{"id":7321,"date":"2025-09-11T09:00:00","date_gmt":"2025-09-11T09:00:00","guid":{"rendered":"https:\/\/www.securitytoday.de\/2026\/04\/02\/post_id-3611\/"},"modified":"2026-07-04T10:21:42","modified_gmt":"2026-07-04T10:21:42","slug":"dora-in-practice-first-experiences-from-the-financial-sector","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2025\/09\/11\/dora-in-practice-first-experiences-from-the-financial-sector\/","title":{"rendered":"DORA in Practice: First Experiences from the Financial Sector"},"content":{"rendered":"<p style=\"color:#69d8ed;font-size:0.9em;margin:0 0 16px;padding:0;\">1 min Reading Time<\/p>\n<p><strong>DORA has been fully applicable since January 17, 2025. After the first few months, it is clear: The technical requirements for ICT risk management, testing, and third-party control are complex  &#8211;  but the biggest bottleneck is often not the technology, but governance and third-party contracts.<\/strong><\/p>\n<h2>TL;DR<\/h2>\n<ul>\n<li><strong>DORA mandatory since January 2025:<\/strong> All financial institutions in the EU are subject to the requirements.<\/li>\n<li><strong>5 Pillars:<\/strong> ICT risk management, incident reporting, resilience testing, third-party management, information sharing.<\/li>\n<li><strong>Third-party management is the biggest stumbling block:<\/strong> Contracts with ICT service providers must include DORA clauses.<\/li>\n<li><strong>TLPT for systemically important institutions:<\/strong> Threat-Led Penetration Testing  &#8211;  more complex and expensive than classic penetration tests.<\/li>\n<li><strong>Overlaps with NIS2:<\/strong> Companies compliant with NIS2 have a good foundation, but DORA goes further in some areas.<\/li>\n<\/ul>\n<h2>The 5 DORA Pillars in Overview<\/h2>\n<p><strong>1. ICT Risk Management:<\/strong> Comprehensive framework with risk policy, asset inventory, protective measures, and monitoring. Not just documented, but lived and regularly tested.<\/p>\n<p><strong>2. ICT Incident Reporting:<\/strong> Significant incidents must be reported to the competent authority within 4 hours (initial warning), 24 hours (interim report), and 1 month (final report). Clear classification criteria for &#8220;significant&#8221; are mandatory.<\/p>\n<p><strong>3. Digital Operational Resilience Testing:<\/strong> Annual ICT test programs, with additional Threat-Led Penetration Testing (TLPT) every 3 years for significant institutions, conducted by certified external testers.<\/p>\n<p><strong>4. ICT Third-Party Management:<\/strong> Register of all critical ICT service providers, risk classification, contract clauses (audit rights, exit plans, subcontracting), concentration risk analysis.<\/p>\n<p><strong>5. Information Sharing:<\/strong> Voluntary exchange of cyber threat information within the financial industry  &#8211;  institutionalized through DORA.<\/p>\n<h2>First Practical Experiences: What is More Challenging Than Expected<\/h2>\n<p><strong>Third-Party Contract Adjustments:<\/strong> Thousands of existing contracts with ICT service providers must include DORA clauses. Many providers resist audit rights or do not accept DORA-compliant subcontracting regulations. This is time-consuming and ties up significant legal and procurement resources.<\/p>\n<p><strong>Criticality Assessment:<\/strong> Which ICT service providers are &#8220;critical&#8221;? The DORA criteria are clear, but their application in practice is less so. Many institutions have identified 50+ critical service providers  &#8211;  setting up a complete DORA-compliant monitoring system for each exceeds their capacities.<\/p>\n<p><strong>TLPT Preparation:<\/strong> Threat-Led Penetration Testing is more complex than classic penetration tests. It requires threat intelligence about the specific threat profile of the institution, a certified external tester (TIBER-EU Framework), and months of preparation.<\/p>\n<h2>What Works Well  &#8211;  and What NIS2 Companies Can Do<\/h2>\n<p>Companies that are already NIS2-compliant have a significant advantage: ICT risk management framework, incident response processes, and third-party monitoring are already in place. DORA requires more granularity and more specific testing requirements, but the foundation is there.<\/p>\n<p>What works well: The incident reporting chains are clearer than under NIS2 alone  &#8211;  banks have years of experience with reporting obligations to BaFin and EBA. The 4-hour initial reporting deadline is demanding, but technically achievable with well-configured SIEM and on-call processes.<\/p>\n<h2>Key Facts at a Glance<\/h2>\n<p><strong>DORA Application Date:<\/strong> January 17, 2025<\/p>\n<p><strong>Betroffene Institute:<\/strong> Over 22,000 financial companies in the EU<\/p>\n<p><strong>Initial Reporting SLA:<\/strong> 4 hours for significant ICT incidents<\/p>\n<p><strong>TLPT Requirement:<\/strong> Every 3 years for systemically important institutions (TIBER-EU Framework)<\/p>\n<p><strong>Penalties:<\/strong> Up to 1% of daily global revenue<\/p>\n<p><strong>Fact:<\/strong> Through DORA, over 22,000 financial institutions and their critical ICT service providers across the EU are required to conduct digital resilience tests  &#8211;  a regulatory first.<\/p>\n<p><strong>Fact:<\/strong> The BaFin reports that 38% of the institutions examined in the first DORA readiness check showed deficiencies in their ICT risk management frameworks.<\/p>\n<h2>Frequently Asked Questions<\/h2>\n<p class=\"st-faq-hint\">Every question is locked. A tap unlocks the answer.<\/p>\n<details>\n<summary><strong>Who does DORA apply to?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">All EU-regulated financial companies: banks, insurance companies, investment firms, payment service providers, crypto-asset service providers, and critical ICT third-party service providers in the financial industry.<\/p>\n<\/details>\n<details>\n<summary><strong>What is the difference between DORA and NIS2?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">NIS2 is a horizontal regulation for many sectors. DORA is sector-specific for finance and goes further in several areas: more specific testing requirements, stricter third-party management, and more direct supervision of critical ICT third-party service providers by ESAs.<\/p>\n<\/details>\n<details>\n<summary><strong>What is a critical ICT third-party service provider under DORA?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Providers whose failure could have a systemic impact on the financial sector. Critical ICT third-party service providers are directly supervised by ESAs (EBA, EIOPA, ESMA)  &#8211;  with their own inspection rights and penalty authority.<\/p>\n<\/details>\n<details>\n<summary><strong>What are the most important DORA contract clauses?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Exit clauses, audit rights (including for sub-service providers), service level agreements for business continuity, data access rights in the event of insolvency, clauses on subcontracting and concentration risk disclosure.<\/p>\n<\/details>\n<details>\n<summary><strong>How does DORA relate to TIBER-EU?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">TIBER-EU (Threat Intelligence-based Ethical Red Teaming) is the European framework for Threat-Led Penetration Testing. DORA makes TLPT according to TIBER-EU guidelines mandatory for significant institutions  &#8211;  thus turning TIBER-EU from a voluntary framework into a regulatory requirement.<\/p>\n<\/details>\n<h2>Further Articles on the Topic<\/h2>\n<p>\u2192 DORA: More IT and Legal Security in the Financial Sector<\/p>\n<p>\u2192 <a href=\"https:\/\/www.securitytoday.de\/en\/2026\/02\/14\/post_id-3519\/\">NIS2 Checklist 2026<\/a><\/p>\n<h2>Further Reading in the Network<\/h2>\n<p>FinTech &#038; Regulation: <a href=\"https:\/\/mybusinessfuture.com\/ki-made-in-germany-935-startups-oekosystem\/\" target=\"_blank\" rel=\"noopener\">mybusinessfuture.com<\/a><\/p>\n<p>Security for the Financial Sector: <a href=\"https:\/\/www.digital-chiefs.de\/149-000-offene-it-stellen-wie-cios-ki-copiloten-als-fachkraeftersatz-nutzen\/\" target=\"_blank\" rel=\"noopener\">digital-chiefs.de<\/a><\/p>\n<h2>Related Articles<\/h2>\n<ul>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/02\/26\/post_id-3531\/\">GDPR 2026: What&#8217;s Changing and What Companies Need to Pay Attention To<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/02\/14\/post_id-3519\/\">NIS2 Checklist 2026: What Companies Need to Implement Now<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2025\/02\/25\/case-study-financial-services-cloud-migration-security\/\">Case Study: Cloud Migration of a Financial Service Provider  &#8211;  Security from the Start<\/a><\/li>\n<\/ul>\n<p style=\"font-weight:700;color:#e6e3da;font-size:1.05em;margin:48px 0 16px;\">More from the MBF Media Network<\/p>\n<div style=\"display:flex;flex-direction:column;gap:14px;margin-bottom:40px;\"><a href=\"https:\/\/www.cloudmagazin.com\" class=\"st-net-card\" style=\"display:block;padding:16px 18px;background:#23261f;border:1px solid rgba(105,216,237,0.22);border-radius:10px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 2px 10px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;\"><span style=\"display:block;margin-bottom:6px;font-size:0.72em;font-weight:700;letter-spacing:0.06em;text-transform:uppercase;color:#0bb7fd;\">cloudmagazin<\/span><span style=\"display:block;color:#e6e3da;line-height:1.45;\">cloudmagazin<\/span><\/a><a href=\"https:\/\/mybusinessfuture.com\" class=\"st-net-card\" style=\"display:block;padding:16px 18px;background:#23261f;border:1px solid rgba(105,216,237,0.22);border-radius:10px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 2px 10px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;\"><span style=\"display:block;margin-bottom:6px;font-size:0.72em;font-weight:700;letter-spacing:0.06em;text-transform:uppercase;color:#aa8ac2;\">MyBusinessFuture<\/span><span style=\"display:block;color:#e6e3da;line-height:1.45;\">MyBusinessFuture<\/span><\/a><a href=\"https:\/\/www.digital-chiefs.de\" class=\"st-net-card\" style=\"display:block;padding:16px 18px;background:#23261f;border:1px solid rgba(105,216,237,0.22);border-radius:10px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 2px 10px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;\"><span style=\"display:block;margin-bottom:6px;font-size:0.72em;font-weight:700;letter-spacing:0.06em;text-transform:uppercase;color:#d65663;\">Digital Chiefs<\/span><span style=\"display:block;color:#e6e3da;line-height:1.45;\">Digital Chiefs<\/span><\/a><\/div>\n","protected":false},"excerpt":{"rendered":"DORA has been fully applicable since January 17, 2025. After the first few months, it is clear: The technical requirements for ICT risk management, testing, and third-party control are complex &#8211; but the biggest bottleneck is often not the technology, but governance and third-party contracts. TL;DR DORA mandatory since January 2025: [&hellip;]","protected":false},"author":55,"featured_media":3610,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"dora","_yoast_wpseo_title":"DORA in Practice: First Experiences from the Financial Sector","_yoast_wpseo_metadesc":"DORA compliance made easy: Learn how financial firms are mastering ICT risk, testing & third-party controls\u2014get actionable insights now!","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"","_yoast_wpseo_twitter-image-id":0,"_evm_slot_owner":"","evm_cvss":0,"evm_risk":0,"evm_casefile":"","evm_primary_cve":"","evm_pin_until":0,"evm_external_preview_token":"","evm_external_preview_expires":"","_evm_translation_lang":"","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":["post_id-3611"],"footnotes":""},"categories":[215],"tags":[],"class_list":["post-7321","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-case-studies"],"evm_reading_time_minutes":5,"wpml_language":"en","wpml_translation_of":3611,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/7321","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/55"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=7321"}],"version-history":[{"count":4,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/7321\/revisions"}],"predecessor-version":[{"id":18600,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/7321\/revisions\/18600"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/3610"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=7321"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=7321"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=7321"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}