The financial sector’s reliance on digital technology and ICT (Information and Communication Technology) has grown significantly in recent years. However, this growing dependence has also led to greater exposure to significant cyber threats and operational disruptions.
To address these concerns, the European Union has introduced the Digital Operational Resilience Act which was a crucial step towards enhancing digital resilience in the financial sector.
Keep reading to learn more about this regulation, why it matters, the consequences of non-compliance, and how financial organizations can prepare for it.
Key takeaways:
- The Digital Operational Resilience Act, effective January 17, 2025, aims to strengthen digital resilience and enhance the ability of financial institutions to withstand cyberattacks and operational disruptions
- It applies to a large number of financial institutions and ICT service providers, over 22,000 in the EU
- It covers five areas: ICT risk management, incident reporting, resilience testing, third-party risk management, and information sharing
What is the Digital Operational Resilience Act?
The Digital Operational Resilience Act is an EU regulation that sets a new standard for ICT risk management in the financial sector. It comes into force on 16 January 2023 and will apply from 17 January 2025.
At its core, it aims to build a resilient financial ecosystem that can handle technical issues and cyber threats effectively. By establishing clear and consistent rules across all member states, it ensures that banks, insurance companies, and other financial institutions can operate without disruption, even in the face of technical problems or cyber threats.
The Digital Operational Resilience Act also applies to key third-party providers, such as cloud services and data analytics services, meaning organizations must ensure these partners comply with DORA outsourcing requirements related to risk management, operational resilience, and regulatory oversight.
The organizations that fail to comply in time will face harsh penalties. However, following DORA doesn’t just mean avoiding fines; it’s a chance to boost how financial institutions handle cyber threats and recover from problems. This regulation shows the EU’s dedication to close supervision with a focus on regular reporting and clear communication.
Why is this regulation relevant?
Given that currently there’s no unified framework for managing and mitigating ICT risks in the European financial sector, the Digital Operational Resilience Act becomes groundbreaking. The regulation stands out because it:
- Applies to over 22,000 financial entities and ICT service providers operating in the EU.
- Introduces new and clear requirements for all financial institutions.
- Addresses regulatory gaps and conflicts between different EU states and makes it easier for financial institutions to follow the rules.
- Establishes a comprehensive framework for risk management, operational capabilities, and third-party management.
- Ensures the stability and integrity of the EU’s financial system, considering the entire value chain.
- Introduces EU-wide supervision of key external ICT service providers.
What financial institutions must comply?

The Digital Operational Resilience Act will impact all financial organizations subject to EU regulation such as:
- banks
- investment firms
- insurance companies
- payment service providers
- credit institutions
- stock exchanges and trading venues
- crypto-asset providers
- pension funds
- reporting service providers
- cloud service providers
- third-party ICT service providers
The 5 pillars of the Digital Operational Resilience Act
The regulation provides a clear framework to enhance the digital and cybersecurity resilience of financial systems across European markets. It focuses on five key areas to strengthen how financial institutions manage and respond to digital risks.

Pillar 1: ICT risk management
ICT risk management is the foundation of the Digital Operational Resilience Act. Financial institutions are required to develop, implement, and maintain strong ICT systems and protocols. These include secure networks, encrypted databases, and regular backups. By setting up detailed risk assessment processes, businesses can identify potential weaknesses in their digital operations.
However, responding to these incidents is not the only aim. It’s crucial to actively manage and reduce ICT-related risks. Developing a clear ICT risk management strategy ensures businesses are ready for and can swiftly address any disruptions or threats.
Key requirements under the Digital Operational Resilience Act include:
- Determining acceptable levels of risk and impact from ICT disruptions.
- Planning and approving strategies to keep the business running during disruptions.
- Creating disaster recovery plans for handling and recovering from major incidents.
- Setting up security measures to protect important digital assets and resources.
Pillar 2: ICT incident reporting
The second pillar focuses on standardizing how financial institutions report major ICT-related incidents. The established centralized reporting hub for incidents like system outages, cyberattacks, and data breaches will help gather data and identify common issues across the sector, strengthening overall resilience.
To comply, financial institutions need to have systems for monitoring and reporting these incidents both internally for management and mitigation. They must also report externally to EU authorities and, when necessary, to affected customers. A root cause report must be submitted within a month of any major incident to ensure transparency and identify common risks.
Pillar 3: Digital operational resilience testing
All financial institutions are required to regularly test their ICT systems to ensure they can handle disruptions. Key requirements include:
- Performing annual ICT tests on the ICT tools and systems.
- Identifying, mitigating, and eliminating any weaknesses and issues by implementing counteractive measures.
- Conducting advanced threat-based penetration testing (TLPT) for ICT services that affect critical functions.
- Requiring external ICT service providers to participate in and fully cooperate with testing activities.
Pillar 4: Third-party risk management
The Digital Operational Resilience Act also applies to ICT providers that support the financial sector. Financial institutions must actively manage risks related to these third-party services. When outsourcing crucial functions, they need to set clear terms in contracts for things like exit strategies, audits, and security. They can only work with providers who meet these standards, and authorities have the power to suspend contracts if providers don’t comply.
Institutions must track their ICT dependencies and avoid relying too heavily on any single provider. Critical ICT service providers will be monitored directly by European Supervisory Authorities (ESAs). These authorities will ensure compliance and can ban providers that don’t meet these requirements from working with financial firms.
Pillar 5: Information and threat intelligence sharing
This pillar highlights the need for financial entities to learn from ICT incidents by sharing information. They are encouraged to join voluntary threat intelligence networks to improve their understanding and response to cyber risks. However, any shared data must be safeguarded in accordance with regulations, such as protecting personal information under the General Data Protection Regulation (GDPR).
The timeline of the Digital Operational Resilience Act
The timeline below highlights the major milestones in the history of the Digital Operational Resilience Act.

Current status of DORA
Even though it has been officially adopted, the European Supervisory Authorities are still finalizing the detailed regulations. These rules, which will guide how the Digital Operational Resilience Act is implemented, are expected to be completed in 2024. The European Commission is also working on a framework to oversee critical ICT providers. It will be finalized in 2024 as well.