THREAT BRIEFING · 18.07.2026 DEENFRES

Case Studies

DORA in Practice: First Experiences from the Financial Sector

By Tobias Massow · September 11, 2025 · 5 min read

DORA has been fully applicable since January 17, 2025. After the first few months, it is clear: The technical requirements for ICT risk management, testing, and third-party control are complex – but the biggest bottleneck is often not the technology, but governance and third-party contracts.

TL;DR

The 5 DORA Pillars in Overview

1. ICT Risk Management: Comprehensive framework with risk policy, asset inventory, protective measures, and monitoring. Not just documented, but lived and regularly tested.

2. ICT Incident Reporting: Significant incidents must be reported to the competent authority within 4 hours (initial warning), 24 hours (interim report), and 1 month (final report). Clear classification criteria for “significant” are mandatory.

3. Digital Operational Resilience Testing: Annual ICT test programs, with additional Threat-Led Penetration Testing (TLPT) every 3 years for significant institutions, conducted by certified external testers.

4. ICT Third-Party Management: Register of all critical ICT service providers, risk classification, contract clauses (audit rights, exit plans, subcontracting), concentration risk analysis.

5. Information Sharing: Voluntary exchange of cyber threat information within the financial industry – institutionalized through DORA.

First Practical Experiences: What is More Challenging Than Expected

Third-Party Contract Adjustments: Thousands of existing contracts with ICT service providers must include DORA clauses. Many providers resist audit rights or do not accept DORA-compliant subcontracting regulations. This is time-consuming and ties up significant legal and procurement resources.

Criticality Assessment: Which ICT service providers are “critical”? The DORA criteria are clear, but their application in practice is less so. Many institutions have identified 50+ critical service providers – setting up a complete DORA-compliant monitoring system for each exceeds their capacities.

TLPT Preparation: Threat-Led Penetration Testing is more complex than classic penetration tests. It requires threat intelligence about the specific threat profile of the institution, a certified external tester (TIBER-EU Framework), and months of preparation.

What Works Well – and What NIS2 Companies Can Do

Companies that are already NIS2-compliant have a significant advantage: ICT risk management framework, incident response processes, and third-party monitoring are already in place. DORA requires more granularity and more specific testing requirements, but the foundation is there.

What works well: The incident reporting chains are clearer than under NIS2 alone – banks have years of experience with reporting obligations to BaFin and EBA. The 4-hour initial reporting deadline is demanding, but technically achievable with well-configured SIEM and on-call processes.

Key Facts at a Glance

DORA Application Date: January 17, 2025

Betroffene Institute: Over 22,000 financial companies in the EU

Initial Reporting SLA: 4 hours for significant ICT incidents

TLPT Requirement: Every 3 years for systemically important institutions (TIBER-EU Framework)

Penalties: Up to 1% of daily global revenue

Fact: Through DORA, over 22,000 financial institutions and their critical ICT service providers across the EU are required to conduct digital resilience tests – a regulatory first.

Fact: The BaFin reports that 38% of the institutions examined in the first DORA readiness check showed deficiencies in their ICT risk management frameworks.

Frequently Asked Questions

Every question is locked. A tap unlocks the answer.

Who does DORA apply to?

All EU-regulated financial companies: banks, insurance companies, investment firms, payment service providers, crypto-asset service providers, and critical ICT third-party service providers in the financial industry.

What is the difference between DORA and NIS2?

NIS2 is a horizontal regulation for many sectors. DORA is sector-specific for finance and goes further in several areas: more specific testing requirements, stricter third-party management, and more direct supervision of critical ICT third-party service providers by ESAs.

What is a critical ICT third-party service provider under DORA?

Providers whose failure could have a systemic impact on the financial sector. Critical ICT third-party service providers are directly supervised by ESAs (EBA, EIOPA, ESMA) – with their own inspection rights and penalty authority.

What are the most important DORA contract clauses?

Exit clauses, audit rights (including for sub-service providers), service level agreements for business continuity, data access rights in the event of insolvency, clauses on subcontracting and concentration risk disclosure.

How does DORA relate to TIBER-EU?

TIBER-EU (Threat Intelligence-based Ethical Red Teaming) is the European framework for Threat-Led Penetration Testing. DORA makes TLPT according to TIBER-EU guidelines mandatory for significant institutions – thus turning TIBER-EU from a voluntary framework into a regulatory requirement.

Further Articles on the Topic

→ DORA: More IT and Legal Security in the Financial Sector

NIS2 Checklist 2026

Further Reading in the Network

FinTech & Regulation: mybusinessfuture.com

Security for the Financial Sector: digital-chiefs.de

Related Articles

More from the MBF Media Network

cloudmagazincloudmagazinMyBusinessFutureMyBusinessFutureDigital ChiefsDigital Chiefs

Further reading

Case Studies · July 5, 2026

Südwestfalen IT: The Lesson of Municipal IT

Two years after the Southwestphalia IT attack, Security Today dissects: VPN without MFA, rebuilding without ransom, and five lessons for municipal IT.

A magazine by Evernine Media GmbH