Compliance & Regulation

DORA

What Is DORA? Definition and How It Works

Definition

DORA (Digital Operational Resilience Act) is the EU regulation establishing a unified framework for digital operational resilience in the financial sector, applicable from January 17, 2025. DORA requires financial entities, including payment institutions, e-money institutions, and credit institutions, and their critical ICT third-party providers to demonstrate their ability to withstand, respond to, and recover from ICT-related disruptions and cyber threats.

How it works

DORA applies to financial entities regulated in the EU and to critical third-party ICT providers designated by European supervisory authorities (EBA, ESMA, EIOPA). The framework has five pillars.

ICT risk management requires comprehensive frameworks covering governance, asset management, protection, detection, and recovery. ICT incident reporting standardises how significant incidents are reported to national authorities, with defined classification criteria and timelines, initial notification within 4 hours of classification, intermediate report within 72 hours, final report within one month.

Digital operational resilience testing requires regular vulnerability assessments and penetration testing; significant entities must conduct Threat-Led Penetration Testing (TLPT) under the TIBER-EU framework. ICT third-party risk management requires comprehensive due diligence and mandated contractual provisions for all ICT third-party relationships. Information sharing enables voluntary cyber threat intelligence exchange.

Why it matters

DORA was prompted by increasing cyber incidents affecting EU financial institutions and the fragmented, inconsistent resilience requirements that previously existed across different subsectors and member states. A bank, payment institution, and EMI in the same country could face materially different ICT resilience requirements; DORA creates a single harmonised standard.

The third-party provisions are particularly impactful for payment firms. Using cloud providers, payment processors, or data analytics tools requires DORA-compliant due diligence and specific contractual provisions covering access rights, audit, business continuity, exit assistance, and service levels. Existing non-compliant contracts must be renegotiated.

With PXP

PXP supports merchants and partners across the payments value chain. To talk through operational resilience as part of your payment strategy, get in touch with our team.

Talk to a payments specialist

Frequently asked questions

Who does DORA apply to?

DORA applies to EU-regulated financial entities including banks, investment firms, payment institutions, e-money institutions, insurance companies, pension funds, crypto-asset service providers, and data reporting services. It also applies to critical ICT third-party providers designated by EU supervisory authorities, cloud providers, software vendors, and data analytics providers systemically important to EU financial services.

What are the DORA incident reporting requirements?

Major ICT-related incidents must be reported to the national competent authority in three stages: initial notification within 4 hours of classification, intermediate report within 72 hours, and final report within one month. Significant cyber threats that have not yet materialised as incidents must also be reported voluntarily.

What contractual requirements does DORA impose on ICT third-party contracts?

DORA mandates contracts with ICT third-party providers include provisions covering: full description of services and SLAs; data location; cooperative assistance during incidents; access and audit rights for the entity and regulators; business continuity requirements; exit provisions and transition assistance; and data deletion on termination. Existing contracts lacking these provisions must be renegotiated.