DORA: Operational Resilience for the Financial Sector
DORA (Digital Operational Resilience Act) is the EU regulation that entered into force for the financial sector in January 2025. It mandates digital operational resilience through strict requirements for ICT risk management, TLPT testing, incident reporting, and supply-chain management. It has a major impact on network infrastructure. DORA 2026 guide.
Entities in scope
- Banks, asset management companies, and insurers
- FinTech and crypto-asset firms (MiCA)
- Market infrastructures (stock exchanges, CCPs)
- Critical ICT providers (cloud providers, B2B FinTech firms)
- Exemption: microenterprises with <10 employees and <€2M in revenue
The 5 pillars of DORA
1. ICT risk management
- Governance: CEO accountability
- Comprehensive ICT mapping
- Formalized risk management + annual review
- Tested BCP + DRP
2. Incident reporting
- Classification of major incidents affecting critical services
- Notification to the relevant authority: initial report within <4h, follow-up within 24-48h, and final report within 1 month
- In France: ACPR + AMF, depending on the sector
3. Operational resilience testing
- Annual testing + advanced testing every 3 years
- TLPT (Threat-Led Penetration Testing) for large entities
- Red team exercises
- Advanced scenarios: ransomware and supply-chain attacks
4. Third-party risk
- ICT provider register
- Mandatory contracts with specific clauses
- Customer audit rights
- Concentration risk: identify critical 3P dependencies
5. Information sharing
- Threat intelligence sharing among financial entities (voluntary but encouraged)
- Participation in TIBER-EU
Network impact
- Mandatory segmentation + micro-segmentation
- 24×7 SIEM + SOC for rapid notification
- Geographically diverse DC redundancy for backup scenarios
- 10-year log retention
- Annual cyber-resilience testing
- Mandatory annual penetration testing and TLPT every 3 years for large enterprises
ICT supply chain
Major impact on cloud providers (AWS, Azure, GCP, OVH):
- Security transparency requirements
- Audit rights for regular customers
- Streamlined proprietary contract exit process
- Concentration risk: limits on single-vendor dependency
Penalties
- Fines: up to 2% of annual worldwide revenue
- For executives: personal fine of €1M
- Possible suspension of operations
- Reputational impact: public disclosure
Compliance: 12-month roadmap
- Months 1-3: gap analysis against DORA
- Months 3-6: redesign risk management + incident processes
- Months 6-9: deploy tools (SIEM, SOC, SIEM, TLPT)
- Months 9-12: testing + documentation
- After completion: annual ACPR audit
Typical compliance budget
- SME bank: €500k-2M
- Mid-sized enterprise: €5-15M
- Large bank: €30-100M
- Includes tools, consultants, testing, and training
Order from OPTINOC
DORA compliance support: audits, tool deployment (Splunk/Sentinel SIEM, ZTNA, micro-segmentation), and partner-led TLPT. Financial-sector expertise. Quote within 1 week.
