What is DORA (Digital Operational Resilience Act)?

Get reliable IT support and cyber security for your London business.

Contact us today to find out how we can help.

DORA, or the Digital Operational Resilience Act, is an EU regulation designed to strengthen the ability of financial organisations to withstand, respond to, and recover from technology-related disruption. It establishes common requirements for ICT risk management, incident reporting, digital operational resilience testing, third-party technology risk, and information sharing across much of the European financial sector.

DORA applies directly to a wide range of financial entities operating within its scope in the European Union and also creates significant requirements around the ICT providers those firms depend on. UK organisations are not automatically subject to DORA simply because they provide technology or professional services, but firms supporting EU financial entities may face increased contractual, evidence, resilience, and supplier-assurance requirements as their clients implement DORA obligations.

Why DORA Is Important for Financial Firms

Financial services organisations depend heavily on technology. Banking platforms, trading systems, insurance applications, payment infrastructure, cloud services, customer portals, communications, and third-party software all form part of modern financial operations.

A failure in any of these areas can create significant operational disruption and potentially affect customers, financial markets, or regulated services.

DORA aims to create a more consistent approach to digital operational resilience across the EU financial sector.

Key objectives of DORA include:

  • Strengthening ICT risk management
  • Improving the ability to withstand technology disruption
  • Creating more consistent ICT incident reporting
  • Increasing digital operational resilience testing
  • Strengthening oversight of ICT third-party providers
  • Improving visibility of technology dependencies
  • Reducing concentration and supplier risk
  • Increasing management accountability for ICT resilience
  • Encouraging better documentation and evidence
  • Improving coordination across the financial sector

DORA is important because it moves technology resilience beyond a traditional IT availability issue.

A financial organisation may have strong cyber security but still face significant operational risk if it cannot recover from a cloud outage, supplier failure, system disruption, or major cyber incident.

The regulation therefore looks at technology risk from a broader operational perspective.

It expects organisations to understand how ICT supports critical and important functions, how technology failures could affect those functions, and whether appropriate controls exist to prevent, manage, and recover from disruption.

How DORA Works

DORA creates a common framework for managing digital operational resilience across regulated financial organisations.

Rather than focusing on one specific technology or cyber security control, it establishes requirements covering governance, risk management, incidents, resilience testing, suppliers, contracts, and oversight.

A typical DORA readiness process may include:

  1. Identifying which parts of the organisation fall within the relevant scope.
  2. Mapping critical and important business functions to supporting ICT systems.
  3. Identifying ICT assets, applications, infrastructure, data, and suppliers.
  4. Assessing technology and cyber security risks.
  5. Establishing appropriate ICT risk management controls.
  6. Defining incident detection and escalation processes.
  7. Creating processes for classifying and reporting major ICT incidents.
  8. Testing digital operational resilience.
  9. Assessing third-party ICT dependencies.
  10. Reviewing supplier contracts and resilience requirements.
  11. Maintaining registers of ICT third-party arrangements where required.
  12. Tracking weaknesses and remediation.
  13. Reporting significant ICT risks to senior management.
  14. Continuously reviewing resilience as the environment changes.

The process is intended to be ongoing.

Technology estates change regularly as organisations adopt new cloud services, change suppliers, develop new applications, and introduce different working practices.

DORA therefore places significant importance on governance and continuous management rather than treating resilience as a one-time compliance exercise.

For example, identifying a critical cloud dependency is only the beginning. The organisation should also understand what services rely on it, what would happen if it became unavailable, how the provider is monitored, what contractual protections exist, and whether realistic contingency arrangements have been tested.

Key DORA Requirements

DORA is built around several major areas of digital operational resilience. These requirements are designed to work together rather than as independent compliance exercises.

ICT Risk Management

Financial entities are expected to maintain a structured framework for managing ICT risk.

This includes understanding and protecting:

  • Networks
  • Infrastructure
  • Applications
  • Data
  • Endpoints
  • Cloud services
  • Technology suppliers
  • Communications systems
  • Critical ICT dependencies

The organisation should understand which technology supports important business activities and what risks could disrupt those services.

ICT risk management should also include prevention, detection, response, recovery, learning, and communication.

ICT Incident Management and Reporting

DORA establishes requirements around the identification, management, classification, and reporting of ICT-related incidents.

Organisations need processes for:

  • Detecting incidents
  • Recording them
  • Assessing severity
  • Determining business impact
  • Escalating significant events
  • Managing response and recovery
  • Reporting qualifying incidents where required
  • Learning from incidents afterwards

Effective incident management therefore requires both technical detection and clear organisational responsibilities.

Digital Operational Resilience Testing

Controls and recovery plans should be tested rather than assumed to work.

Testing may include activities such as:

  • Vulnerability assessments
  • Scenario-based exercises
  • Recovery testing
  • Business continuity testing
  • Network security assessments
  • Penetration testing
  • Threat-led penetration testing for certain organisations

The level of testing should reflect the organisation’s size, risk profile, and regulatory requirements.

Testing should also result in improvement. Findings should be recorded, prioritised, remediated, and retested where appropriate.

ICT Third-Party Risk Management

Third-party technology risk is a major area of DORA.

Financial firms increasingly depend on:

  • Cloud providers
  • SaaS platforms
  • Managed service providers
  • Data providers
  • Software vendors
  • Hosting companies
  • Telecommunications providers

DORA requires organisations to understand these dependencies and manage the associated risks.

This includes areas such as supplier assessment, contracts, resilience, concentration risk, monitoring, and exit planning.

Information and Intelligence Sharing

DORA also supports voluntary sharing of cyber threat information and intelligence between financial entities under appropriate conditions.

This can help organisations improve awareness of emerging threats and strengthen the sector’s overall resilience.

Together, these areas create a broader operational resilience framework rather than a narrow cyber security standard.

DORA and Third-Party ICT Risk

Third-party ICT risk is one of the most significant elements of DORA because modern financial services organisations often depend on technology they do not directly control.

A financial firm may rely on multiple external platforms to provide critical services. A failure at one provider can therefore create operational disruption even if the organisation’s own internal systems remain secure.

Common third-party ICT risks include:

  • Dependence on a single cloud provider
  • Multiple suppliers relying on the same underlying infrastructure
  • Limited visibility of subcontractors
  • Weak supplier incident reporting
  • Inadequate recovery arrangements
  • Unclear exit strategies
  • Poor contractual security requirements
  • Limited evidence of supplier control effectiveness
  • Supplier concentration risk
  • Changes to services that are not communicated properly
  • Incomplete understanding of data locations
  • Weak oversight of critical technology dependencies

DORA requires financial organisations to take a more structured approach to these relationships.

This can include maintaining information about ICT contracts, identifying which suppliers support critical or important functions, reviewing contractual protections, monitoring supplier performance, and considering how services could continue or transition if a provider became unavailable.

The regulation also introduces an EU-level oversight framework for certain ICT third-party service providers designated as critical.

For suppliers outside the EU, including UK-based providers, DORA can still be commercially important.

A UK technology provider serving EU financial institutions may be asked to provide stronger evidence around:

  • Cyber security controls
  • Incident management
  • Business continuity
  • Disaster recovery
  • Subcontractors
  • Data handling
  • Security testing
  • Audit rights
  • Resilience arrangements
  • Exit support

This does not necessarily make the supplier directly subject to every DORA requirement, but the client’s regulatory obligations can flow into contracts, due diligence, and ongoing supplier oversight.

Common DORA Readiness Challenges

DORA readiness can be difficult because digital operational resilience extends across technology, risk, compliance, procurement, legal, security, and senior management.

One common challenge is understanding technology dependencies.

An organisation may know its direct suppliers but have limited visibility of the providers or infrastructure those suppliers depend on.

Common DORA readiness challenges include:

  • Incomplete ICT asset inventories
  • Poor mapping of critical and important functions
  • Limited visibility of third-party dependencies
  • Weak supplier risk assessments
  • Inconsistent ICT incident classification
  • Incident response plans that have not been tested
  • Recovery processes that do not reflect current systems
  • Missing evidence of control effectiveness
  • Contracts without appropriate ICT resilience provisions
  • Weak exit planning
  • Limited oversight of subcontractors
  • Incomplete registers of ICT arrangements
  • Testing that does not reflect realistic disruption scenarios
  • Remediation actions that remain unresolved
  • Limited management visibility of ICT risk

Another challenge is treating DORA as purely a cyber security project.

Cyber security is an important part of the regulation, but digital operational resilience also includes availability, recovery, supplier dependencies, continuity, governance, and the ability to maintain important services during disruption.

A company may have strong endpoint protection and vulnerability management while still having weak resilience if a critical cloud platform fails.

Similarly, backups may exist, but if recovery has never been tested against business requirements, the organisation may not know whether services can be restored within an acceptable period.

DORA therefore requires organisations to connect technical controls with operational outcomes.

Best Practices for DORA Readiness

DORA readiness should be approached as an ongoing resilience programme rather than a one-time compliance exercise.

Best practices include:

  • Identifying critical and important business functions
  • Mapping ICT systems to those functions
  • Maintaining accurate technology asset inventories
  • Identifying critical ICT suppliers
  • Reviewing third-party concentration risk
  • Strengthening ICT risk governance
  • Assigning clear risk and control owners
  • Maintaining documented incident management procedures
  • Testing incident escalation and communication
  • Establishing appropriate resilience testing
  • Testing backups and recovery arrangements
  • Running realistic disruption scenarios
  • Reviewing supplier contracts
  • Maintaining appropriate ICT third-party records
  • Tracking control weaknesses and remediation
  • Keeping evidence of resilience activities
  • Reporting significant ICT risks to management
  • Reviewing controls after major technology changes

Organisations should also pay close attention to evidence.

A resilience policy may define how incidents should be managed, but stronger assurance comes from incident exercises, recovery tests, supplier assessments, management reviews, and remediation records showing that the process works in practice.

Third-party oversight should also continue after the initial supplier assessment.

A supplier that was considered low risk several years ago may become critical as the organisation moves additional services onto its platform.

Similarly, a provider’s subcontracting arrangements, certifications, or infrastructure may change over time.

Continuous monitoring helps ensure that the organisation’s understanding of technology risk remains current.

Conclusion: Why DORA Matters

DORA establishes a comprehensive approach to digital operational resilience for the EU financial sector. It requires organisations to look beyond traditional cyber security and consider whether technology, suppliers, people, controls, and recovery processes can continue supporting important financial services during serious disruption.

For financial firms, DORA strengthens expectations around ICT risk management, incident response, resilience testing, third-party oversight, and governance. For technology providers supporting regulated EU clients, it can also lead to greater demand for evidence, contractual assurance, resilience testing, and ongoing security oversight.

Digital operational resilience cannot be demonstrated through a single assessment or policy. Systems, suppliers, threats, and business services continue to change. Organisations that continuously review dependencies, test controls, maintain evidence, and remediate weaknesses are better positioned to manage both regulatory expectations and the real operational risks created by an increasingly interconnected financial technology environment.