operational Resilience Act (DORA) requires financial entities to implement comprehensive ICT risk management frameworks, including incident reporting, resilience testing, and third-party oversight. Mandatory since January 17, 2025, it applies to over 22,000 financial entities across the EU.

With five G-SIBs headquartered in Paris and directly supervised by the ECB, the stakes of DORA non-compliance are enormous — fines from ACPR can reach 10% of annual turnover. BNP Paribas, processing billions of transactions daily across 65 countries, must demonstrate ICT resilience under DORA Art. 6-16. Société Générale's high-profile IT incidents (including the 2008 Kerviel affair) underscore how critical robust ICT governance is. France's AMF has been one of the most active securities regulators in Europe; combined with ACPR's banking supervision, Paris-based institutions operate under some of the strictest oversight in the EU. The Paris FinTech Forum draws 3,000+ attendees annually, reflecting a thriving ecosystem where compliance automation is rapidly becoming a competitive requirement.

Supervisory Bodies

ACPR, AMF, ECB (SSM)

Key Industries

  • Universal Banking & G-SIBs
  • Asset Management & Insurance
  • Capital Markets & Euronext
  • FinTech & PayTech

Notable financial institutions in Paris

BNP ParibasCrédit AgricoleSociété GénéraleGroupe BPCEAXAAmundiNatixisEuronext

DORA Key Requirements

ICT risk management framework (Art. 5-16)
Major incident reporting to BaFin within 4 hours (Art. 17-23)
Threat-led penetration testing / TLPT every 3 years (Art. 24-27)
Register of all ICT third-party providers (Art. 28-44)
Cyber threat information sharing (Art. 45)
ICT business continuity and disaster recovery plans