+49 6151 6290246

Published: August 6, 2026

DORA: The Digital Operational Resilience Act Explained

This text was generated using artificial intelligence (AI).

The Digital Operational Resilience Act (DORA) requires the European financial sector to adopt a uniform approach to IT risks. The regulation has been in effect since January 17, 2025, and applies not only to banks and insurers but also to their ICT service providers. This overview explains the scope of application, the five pillars, supervision, sanctions, and how it differs from the NIS2 Directive (as of August 2026).

DORA stands for Digital Operational Resilience Act. In German, the terms are DORA Regulation and Regulation on Digital Operational Resilience in the Financial Sector commonly used. The term „DORA Directive,“ which is sometimes used, is inaccurate: DORA is a directly applicable EU regulation.

Key Points at a Glance

What is the Digital Operational Resilience Act?

DORA is an EU regulation on digital operational resilience in the financial sector. It was published in December 2022 as Regulation (EU) 2022/2554 in the Official Journal of the European Union. Following a transition period of approximately two years, it has been mandatory since January 17, 2025. As a regulation, DORA is directly applicable in every Member State; unlike a directive, it does not require national legislation to implement its provisions.

The goal: Financial institutions should be able to withstand IT disruptions and cyberattacks without critical business processes failing. To this end, DORA harmonizes requirements that were previously scattered across national circulars. In Germany, BaFin has repealed its IT supervisory circulars VAIT, KAIT, and ZAIT effective January 17, 2025, because DORA covers their content. According to BaFin, the BAIT guidelines now apply only to supervised entities that are not yet required to implement ICT risk management in accordance with DORA.

The regulation itself constitutes only the first level. Regulatory Technical Standards (RTS) and Implementing Technical Standards (ITS) specify many obligations in detail, such as the classification of incidents, the content of reports, or the contractual requirements for service providers. Anyone implementing DORA must also review these Level 2 legal acts.

Who is affected by DORA?

Article 2 of the regulation lists approximately 20 categories of financial institutions. These include, among others:

In addition, there are third-party ICT service providers—that is, providers of cloud services, data centers, software, or data analytics for the financial sector. They are subject to DORA requirements indirectly through their contracts with their financial clients. If they are classified as critical by European supervisory authorities, an additional direct supervisory framework applies. The regulation provides for exemptions for micro-enterprises, and certain groups, such as small insurance intermediaries, are exempt.

In Germany, the FinmadiG, which was enacted in December 2024, has further expanded the scope. According to BaFin, this means that additional institutions governed by the German Banking Act (Kreditwesengesetz) now fall under DORA, such as guarantee banks and financial services institutions. A transition period applies to them until January 1, 2027; however, the reporting requirements have been in effect since January 17, 2025.

The Five Pillars of DORA

DORA organizes the requirements into five thematic blocks that build on one another:

In practice, the fourth pillar ties up the most resources. While many financial firms are familiar with their contracts, they are not aware of the actual security status of their service providers. This is precisely where continuous assessment procedures come into play.

Reporting Requirements: Deadlines for Serious ICT Incidents

The reporting deadlines are set forth in Delegated Regulation (EU) 2025/301. It provides for a three-step procedure:

AnnouncementDeadlineContents
Initial ReportWithin 4 hours of being classified as serious, and no later than 24 hours after becoming aware of the incidentInitial Assessment, Affected Services, Preliminary Evaluation
Interim ReportNo later than 72 hours after the initial report is submittedStatus Update, Impact, Actions Taken
Final ReportNo later than one month after the last (updated) interim reportRoot Cause Analysis, Actual Impacts, Corrective Actions

In Germany, BaFin serves as the central authority for receiving these reports. If a deadline falls on a weekend or a holiday, financial institutions may submit their reports by 12:00 p.m. on the next business day. This exemption does not apply to initial and interim reports from credit institutions, central counterparties, trading venue operators, and NIS2 entities classified as critical or important. In addition, financial firms may voluntarily report significant cyber threats. To meet these deadlines, firms need well-established detection and classification processes; a purely ad hoc response is not sufficient.

Supervision: BaFin and the European Supervisory Framework

For German financial institutions, BaFin is the competent supervisory authority; it works closely with the Deutsche Bundesbank. BaFin serves as the national reporting center for ICT incidents, receives the information registers on third-party risk, and evaluates the data with regard to risks to the financial sector. It also determines which companies are required to conduct threat-based penetration tests.

A new development is the European level: The three EU supervisory authorities—EBA, EIOPA, and ESMA—classify certain third-party ICT service providers as critical to the financial sector. For each critical provider, a lead supervisory authority assumes direct oversight, with rights to request information, conduct investigations, and carry out inspections—including on-site audits. As a result, major cloud and IT providers are subject to their own financial supervision at the EU level for the first time, even though they are not financial institutions themselves.

Penalties for Violations

DORA does not prescribe uniform EU-wide fine amounts for financial institutions. Article 50 requires Member States to establish sanctions and corrective measures that are „effective, proportionate, and dissuasive.“ In Germany, the FinmadiG has enshrined the sanction standards in the German Banking Act (KWG), among other laws. Section 56 of the KWG now also covers DORA violations; for legal entities, it provides for fines of up to 20 million euros or 10 percent of total annual revenue for certain violations, whichever amount is higher.

For critical third-party ICT service providers, the regulation itself includes a powerful enforcement tool: Under Article 35 of DORA, the lead supervisory authority may impose daily penalty payments of up to one percent of the average global daily revenue in the preceding fiscal year, on a daily basis for a period of up to six months.

Added to this is the personal dimension: According to Article 5 of DORA, the governing body bears ultimate responsibility for ICT risk management. Executive boards that neglect implementation and oversight thereby also expose themselves to personal liability risks.

DORA and NIS2: Similarities and Differences

DORA and the NIS2 Directive Both stem from the EU legislative package of December 2022, but take different approaches. Article 4 of the NIS2 Directive governs the relationship: Sector-specific legal acts with at least equivalent effect take precedence. For financial firms, DORA is therefore considered lex specialis, but only with regard to ICT risk management and incident reporting. An overview of the NIS2 Requirements and Mandatory Measures shows which other topics the directive covers.

CriterionDORANIS2
Legal NatureEU Regulation, directly applicableEU Directive; national implementation required
ValidityEffective January 17, 2025Implementation deadline: October 17, 2024; progress varies by member state
RecipientsFinancial institutions and third-party ICT service providers18 sectors, including energy, transportation, health care, and digital infrastructure
FocusDigital Operational Resilience of ICT Systems in the Financial SectorCybersecurity Risk Management and Reporting Requirements Across Industries
Regulation in GermanyBaFin, in cooperation with the BundesbankBSI, in accordance with national implementation
Sanctions FrameworkRegulated at the national level; in Germany, among other things, through the KWG; penalties for non-compliant third-party ICT service providers of up to 1 % of global daily revenueFor essential facilities, at least 10 million euros or 2 % of global revenue; for important facilities, 7 million euros or 1.4 %

Important for practice: The priority rule does not generally exempt financial firms from NIS2. It merely supersedes the obligations that DORA regulates in an equivalent or more stringent manner. Groups with companies both within and outside the financial sector must monitor both sets of regulations in parallel.

Frequently asked questions


The regulation took effect in January 2023 and has been mandatory since January 17, 2025. According to BaFin, institutions that fall under DORA for the first time as a result of the German FinmadiG are subject to a transition period until January 1, 2027; however, their reporting obligations are already in effect.


Yes, in two stages. All third-party ICT service providers for financial firms meet the requirements indirectly through the minimum contractual terms that their clients must enforce. Providers classified as critical are also subject to direct oversight by European supervisory authorities, including audits and fines.


A threat-led penetration test simulates real-world attacks on a financial institution’s production systems, based on current threat scenarios. Under Article 26 of DORA, it must be conducted at least once every three years. The competent supervisory authority determines which companies are subject to this requirement based on the criteria set forth in the regulation.


No. DORA takes precedence over NIS2 for financial institutions only where the obligations overlap—that is, in the areas of ICT risk management and incident reporting. For companies outside the financial sector, NIS2 remains the governing framework.


One Security Rating assesses a company’s externally visible attack surface based on measurable criteria. This allows for continuous monitoring of the security status of a company’s own systems and those of its ICT service providers, for example as a component of ongoing monitoring under Pillar Four. The contractual and organizational implementation of DORA does not replace a rating, but it does provide reliable data for risk-based decisions.

Conclusion: Address third-party risk as an ongoing task

DORA makes the management of ICT service providers an ongoing obligation: maintaining information registries, refining contracts, and continuously evaluating service providers. LocateRisk supports you in this process with a vendor risk management solution that combines questionnaires and KPI-based security ratings. The analysis examines the externally visible attack surface of your service providers—without requiring agent installation, in compliance with the GDPR, and hosted in certified German data centers. Learn how to set up your vendor risk management for DORA.


Want to find out more, book a demo or simply exchange ideas? We look forward to hearing from you!

Your personal consultantLukas BaumannCEO

+49 6151 6290246

Get in Touch Now

en_USEnglish