DORA Defined in Plain Terms
The DORA regulation or Digital Operational Resilience Act is an EU law that requires banks, insurers and other financial firms to withstand, respond to and recover from every kind of technology disruption. It sets one binding standard for ICT risk across the whole EU financial sector from cyberattacks to simple software failures.
Formally it is Regulation (EU) 2022/2554. The European Parliament and Council adopted it on 14 December 2022, it entered into force on 16 January 2023 and it has applied across all 27 member states since 17 January 2025.
Before DORA, digital resilience rules for finance were scattered across different directives and national regimes. A bank in Stockholm and a payment firm in Frankfurt could face very different expectations. DORA replaces that patchwork with a single rulebook that applies directly without each country passing its own version first.
Who DORA Applies To
DORA covers around 20 categories of financial entity listed in Article 2. That includes credit institutions, payment and electronic money institutions, investment firms, insurers and reinsurers, crypto-asset service providers, central securities depositories and trading venues.
It also reaches beyond finance itself. The technology companies that supply these firms from cloud platforms to trading and data providers, are pulled into scope as ICT third-party service providers. This is the part of DORA that makes it unusual.
For financial entities, DORA takes precedence over NIS2. The two overlap but DORA is the sector-specific law so a bank follows DORA for its ICT risk rather than the general regime. Firms in sectors like energy, transport and health follow NIS2 instead.
The Five Pillars of DORA
DORA is built on five pillars. Together they cover the full lifecycle of an ICT problem from preventing it to sharing what you learned afterwards.
- ICT Risk Management: The board owns a framework to identify, protect, detect, respond and recover across all technology the firm relies on.
- ICT Incident Management and Reporting: Firms classify incidents by severity and report the major ones to their supervisor on a fixed clock.
- Digital Operational Resilience Testing: Regular testing of systems, rising to threat-led penetration testing for the largest firms.
- ICT Third-Party Risk Management: Oversight of every technology supplier with contracts, exit plans and a register of arrangements.
- Information Sharing: Voluntary exchange of cyber threat intelligence between financial firms with legal cover for good-faith sharing.

Sitting on top of these is something new for the EU. The regulation lets the European Supervisory Authorities designate the most systemically important technology suppliers as critical ICT third-party providers and supervise them directly.
What DORA Requires of Financial Entities
DORA turns those pillars into concrete duties. A few carry real operational weight.
The management body is accountable. Under Article 5 the board must approve and oversee the ICT risk framework, and directors can be held personally responsible for failures. Digital resilience is a boardroom matter not something to delegate and forget.
Every firm must keep a register of information covering all its ICT third-party contracts under Article 28 and submit it to the supervisor each year. Regulators use these registers to see where the whole sector leans on the same few suppliers.
Contracts with ICT providers must contain specific terms under Article 30 including audit rights, service levels, exit strategies and rules on sub-outsourcing. A handshake arrangement with a critical supplier no longer meets the standard.
Major ICT-related incidents must be reported to the supervisor on a strict timetable set by Article 19 and the technical standards. The clock is tight.
- Initial notification: As soon as possible within 4 hours of classifying an incident as major and no later than 24 hours after becoming aware of it.
- Intermediate report: Within 72 hours of the initial notification even if nothing has changed.
- Final report: No later than one month after the last intermediate report.
The four-hour clock starts at classification not at first detection, so fast and defensible classification is the real challenge.
All in-scope firms must test their resilience regularly including vulnerability assessments and penetration testing. The largest and most systemic firms go further and run threat-led penetration testing at least every three years under Article 26 using live systems and the ECB’s TIBER-EU method.
Real-World ICT Incidents Behind DORA
DORA did not appear from nowhere. A run of incidents showed how a single technology failure can ripple across the financial system. Three make the point.

The CrowdStrike Outage of July 2024
On 19 July 2024 the security vendor CrowdStrike pushed a faulty update to its Falcon sensor. According to Microsoft it crashed around 8.5 million Windows devices worldwide, a figure that counts only the machines that reported the crash.
This was not an attack. It was a routine update gone wrong yet it grounded flights, froze hospitals and disrupted banks, brokerages and the London Stock Exchange Group’s Workspace platform. One supplier’s mistake became everyone’s outage.
DORA answers this through its third-party pillar. Firms have to map where they depend on a single provider and hold tested continuity plans so that one supplier’s failure does not halt their own critical services.
The ION Group Attack of January 2023
On 31 January 2023 ION Cleared Derivatives, part of ION Group, was hit by ransomware attributed to the LockBit group. The firm’s software automates derivatives trading and clearing for banks and brokers across Europe and the United States.
With the platform down, at least 42 of ION’s clients had to process trades by hand according to Bloomberg and settlement was delayed. The Futures Industry Association stepped in to coordinate information between affected members while the damage was assessed.
ION contained the incident and brought clients back online over the following days and US officials judged that it had not created systemic risk. Even so it showed why DORA pairs third-party oversight with information sharing during a cross-firm crisis.
The TSB Migration of 2018
In April 2018 the UK bank TSB moved its data to a new IT platform. The data arrived intact but the platform failed on contact locking a large share of TSB’s 5.2 million customers out of branch, phone and online banking for months.
In December 2022 the FCA and the Prudential Regulation Authority fined TSB 48.65 million pounds for the operational and outsourcing failures behind the migration and TSB paid 32.7 million pounds in customer redress. The case predates DORA and sits under UK rules but it is exactly the failure DORA now targets.
The lesson DORA draws is simple. Test major changes on the systems that matter before you go live and keep a rollback plan you have actually rehearsed.
Penalties and Enforcement Under DORA
DORA splits enforcement in two and the split matters.
DORA itself sets no EU-wide fine for financial entities. Sweden’s supplementary act, lag (2024:1278), sets its own ceilings for a defined group of entities including crypto-asset service providers, pension foundations and trade repositories at the highest of EUR 1 million, ten per cent of turnover or three times the gain. For every other financial entity including banks and insurers, penalties run through the law governing that firm’s business. For credit institutions under lagen om bank- och finansieringsrörelse the ceiling likewise reaches ten per cent of turnover.
For the designated critical ICT third-party providers, DORA sets the penalty itself. A Lead Overseer from the European Supervisory Authorities can impose daily payments of up to 1 percent of the provider’s average daily worldwide turnover for as long as six months under Article 35.
On 18 November 2025 the Authorities named the first 19 critical providers, a list built around the large cloud and infrastructure suppliers the sector leans on. Each one now answers to a Lead Overseer and to direct EU supervision.
In Sweden the supervisor is Finansinspektionen which receives incident reports and made digital operational resilience a supervisory priority for 2025. Directors carry personal accountability under Article 5 so the risk is not only financial.
How DORA Works With NIS2, GDPR and Swedish Law
DORA does not sit alone. Most financial firms already juggle other rules and the overlaps are easy to trip over.
NIS2 is the EU’s broad cybersecurity directive brought into Swedish law as Cybersäkerhetslagen, in force since 15 January 2026 and coordinated by the National Cyber Security Centre (NCSC) at FRA, which took over these functions from MCF (formerly
MSB) on 1 July 2026. For financial entities DORA takes precedence so a bank meets its ICT duties through DORA rather than NIS2 compliance in Sweden.
GDPR is separate again. A cyber incident that exposes personal data can trigger DORA reporting to Finansinspektionen and at the same time a 72-hour breach notification to IMY under GDPR Article 33. That is one incident triggering two separate reporting duties.
People often search for DORA EBA guidelines but the binding detail does not live in a single agency’s guidance. It sits in the regulatory and implementing technical standards written jointly by the three European Supervisory Authorities, the EBA, ESMA and EIOPA. The classification thresholds, the reporting templates and the testing rules all come from these standards.
The practical takeaway for a Swedish firm is to treat these as one programme. The controls overlap heavily, and mapping them together avoids doing the same work three times. Our DORA compliance and CISO advisory pages set out how the obligations line up.
How to Prepare for DORA
Preparing for DORA is less about buying a product and more about proving your resilience holds. A sensible order of work looks like this.

- Map your critical or important functions and the ICT systems and suppliers behind each one.
- Build your register of information so every third-party arrangement is documented and current.
- Fix your contracts, adding audit rights, exit plans and service levels for critical suppliers.
- Rehearse incident reporting against the four-hour and 72-hour clocks until classification is fast.
- Test the systems that matter, from vulnerability assessments to threat-led penetration testing where it applies.
- Put the board in the loop, since Article 5 makes directors accountable for the whole framework.
None of this is a one-off. DORA expects resilience to be maintained, tested and evidenced year after year which is why most firms run it as a standing programme rather than a project with an end date.
If you want help scoping the work, eBuilder’s DORA compliance service and CISO advisory are built around exactly these obligations.


