Compliance & frameworks

What is the DORA Regulation?

The EU rulebook for keeping banks, insurers and other financial firms running through any ICT failure. Here is what DORA requires, who it covers and how Sweden enforces it.

Key takeaways
  • DORA, Regulation (EU) 2022/2554, is the EU law requiring financial firms to withstand and recover from any ICT disruption. It has applied across the EU since 17 January 2025.
  • It entered into force on 16 January 2023 after adoption on 14 December 2022, giving firms a two-year runway to comply.
  • DORA covers around 20 categories of financial entity under Article 2, plus the ICT suppliers that serve them.
  • The regulation rests on five pillars: ICT risk management, incident reporting, resilience testing, third-party risk management and information sharing.
  • Major incidents follow a fixed clock: initial notification within 4 hours of classification, an intermediate report within 72 hours and a final report within one month.
  • The largest firms must run threat-led penetration testing at least every three years under Article 26, based on the ECB’s TIBER-EU method.
  • “For financial entities DORA sets no EU-wide fine. Swedish penalties depend on the type of firm and reach up to 10 per cent of turnover for the largest institutions, and the management body carries ultimate responsibility under Article 5.
  • The European Supervisory Authorities can supervise the most critical ICT suppliers directly and fine them up to 1 percent of daily worldwide turnover under Article 35.
  • On 18 November 2025 the Authorities designated the first 19 critical ICT third-party providers.
  • In Sweden, Finansinspektionen supervises DORA and receives incident reports, and DORA takes precedence over NIS2 for financial firms.

DORA Defined in Plain Terms

The DORA regulation or Digital Operational Resilience Act is an EU law that requires banks, insurers and other financial firms to withstand, respond to and recover from every kind of technology disruption. It sets one binding standard for ICT risk across the whole EU financial sector from cyberattacks to simple software failures.

Formally it is Regulation (EU) 2022/2554. The European Parliament and Council adopted it on 14 December 2022, it entered into force on 16 January 2023 and it has applied across all 27 member states since 17 January 2025.

Before DORA, digital resilience rules for finance were scattered across different directives and national regimes. A bank in Stockholm and a payment firm in Frankfurt could face very different expectations. DORA replaces that patchwork with a single rulebook that applies directly without each country passing its own version first.

Who DORA Applies To

DORA covers around 20 categories of financial entity listed in Article 2. That includes credit institutions, payment and electronic money institutions, investment firms, insurers and reinsurers, crypto-asset service providers, central securities depositories and trading venues.

It also reaches beyond finance itself. The technology companies that supply these firms from cloud platforms to trading and data providers, are pulled into scope as ICT third-party service providers. This is the part of DORA that makes it unusual.

For financial entities, DORA takes precedence over NIS2. The two overlap but DORA is the sector-specific law so a bank follows DORA for its ICT risk rather than the general regime. Firms in sectors like energy, transport and health follow NIS2 instead.

The Five Pillars of DORA

DORA is built on five pillars. Together they cover the full lifecycle of an ICT problem from preventing it to sharing what you learned afterwards.

  • ICT Risk Management: The board owns a framework to identify, protect, detect, respond and recover across all technology the firm relies on.
  • ICT Incident Management and Reporting: Firms classify incidents by severity and report the major ones to their supervisor on a fixed clock.
  • Digital Operational Resilience Testing: Regular testing of systems, rising to threat-led penetration testing for the largest firms.
  • ICT Third-Party Risk Management: Oversight of every technology supplier with contracts, exit plans and a register of arrangements.
  • Information Sharing: Voluntary exchange of cyber threat intelligence between financial firms with legal cover for good-faith sharing.
The Five Pillars of DORA

Sitting on top of these is something new for the EU. The regulation lets the European Supervisory Authorities designate the most systemically important technology suppliers as critical ICT third-party providers and supervise them directly.

What DORA Requires of Financial Entities

DORA turns those pillars into concrete duties. A few carry real operational weight.

The management body is accountable. Under Article 5 the board must approve and oversee the ICT risk framework, and directors can be held personally responsible for failures. Digital resilience is a boardroom matter not something to delegate and forget.

Every firm must keep a register of information covering all its ICT third-party contracts under Article 28 and submit it to the supervisor each year. Regulators use these registers to see where the whole sector leans on the same few suppliers.

Contracts with ICT providers must contain specific terms under Article 30 including audit rights, service levels, exit strategies and rules on sub-outsourcing. A handshake arrangement with a critical supplier no longer meets the standard.

Major ICT-related incidents must be reported to the supervisor on a strict timetable set by Article 19 and the technical standards. The clock is tight.

  • Initial notification: As soon as possible within 4 hours of classifying an incident as major and no later than 24 hours after becoming aware of it.
  • Intermediate report: Within 72 hours of the initial notification even if nothing has changed.
  • Final report: No later than one month after the last intermediate report.

The four-hour clock starts at classification not at first detection, so fast and defensible classification is the real challenge.

All in-scope firms must test their resilience regularly including vulnerability assessments and penetration testing. The largest and most systemic firms go further and run threat-led penetration testing at least every three years under Article 26 using live systems and the ECB’s TIBER-EU method.

Real-World ICT Incidents Behind DORA

DORA did not appear from nowhere. A run of incidents showed how a single technology failure can ripple across the financial system. Three make the point.

Real-World ICT Incidents Behind DORA

The CrowdStrike Outage of July 2024

On 19 July 2024 the security vendor CrowdStrike pushed a faulty update to its Falcon sensor. According to Microsoft it crashed around 8.5 million Windows devices worldwide, a figure that counts only the machines that reported the crash.

This was not an attack. It was a routine update gone wrong yet it grounded flights, froze hospitals and disrupted banks, brokerages and the London Stock Exchange Group’s Workspace platform. One supplier’s mistake became everyone’s outage.

DORA answers this through its third-party pillar. Firms have to map where they depend on a single provider and hold tested continuity plans so that one supplier’s failure does not halt their own critical services.

The ION Group Attack of January 2023

On 31 January 2023 ION Cleared Derivatives, part of ION Group, was hit by ransomware attributed to the LockBit group. The firm’s software automates derivatives trading and clearing for banks and brokers across Europe and the United States.

With the platform down, at least 42 of ION’s clients had to process trades by hand according to Bloomberg and settlement was delayed. The Futures Industry Association stepped in to coordinate information between affected members while the damage was assessed.

ION contained the incident and brought clients back online over the following days and US officials judged that it had not created systemic risk. Even so it showed why DORA pairs third-party oversight with information sharing during a cross-firm crisis.

The TSB Migration of 2018

In April 2018 the UK bank TSB moved its data to a new IT platform. The data arrived intact but the platform failed on contact locking a large share of TSB’s 5.2 million customers out of branch, phone and online banking for months.

In December 2022 the FCA and the Prudential Regulation Authority fined TSB 48.65 million pounds for the operational and outsourcing failures behind the migration and TSB paid 32.7 million pounds in customer redress. The case predates DORA and sits under UK rules but it is exactly the failure DORA now targets.

The lesson DORA draws is simple. Test major changes on the systems that matter before you go live and keep a rollback plan you have actually rehearsed.

Penalties and Enforcement Under DORA

DORA splits enforcement in two and the split matters.

DORA itself sets no EU-wide fine for financial entities. Sweden’s supplementary act, lag (2024:1278), sets its own ceilings for a defined group of entities including crypto-asset service providers, pension foundations and trade repositories at the highest of EUR 1 million, ten per cent of turnover or three times the gain. For every other financial entity including banks and insurers, penalties run through the law governing that firm’s business. For credit institutions under lagen om bank- och finansieringsrörelse the ceiling likewise reaches ten per cent of turnover.

For the designated critical ICT third-party providers, DORA sets the penalty itself. A Lead Overseer from the European Supervisory Authorities can impose daily payments of up to 1 percent of the provider’s average daily worldwide turnover for as long as six months under Article 35.

On 18 November 2025 the Authorities named the first 19 critical providers, a list built around the large cloud and infrastructure suppliers the sector leans on. Each one now answers to a Lead Overseer and to direct EU supervision.

In Sweden the supervisor is Finansinspektionen which receives incident reports and made digital operational resilience a supervisory priority for 2025. Directors carry personal accountability under Article 5 so the risk is not only financial.

How DORA Works With NIS2, GDPR and Swedish Law

DORA does not sit alone. Most financial firms already juggle other rules and the overlaps are easy to trip over.

NIS2 is the EU’s broad cybersecurity directive brought into Swedish law as Cybersäkerhetslagen, in force since 15 January 2026 and coordinated by the National Cyber Security Centre (NCSC) at FRA, which took over these functions from MCF (formerly
MSB) on 1 July 2026. For financial entities DORA takes precedence so a bank meets its ICT duties through DORA rather than NIS2 compliance in Sweden.

GDPR is separate again. A cyber incident that exposes personal data can trigger DORA reporting to Finansinspektionen and at the same time a 72-hour breach notification to IMY under GDPR Article 33. That is one incident triggering two separate reporting duties.

People often search for DORA EBA guidelines but the binding detail does not live in a single agency’s guidance. It sits in the regulatory and implementing technical standards written jointly by the three European Supervisory Authorities, the EBA, ESMA and EIOPA. The classification thresholds, the reporting templates and the testing rules all come from these standards.

The practical takeaway for a Swedish firm is to treat these as one programme. The controls overlap heavily, and mapping them together avoids doing the same work three times. Our DORA compliance and CISO advisory pages set out how the obligations line up.

How to Prepare for DORA

Preparing for DORA is less about buying a product and more about proving your resilience holds. A sensible order of work looks like this.

How to Prepare for DORA
  • Map your critical or important functions and the ICT systems and suppliers behind each one.
  • Build your register of information so every third-party arrangement is documented and current.
  • Fix your contracts, adding audit rights, exit plans and service levels for critical suppliers.
  • Rehearse incident reporting against the four-hour and 72-hour clocks until classification is fast.
  • Test the systems that matter, from vulnerability assessments to threat-led penetration testing where it applies.
  • Put the board in the loop, since Article 5 makes directors accountable for the whole framework.

None of this is a one-off. DORA expects resilience to be maintained, tested and evidenced year after year which is why most firms run it as a standing programme rather than a project with an end date.

If you want help scoping the work, eBuilder’s DORA compliance service and CISO advisory are built around exactly these obligations.

Myths & Facts

Myth

DORA only matters if you are a big bank.

DORA is just another cybersecurity rulebook about hackers.

If we comply with NIS2 we are already covered for DORA.

DORA compliance is the IT department's job.

Outsourcing our IT means the provider carries the DORA risk.

DORA is an EU rule, so Swedish specifics do not matter.

Fact

DORA covers around 20 categories of financial entity, from large banks to small payment firms, investment firms and crypto-asset providers. Size changes the detail, not whether the rules apply.

DORA covers every ICT disruption, not only attacks. A faulty supplier update or a failed IT migration is squarely in scope, as the CrowdStrike and TSB cases showed.

For financial entities DORA takes precedence over NIS2 and adds duties NIS2 does not, including a register of information, specific contract terms and threat-led penetration testing.

Article 5 makes the management body accountable for the ICT risk framework, and directors can be held personally responsible. The board cannot delegate the duty away.

The financial entity stays responsible for its ICT third-party risk under DORA. That means audit rights, exit plans and a documented register for every critical supplier.

In Sweden, Finansinspektionen supervises DORA, receives incident reports and made resilience a 2025 priority, and national rules set penalties reaching up to 10 per cent of turnover for the largest institutions.

Test Yourself

Four real-world scenarios, then six knowledge questions. See how prepared you would be under pressure.

Scenario Simulation

  1. Your firm confirms at 09:00 that a ransomware incident has hit a system supporting a critical function. You classify it as major at 11:00.

    When is your initial notification to the supervisor due?

    • By 15:00, four hours after classification
    • By 09:00 the next day, 24 hours after awareness
    • Within 72 hours
    • Only once the incident is resolved
  2. A single security vendor pushes a faulty update that crashes the laptops running one of your critical services. It is not an attack, just a bad update.

    Is this in scope for DORA, and what should have limited the damage?

    • Yes. It is an ICT incident, and tested continuity plans for that supplier should limit it
    • No. DORA only covers cyberattacks, not vendor mistakes
    • Yes, but nothing could have limited it
    • No, because the vendor is responsible, not you
  3. You are onboarding a new cloud provider that will host a critical function. Procurement wants to sign the provider's standard terms to save time.

    What does DORA require before you sign?

    • Specific terms including audit rights, exit plans and service levels
    • Nothing extra, standard terms are fine
    • Only a price agreement
    • A verbal assurance from the provider
  4. At a board meeting a director says ICT risk is fully handled by the IT team and does not need board attention.

    How should you respond under DORA?

    • The board must approve and oversee the framework and is accountable under Article 5
    • Agree, since ICT risk is an IT matter
    • It only matters if an incident occurs
    • Only the CISO is accountable

Knowledge Test

  1. What does DORA stand for?

    • Data Operations Resilience Act
    • Digital Operational Resilience Act
    • Digital Oversight and Reporting Act
    • Data Oversight Resilience Agreement

    DORA is the Digital Operational Resilience Act, Regulation (EU) 2022/2554.

  2. Since when has DORA applied across the EU?

    • 16 January 2023
    • 14 December 2022
    • 17 January 2025
    • 1 January 2026

    DORA entered into force on 16 January 2023 but has applied since 17 January 2025.

  3. How many pillars does DORA have?

    • Three
    • Four
    • Five
    • Six

    DORA rests on five pillars, plus a separate oversight framework for critical ICT suppliers.

  4. How often must identified firms run threat-led penetration testing?

    • Every year
    • At least every three years
    • Every five years
    • Only once

    Article 26 requires TLPT at least every three years for identified firms, based on TIBER-EU.

  5. Who supervises DORA in Sweden?

    • MCF (formerly MSB)
    • IMY
    • Finansinspektionen
    • The European Central Bank

    Finansinspektionen is Sweden's competent authority for DORA. NCSC at FRA coordinates NIS2, a role it took over from MCF on 1 July 2026, and IMY handles GDPR.

  6. What is the maximum daily penalty for a designated critical ICT provider?

    • 1 percent of daily worldwide turnover
    • 2 percent of annual turnover
    • 10 percent of turnover
    • A fixed 5 million euro fine

    Under Article 35 a Lead Overseer can impose up to 1 percent of average daily worldwide turnover per day, for up to six months.

Take It with You

Share the Summary PDF with Your Team

A short distilled brief in PDF: key findings, red flags and action steps.

Download summary PDF

Why Training Matters

DORA does not treat technology as separate from the people running it. Article 13 requires financial firms to run ICT security awareness programmes and staff training as part of the risk framework, supervised by Finansinspektionen.

The reasoning is practical. Most incidents start with a person, whether that is a mis-sent credential, a phishing click or a change pushed without proper checks. Regular, role-relevant security awareness training turns staff from the softest part of the system into an early warning layer.

It also gives the board evidence that the awareness duty under DORA is being met, which is exactly the kind of proof a supervisor looks for.

You Understand the Risk.
Now See Where You Stand.

Book a 30-minute briefing with one of our analysts, or run the free breach check first to find out what attackers already know about your organisation.

Book a 30-Min Briefing
No sales pitch, just a straight assessment

How eBuilder Security Can Help

Awareness is the first layer. These are the services that turn it into measurable protection.