{"id":9293,"date":"2026-08-06T10:03:35","date_gmt":"2026-08-06T10:03:35","guid":{"rendered":"http:\/\/locaterisk.com\/de\/?post_type=wissen&#038;p=9293"},"modified":"2026-08-06T11:22:08","modified_gmt":"2026-08-06T11:22:08","slug":"dora-regulation-overview","status":"publish","type":"wissen","link":"https:\/\/locaterisk.com\/en\/know\/dora-regulation-overview\/","title":{"rendered":"DORA: The Digital Operational Resilience Act Explained"},"content":{"rendered":"<h1 class=\"wp-block-heading\">DORA: The Digital Operational Resilience Act Explained<\/h1>\n<span class=\"lr-ai-disclosure\" style=\"display:block;max-width:843px;margin:8px auto 28px;font-size:14px;line-height:1.4;color:#8b93a7;font-family:inherit;font-style:italic;\">This text was generated using artificial intelligence (AI).<\/span>\n\n\n<p>The Digital Operational Resilience Act (DORA) requires the European financial sector to adopt a uniform approach to IT risks. The regulation has been in effect since January 17, 2025, and applies not only to banks and insurers but also to their ICT service providers. This overview explains the scope of application, the five pillars, supervision, sanctions, and how it differs from the NIS2 Directive (as of August 2026).<\/p>\n<p><strong>DORA<\/strong> stands for <strong>Digital Operational Resilience Act<\/strong>. In German, the terms are <strong>DORA Regulation<\/strong> and <strong>Regulation on Digital Operational Resilience in the Financial Sector<\/strong> commonly used. The term \u201eDORA Directive,\u201c which is sometimes used, is inaccurate: DORA is a directly applicable EU regulation.<\/p>\n\n\n<h2 class=\"wp-block-heading\">Key Points at a Glance<\/h2>\n\n\n\n<ul class=\"wp-block-list\"><li>DORA (Regulation (EU) 2022\/2554) has been directly applicable in all EU member states since January 17, 2025; no national implementing legislation is required for its provisions.<\/li><li>This affects approximately 20 categories of financial institutions, as well as third-party ICT service providers that offer services to the financial sector.<\/li><li>The regulation is based on five pillars: ICT risk management, incident reporting, resilience testing, third-party ICT risk, and information sharing.<\/li><li>In Germany, BaFin oversees compliance. The Financial Market Digitalization Act (FinmadiG) enshrines these powers and fines in national law.<\/li><li>For financial institutions, DORA takes precedence over the NIS2 Directive as a more specific set of rules, but only with regard to overlapping obligations.<\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">What is the Digital Operational Resilience Act?<\/h2>\n\n\n\n<p>DORA is an EU regulation on digital operational resilience in the financial sector. It was published in December 2022 as Regulation (EU) 2022\/2554 in the Official Journal of the European Union. Following a transition period of approximately two years, it has been mandatory since January 17, 2025. As a regulation, DORA is directly applicable in every Member State; unlike a directive, it does not require national legislation to implement its provisions.<\/p>\n\n\n\n<p>The goal: Financial institutions should be able to withstand IT disruptions and cyberattacks without critical business processes failing. To this end, DORA harmonizes requirements that were previously scattered across national circulars. In Germany, BaFin has repealed its IT supervisory circulars VAIT, KAIT, and ZAIT effective January 17, 2025, because DORA covers their content. According to BaFin, the BAIT guidelines now apply only to supervised entities that are not yet required to implement ICT risk management in accordance with DORA.<\/p>\n\n\n\n<p>The regulation itself constitutes only the first level. Regulatory Technical Standards (RTS) and Implementing Technical Standards (ITS) specify many obligations in detail, such as the classification of incidents, the content of reports, or the contractual requirements for service providers. Anyone implementing DORA must also review these Level 2 legal acts.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Who is affected by DORA?<\/h2>\n\n\n\n<p>Article 2 of the regulation lists approximately 20 categories of financial institutions. These include, among others:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Credit institutions, payment institutions, and electronic money institutions<\/li><li>Investment firms, trading venues, and central counterparties<\/li><li>Asset Management Companies and Managers of Alternative Investment Funds<\/li><li>Insurance and reinsurance companies, as well as large insurance intermediaries<\/li><li>Credit rating agencies, crypto service providers, and crowdfunding service providers<\/li><\/ul>\n\n\n\n<p>In addition, there are third-party ICT service providers\u2014that is, providers of cloud services, data centers, software, or data analytics for the financial sector. They are subject to DORA requirements indirectly through their contracts with their financial clients. If they are classified as critical by European supervisory authorities, an additional direct supervisory framework applies. The regulation provides for exemptions for micro-enterprises, and certain groups, such as small insurance intermediaries, are exempt.<\/p>\n\n\n\n<p>In Germany, the FinmadiG, which was enacted in December 2024, has further expanded the scope. According to BaFin, this means that additional institutions governed by the German Banking Act (Kreditwesengesetz) now fall under DORA, such as guarantee banks and financial services institutions. A transition period applies to them until January 1, 2027; however, the reporting requirements have been in effect since January 17, 2025.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Five Pillars of DORA<\/h2>\n\n\n\n<p>DORA organizes the requirements into five thematic blocks that build on one another:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>ICT Risk Management (Articles 5 through 16):<\/strong> Financial institutions need a documented framework for identification, protection, detection, response, and recovery. The governing body bears ultimate responsibility and must actively oversee implementation. Smaller companies may use a simplified framework.<\/li><li><strong>Handling and Reporting of ICT-Related Incidents (Articles 17 through 23):<\/strong> Incidents must be recorded and classified according to uniform criteria and, if classified as serious, reported to the supervisory authority within a specified time frame.<\/li><li><strong>Tests of Digital Operational Resilience (Articles 24 through 27):<\/strong> A risk-based testing program is mandatory. In addition, companies designated by the regulatory authority must conduct a threat-based penetration test (TLPT) at least once every three years.<\/li><li><strong>Management of Third-Party ICT Risk (Articles 28 through 44):<\/strong> Contracts with ICT service providers must include defined minimum requirements, and all outsourcing relationships must be recorded in an information registry. A separate monitoring framework applies to critical third-party ICT service providers. Details are explained in the article on <a href=\"\/en\/know\/dora-ict-third-party-risk\/\">Third-Party ICT Risk Under DORA<\/a>.<\/li><li><strong>Exchange of Information (Article 45):<\/strong> Financial institutions may voluntarily share threat information and insights regarding cyberattacks within trusted circles.<\/li><\/ul>\n\n\n\n<p>In practice, the fourth pillar ties up the most resources. While many financial firms are familiar with their contracts, they are not aware of the actual security status of their service providers. This is precisely where continuous assessment procedures come into play.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Reporting Requirements: Deadlines for Serious ICT Incidents<\/h2>\n\n\n\n<p>The reporting deadlines are set forth in Delegated Regulation (EU) 2025\/301. It provides for a three-step procedure:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><th>Announcement<\/th><th>Deadline<\/th><th>Contents<\/th><\/tr><\/thead><tbody><tr><td>Initial Report<\/td><td>Within 4 hours of being classified as serious, and no later than 24 hours after becoming aware of the incident<\/td><td>Initial Assessment, Affected Services, Preliminary Evaluation<\/td><\/tr><tr><td>Interim Report<\/td><td>No later than 72 hours after the initial report is submitted<\/td><td>Status Update, Impact, Actions Taken<\/td><\/tr><tr><td>Final Report<\/td><td>No later than one month after the last (updated) interim report<\/td><td>Root Cause Analysis, Actual Impacts, Corrective Actions<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>In Germany, BaFin serves as the central authority for receiving these reports. If a deadline falls on a weekend or a holiday, financial institutions may submit their reports by 12:00 p.m. on the next business day. This exemption does not apply to initial and interim reports from credit institutions, central counterparties, trading venue operators, and NIS2 entities classified as critical or important. In addition, financial firms may voluntarily report significant cyber threats. To meet these deadlines, firms need well-established detection and classification processes; a purely ad hoc response is not sufficient.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Supervision: BaFin and the European Supervisory Framework<\/h2>\n\n\n\n<p>For German financial institutions, BaFin is the competent supervisory authority; it works closely with the Deutsche Bundesbank. BaFin serves as the national reporting center for ICT incidents, receives the information registers on third-party risk, and evaluates the data with regard to risks to the financial sector. It also determines which companies are required to conduct threat-based penetration tests.<\/p>\n\n\n\n<p>A new development is the European level: The three EU supervisory authorities\u2014EBA, EIOPA, and ESMA\u2014classify certain third-party ICT service providers as critical to the financial sector. For each critical provider, a lead supervisory authority assumes direct oversight, with rights to request information, conduct investigations, and carry out inspections\u2014including on-site audits. As a result, major cloud and IT providers are subject to their own financial supervision at the EU level for the first time, even though they are not financial institutions themselves.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Penalties for Violations<\/h2>\n\n\n\n<p>DORA does not prescribe uniform EU-wide fine amounts for financial institutions. Article 50 requires Member States to establish sanctions and corrective measures that are \u201eeffective, proportionate, and dissuasive.\u201c In Germany, the FinmadiG has enshrined the sanction standards in the German Banking Act (KWG), among other laws. Section 56 of the KWG now also covers DORA violations; for legal entities, it provides for fines of up to 20 million euros or 10 percent of total annual revenue for certain violations, whichever amount is higher.<\/p>\n\n\n\n<p>For critical third-party ICT service providers, the regulation itself includes a powerful enforcement tool: Under Article 35 of DORA, the lead supervisory authority may impose daily penalty payments of up to one percent of the average global daily revenue in the preceding fiscal year, on a daily basis for a period of up to six months.<\/p>\n\n\n\n<p>Added to this is the personal dimension: According to Article 5 of DORA, the governing body bears ultimate responsibility for ICT risk management. Executive boards that neglect implementation and oversight thereby also expose themselves to personal liability risks.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">DORA and NIS2: Similarities and Differences<\/h2>\n\n\n\n<p>DORA and the <a href=\"\/en\/know\/nis2-directive-overview\/\">NIS2 Directive<\/a> Both stem from the EU legislative package of December 2022, but take different approaches. Article 4 of the NIS2 Directive governs the relationship: Sector-specific legal acts with at least equivalent effect take precedence. For financial firms, DORA is therefore considered lex specialis, but only with regard to ICT risk management and incident reporting. An overview of the <a href=\"\/en\/know\/nis2-requirements-mandatory-measures\/\">NIS2 Requirements and Mandatory Measures<\/a> shows which other topics the directive covers.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><th>Criterion<\/th><th>DORA<\/th><th>NIS2<\/th><\/tr><\/thead><tbody><tr><td>Legal Nature<\/td><td>EU Regulation, directly applicable<\/td><td>EU Directive; national implementation required<\/td><\/tr><tr><td>Validity<\/td><td>Effective January 17, 2025<\/td><td>Implementation deadline: October 17, 2024; progress varies by member state<\/td><\/tr><tr><td>Recipients<\/td><td>Financial institutions and third-party ICT service providers<\/td><td>18 sectors, including energy, transportation, health care, and digital infrastructure<\/td><\/tr><tr><td>Focus<\/td><td>Digital Operational Resilience of ICT Systems in the Financial Sector<\/td><td>Cybersecurity Risk Management and Reporting Requirements Across Industries<\/td><\/tr><tr><td>Regulation in Germany<\/td><td>BaFin, in cooperation with the Bundesbank<\/td><td>BSI, in accordance with national implementation<\/td><\/tr><tr><td>Sanctions Framework<\/td><td>Regulated at the national level; in Germany, among other things, through the KWG; penalties for non-compliant third-party ICT service providers of up to 1 % of global daily revenue<\/td><td>For essential facilities, at least 10 million euros or 2 % of global revenue; for important facilities, 7 million euros or 1.4 %<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>Important for practice: The priority rule does not generally exempt financial firms from NIS2. It merely supersedes the obligations that DORA regulates in an equivalent or more stringent manner. Groups with companies both within and outside the financial sector must monitor both sets of regulations in parallel.<\/p>\n\n\n\n<div class=\"wp-block-lr-faq-module\"><div class=\"content\"><h3>Frequently asked questions<\/h3><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">Since when has the use of DORA been mandatory?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">The regulation took effect in January 2023 and has been mandatory since January 17, 2025. According to BaFin, institutions that fall under DORA for the first time as a result of the German FinmadiG are subject to a transition period until January 1, 2027; however, their reporting obligations are already in effect.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">Does DORA also apply to IT service providers outside the financial sector?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">Yes, in two stages. All third-party ICT service providers for financial firms meet the requirements indirectly through the minimum contractual terms that their clients must enforce. Providers classified as critical are also subject to direct oversight by European supervisory authorities, including audits and fines.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">What is a TLPT, and who is required to conduct it?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">A threat-led penetration test simulates real-world attacks on a financial institution\u2019s production systems, based on current threat scenarios. Under Article 26 of DORA, it must be conducted at least once every three years. The competent supervisory authority determines which companies are subject to this requirement based on the criteria set forth in the regulation.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">Does DORA replace the NIS2 Directive?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">No. DORA takes precedence over NIS2 for financial institutions only where the obligations overlap\u2014that is, in the areas of ICT risk management and incident reporting. For companies outside the financial sector, NIS2 remains the governing framework.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">How does a security rating support DORA implementation?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">One <a href=\"\/en\/know\/what-is-a-security-rating\/\">Security Rating<\/a> assesses a company\u2019s externally visible attack surface based on measurable criteria. This allows for continuous monitoring of the security status of a company\u2019s own systems and those of its ICT service providers, for example as a component of ongoing monitoring under Pillar Four. The contractual and organizational implementation of DORA does not replace a rating, but it does provide reliable data for risk-based decisions.<\/p><\/div><\/div><\/div><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Conclusion: Address third-party risk as an ongoing task<\/h2>\n\n\n\n<p>DORA makes the management of ICT service providers an ongoing obligation: maintaining information registries, refining contracts, and continuously evaluating service providers. LocateRisk supports you in this process with a vendor risk management solution that combines questionnaires and KPI-based security ratings. The analysis examines the externally visible attack surface of your service providers\u2014without requiring agent installation, in compliance with the GDPR, and hosted in certified German data centers. <a href=\"\/en\/landing\/vendor-risk-management-made-easy\/\">Learn how to set up your vendor risk management for DORA<\/a>.<\/p>","protected":false},"excerpt":{"rendered":"<p>What the Digital Operational Resilience Act Covers: Scope, Five Pillars, BaFin Oversight, Sanctions, and How It Differs from the NIS2 Directive.<\/p>","protected":false},"author":0,"featured_media":0,"template":"","wissen_thema":[819],"class_list":["post-9293","wissen","type-wissen","status-publish","hentry","wissen_thema-regulatorik-compliance"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.2 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>DORA-Verordnung: \u00dcberblick und Pflichten \u2013 LocateRisk<\/title>\n<meta name=\"description\" content=\"DORA im \u00dcberblick: Betroffene, die f\u00fcnf S\u00e4ulen, BaFin-Aufsicht, Sanktionen und Abgrenzung zu NIS2. Kompakt f\u00fcr Finanzunternehmen und IKT-Dienstleister.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"http:\/\/locaterisk.com\/en\/know\/dora-regulation-overview\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"DORA-Verordnung: \u00dcberblick und Pflichten \u2013 LocateRisk\" \/>\n<meta property=\"og:description\" content=\"DORA im \u00dcberblick: Betroffene, die f\u00fcnf S\u00e4ulen, BaFin-Aufsicht, Sanktionen und Abgrenzung zu NIS2. Kompakt f\u00fcr Finanzunternehmen und IKT-Dienstleister.\" \/>\n<meta property=\"og:url\" content=\"http:\/\/locaterisk.com\/en\/know\/dora-regulation-overview\/\" \/>\n<meta property=\"og:site_name\" content=\"LocateRisk\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-06T11:22:08+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_Generisch_03-1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1080\" \/>\n\t<meta property=\"og:image:height\" content=\"1080\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"http:\\\/\\\/locaterisk.com\\\/de\\\/wissen\\\/dora-verordnung-ueberblick\\\/\",\"url\":\"http:\\\/\\\/locaterisk.com\\\/de\\\/wissen\\\/dora-verordnung-ueberblick\\\/\",\"name\":\"DORA-Verordnung: \u00dcberblick und Pflichten \u2013 LocateRisk\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#website\"},\"datePublished\":\"2026-08-06T10:03:35+00:00\",\"dateModified\":\"2026-08-06T11:22:08+00:00\",\"description\":\"DORA im \u00dcberblick: Betroffene, die f\u00fcnf S\u00e4ulen, BaFin-Aufsicht, Sanktionen und Abgrenzung zu NIS2. Kompakt f\u00fcr Finanzunternehmen und IKT-Dienstleister.\",\"breadcrumb\":{\"@id\":\"http:\\\/\\\/locaterisk.com\\\/de\\\/wissen\\\/dora-verordnung-ueberblick\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"http:\\\/\\\/locaterisk.com\\\/de\\\/wissen\\\/dora-verordnung-ueberblick\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"http:\\\/\\\/locaterisk.com\\\/de\\\/wissen\\\/dora-verordnung-ueberblick\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"http:\\\/\\\/locaterisk.com\\\/de\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Wissen\",\"item\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/wissen\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"DORA: Der Digital Operational Resilience Act erkl\u00e4rt\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#website\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/\",\"name\":\"LocateRisk\",\"description\":\"IT-Sicherheit messen und vergleichen\",\"publisher\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#organization\",\"name\":\"LocateRisk\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2020\\\/11\\\/Kettenglieder_V0216-9.jpg\",\"contentUrl\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2020\\\/11\\\/Kettenglieder_V0216-9.jpg\",\"width\":1920,\"height\":1080,\"caption\":\"LocateRisk\"},\"image\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/company\\\/locaterisk\\\/\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"DORA Regulation: Overview and Obligations \u2013 LocateRisk","description":"DORA at a Glance: Affected Parties, the Five Pillars, BaFin Oversight, Sanctions, and Distinction from NIS2. A concise overview for financial institutions and ICT service providers.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"http:\/\/locaterisk.com\/en\/know\/dora-regulation-overview\/","og_locale":"en_US","og_type":"article","og_title":"DORA-Verordnung: \u00dcberblick und Pflichten \u2013 LocateRisk","og_description":"DORA im \u00dcberblick: Betroffene, die f\u00fcnf S\u00e4ulen, BaFin-Aufsicht, Sanktionen und Abgrenzung zu NIS2. Kompakt f\u00fcr Finanzunternehmen und IKT-Dienstleister.","og_url":"http:\/\/locaterisk.com\/en\/know\/dora-regulation-overview\/","og_site_name":"LocateRisk","article_modified_time":"2026-08-06T11:22:08+00:00","og_image":[{"width":1080,"height":1080,"url":"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_Generisch_03-1.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"http:\/\/locaterisk.com\/de\/wissen\/dora-verordnung-ueberblick\/","url":"http:\/\/locaterisk.com\/de\/wissen\/dora-verordnung-ueberblick\/","name":"DORA Regulation: Overview and Obligations \u2013 LocateRisk","isPartOf":{"@id":"https:\/\/locaterisk.com\/de\/#website"},"datePublished":"2026-08-06T10:03:35+00:00","dateModified":"2026-08-06T11:22:08+00:00","description":"DORA at a Glance: Affected Parties, the Five Pillars, BaFin Oversight, Sanctions, and Distinction from NIS2. A concise overview for financial institutions and ICT service providers.","breadcrumb":{"@id":"http:\/\/locaterisk.com\/de\/wissen\/dora-verordnung-ueberblick\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["http:\/\/locaterisk.com\/de\/wissen\/dora-verordnung-ueberblick\/"]}]},{"@type":"BreadcrumbList","@id":"http:\/\/locaterisk.com\/de\/wissen\/dora-verordnung-ueberblick\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"http:\/\/locaterisk.com\/de\/"},{"@type":"ListItem","position":2,"name":"Wissen","item":"https:\/\/locaterisk.com\/de\/wissen\/"},{"@type":"ListItem","position":3,"name":"DORA: Der Digital Operational Resilience Act erkl\u00e4rt"}]},{"@type":"WebSite","@id":"https:\/\/locaterisk.com\/de\/#website","url":"https:\/\/locaterisk.com\/de\/","name":"LocateRisk","description":"Measure and compare IT security","publisher":{"@id":"https:\/\/locaterisk.com\/de\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/locaterisk.com\/de\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/locaterisk.com\/de\/#organization","name":"LocateRisk","url":"https:\/\/locaterisk.com\/de\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/locaterisk.com\/de\/#\/schema\/logo\/image\/","url":"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_V0216-9.jpg","contentUrl":"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_V0216-9.jpg","width":1920,"height":1080,"caption":"LocateRisk"},"image":{"@id":"https:\/\/locaterisk.com\/de\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.linkedin.com\/company\/locaterisk\/"]}]}},"_links":{"self":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen\/9293","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen"}],"about":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/types\/wissen"}],"version-history":[{"count":5,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen\/9293\/revisions"}],"predecessor-version":[{"id":9337,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen\/9293\/revisions\/9337"}],"wp:attachment":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/media?parent=9293"}],"wp:term":[{"taxonomy":"wissen_thema","embeddable":true,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen_thema?post=9293"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}