What is DORA?
Everything you need to know about the European regulation on digital operational resilience for the financial sector.
1Before DORA: a fragmented framework
The growing digitalisation of banks, insurers and investment firms has made the financial sector dependent on its IT systems — and therefore vulnerable to cyberattacks, technical failures and the failures of its technology providers. Before DORA, digital security requirements were scattered across sectoral rules (banking, insurance, markets) and non-harmonised national recommendations, creating gaps in maturity and supervision between Member States.
2The DORA regulation (2022)
Regulation (EU) 2022/2554 (Digital Operational Resilience Act) was published in the Official Journal of the EU on 27 December 2022 and entered into force on 16 January 2023. After a two-year transition period, it has been fully applicable since 17 January 2025 in all Member States.
The 5 pillars of DORA compliance
DORA structures its requirements around five complementary pillars covering the entire digital risk lifecycle.
Who is affected?
DORA applies to around twenty categories of financial entities defined in Article 2 of the regulation, as well as to their ICT service providers.
DORA and NIS2: what's the difference?
Both texts coexist, but DORA acts as lex specialis: a financial entity covered by DORA applies DORA rather than NIS2 for its cybersecurity.
| Criterion | DORA | NIS2 |
|---|---|---|
| Type of text | Regulation (EU) — directly applicable, no transposition | Directive (EU) — transposed by each Member State |
| Sector covered | Financial sector only (~20 categories of entities) | 18 sectors (energy, health, transport, digital...) |
| Relationship | Lex specialis: takes precedence over NIS2 for the entities it covers | Applies by default, except for sectoral lex specialis |
| Resilience testing | TLPT mandatory for significant entities | No harmonised TLPT requirement at this level |
| Third-party providers | Direct oversight of critical ICT providers | No equivalent direct oversight framework |