DORA in Practice: First Experiences from the Financial Sector
DORA has been fully applicable since January 17, 2025. After the first few months, it is clear: The technical requirements for ICT risk management, testing, and third-party control are complex – but the biggest bottleneck is often not the technology, but governance and third-party contracts.
TL;DR
- DORA mandatory since January 2025: All financial institutions in the EU are subject to the requirements.
- 5 Pillars: ICT risk management, incident reporting, resilience testing, third-party management, information sharing.
- Third-party management is the biggest stumbling block: Contracts with ICT service providers must include DORA clauses.
- TLPT for systemically important institutions: Threat-Led Penetration Testing – more complex and expensive than classic penetration tests.
- Overlaps with NIS2: Companies compliant with NIS2 have a good foundation, but DORA goes further in some areas.
The 5 DORA Pillars in Overview
1. ICT Risk Management: Comprehensive framework with risk policy, asset inventory, protective measures, and monitoring. Not just documented, but lived and regularly tested.
2. ICT Incident Reporting: Significant incidents must be reported to the competent authority within 4 hours (initial warning), 24 hours (interim report), and 1 month (final report). Clear classification criteria for “significant” are mandatory.
3. Digital Operational Resilience Testing: Annual ICT test programs, with additional Threat-Led Penetration Testing (TLPT) every 3 years for significant institutions, conducted by certified external testers.
4. ICT Third-Party Management: Register of all critical ICT service providers, risk classification, contract clauses (audit rights, exit plans, subcontracting), concentration risk analysis.
5. Information Sharing: Voluntary exchange of cyber threat information within the financial industry – institutionalized through DORA.
First Practical Experiences: What is More Challenging Than Expected
Third-Party Contract Adjustments: Thousands of existing contracts with ICT service providers must include DORA clauses. Many providers resist audit rights or do not accept DORA-compliant subcontracting regulations. This is time-consuming and ties up significant legal and procurement resources.
Criticality Assessment: Which ICT service providers are “critical”? The DORA criteria are clear, but their application in practice is less so. Many institutions have identified 50+ critical service providers – setting up a complete DORA-compliant monitoring system for each exceeds their capacities.
TLPT Preparation: Threat-Led Penetration Testing is more complex than classic penetration tests. It requires threat intelligence about the specific threat profile of the institution, a certified external tester (TIBER-EU Framework), and months of preparation.
What Works Well – and What NIS2 Companies Can Do
Companies that are already NIS2-compliant have a significant advantage: ICT risk management framework, incident response processes, and third-party monitoring are already in place. DORA requires more granularity and more specific testing requirements, but the foundation is there.
What works well: The incident reporting chains are clearer than under NIS2 alone – banks have years of experience with reporting obligations to BaFin and EBA. The 4-hour initial reporting deadline is demanding, but technically achievable with well-configured SIEM and on-call processes.
Key Facts at a Glance
DORA Application Date: January 17, 2025
Betroffene Institute: Over 22,000 financial companies in the EU
Initial Reporting SLA: 4 hours for significant ICT incidents
TLPT Requirement: Every 3 years for systemically important institutions (TIBER-EU Framework)
Penalties: Up to 1% of daily global revenue
Fact: Through DORA, over 22,000 financial institutions and their critical ICT service providers across the EU are required to conduct digital resilience tests – a regulatory first.
Fact: The BaFin reports that 38% of the institutions examined in the first DORA readiness check showed deficiencies in their ICT risk management frameworks.
Frequently Asked Questions
Every question is locked. A tap unlocks the answer.
Who does DORA apply to?
All EU-regulated financial companies: banks, insurance companies, investment firms, payment service providers, crypto-asset service providers, and critical ICT third-party service providers in the financial industry.
What is the difference between DORA and NIS2?
NIS2 is a horizontal regulation for many sectors. DORA is sector-specific for finance and goes further in several areas: more specific testing requirements, stricter third-party management, and more direct supervision of critical ICT third-party service providers by ESAs.
What is a critical ICT third-party service provider under DORA?
Providers whose failure could have a systemic impact on the financial sector. Critical ICT third-party service providers are directly supervised by ESAs (EBA, EIOPA, ESMA) – with their own inspection rights and penalty authority.
What are the most important DORA contract clauses?
Exit clauses, audit rights (including for sub-service providers), service level agreements for business continuity, data access rights in the event of insolvency, clauses on subcontracting and concentration risk disclosure.
How does DORA relate to TIBER-EU?
TIBER-EU (Threat Intelligence-based Ethical Red Teaming) is the European framework for Threat-Led Penetration Testing. DORA makes TLPT according to TIBER-EU guidelines mandatory for significant institutions – thus turning TIBER-EU from a voluntary framework into a regulatory requirement.
Further Articles on the Topic
→ DORA: More IT and Legal Security in the Financial Sector
Further Reading in the Network
FinTech & Regulation: mybusinessfuture.com
Security for the Financial Sector: digital-chiefs.de
Related Articles
- GDPR 2026: What’s Changing and What Companies Need to Pay Attention To
- NIS2 Checklist 2026: What Companies Need to Implement Now
- Case Study: Cloud Migration of a Financial Service Provider – Security from the Start
More from the MBF Media Network