THREAT BRIEFING · 09.10.2026 DEENFRES

Strategy & Governance

DORA: Why the Digital Operational Resilience Act Is Turning the Financial Sector Upside Down

By Klaus Hauptfleisch · October 20, 2022 · 4 min read

With DORA, the EU is establishing, for the first time, a unified framework for digital operational resilience across the financial sector. As of January 2025, banks, insurers, and financial service providers must fully document, test, and demonstrate to supervisory authorities their entire ICT risk landscape. The effort required is substantial – and the deadline is tight.

TL;DR

How DORA Differs from NIS2

While NIS2 sets cross-sectoral minimum standards, DORA is a sector-specific law for the financial sector – acting as lex specialis relative to NIS2. In several areas, DORA goes significantly further: mandatory Threat-Led Penetration Testing (TLPT), highly detailed incident reporting requirements, and – for the first time – direct supervision of critical ICT third-party providers such as cloud service providers.

For financial institutions, this means: NIS2 compliance alone is insufficient. DORA imposes additional, more specific obligations.

The Five Pillars of DORA

1. ICT Risk Management: Comprehensive inventory of all ICT assets, risk analysis, and documented governance structures – with clear accountability at board level.

2. Incident Reporting: Reporting of major ICT incidents to the competent authority – within defined deadlines and using prescribed formats.

3. Digital Operational Resilience Testing: Regular testing, including TLPT (Threat-Led Penetration Testing) for systemically important institutions.

4. ICT Third-Party Risk: Contractual minimum requirements for ICT service providers and exit strategies for critical dependencies.

5. Information Sharing: Voluntary exchange of threat intelligence among financial institutions.

Why Cloud Providers Are Now Under Scrutiny

DORA grants European supervisory authorities (ESAs) the power – for the first time – to directly oversee critical ICT third-party providers. AWS, Azure, and Google Cloud could be designated as Critical ICT Third-Party Providers (CTPPs).

This has far-reaching consequences: Such providers must grant supervisory authorities access to information, permit audits, and implement recommendations. For financial institutions, the balance of negotiation with their cloud providers shifts fundamentally.

Implementation Roadmap: What Needs to Be Done Now

By January 2025, companies must: establish an ICT risk management framework; review all ICT contracts for DORA compliance; adapt incident response processes to meet reporting obligations; and develop a TLPT implementation plan.

The biggest challenge? Many institutions lack a complete inventory of their ICT assets and dependencies. This foundational work must be completed first.

Key Facts

Scope: 22,000+ financial institutions and ICT service providers in the EU

Reporting obligation: Major incidents must be reported within 4 hours (initial notification)

TLPT requirement: Every three years for systemically important institutions

Frequently Asked Questions

Every question is locked. A tap unlocks the answer.

Does DORA apply to small financial institutions?

Yes – DORA applies in principle to all regulated financial institutions. However, a proportionality principle applies: Smaller institutions with lower-risk profiles face simplified requirements, particularly regarding ICT risk management and resilience testing.

How does DORA relate to existing BaFin requirements?

DORA replaces and expands upon existing national requirements such as BAIT (Supervisory Requirements for IT in Banks). Institutions that have already implemented BAIT have a solid foundation – but must still identify and implement DORA-specific additional requirements.

What happens in case of non-compliance?

Supervisory authorities may impose fines, order corrective measures, and – in extreme cases – restrict business activities. For ICT third-party providers designated as CTPPs, the Lead Oversight Authority may issue direct recommendations.

Related Articles

More from the MBF Media Network

cloudmagazinCloud MagazinMyBusinessFutureMyBusinessFutureDigital ChiefsDigital Chiefs

Translated from the German original using artificial intelligence. The German version is authoritative.

Further reading

A magazine by Evernine Media GmbH