What is DORA (Digital Operations Resilience Act)?

When a major software outage hits the financial system, the consequences can ripple across the whole economy. To ensure that banks, investment firms, and their technology suppliers can withstand severe IT disruptions and cyber attacks, the European Union introduced the Digital Operational Resilience Act (DORA)

If you are an investment firm, build fintech software or even supply tech to EU-regulated firms, this guide breaks down what DORA regulations require, who it affects, and how best to comply to avoid hefty fines and potential bans. 

What is DORA?

DORA is an EU regulation designed to ensure the financial sector can withstand, respond to, and quickly recover from all forms of technological disruptions and cyber threats that may arise.

Unlike older regulatory guidance that treated IT issues as internal bugs, DORA treats digital failures as systemic threats to economic stability. It replaces a patchwork of regional laws with one unified, legally binding standard built around the following 5 core pillars:

  1. ICT Risk Management: Firms must build and maintain a complete risk management strategy. It’s no longer enough to fix bugs when they break; boards must actively identify tech vulnerabilities and maintain business continuity plans.
  2. Major Incident Reporting: Companies must classify incidents using standardised criteria and report major incidents to regulators within hours of their occurrence. 
  3. Digital Operational Resilience Testing: Regular system checkups are mandatory. This ranges from basic annual vulnerability scans to advanced Penetration Testing, essentially paying ethical hackers to carry out simulated attacks on your production environment.
  4. Third-Party Risk Management: Financial entities are held responsible for the tech vendors they rely on. Firms must maintain a strict “Register of Information” mapping out every software supplier, cloud host, and subcontractor they use, complete with mandatory contract terms covering exit strategies and audit rights.
  5. Information Sharing: Encourages financial firms to voluntarily form trusted intelligence-sharing networks to pool threat data, attack patterns, and defensive tactics against cybercriminals.
Icons showing the 5 pillars of the Digital Operations Resilience Act (DORA)

Who Does DORA Affect & Does It Apply To Me?

DORA’s reach is radically broad, explicitly covering 20 distinct types of financial entities.

While traditional banks and lenders are squarely in scope, DORA brings a variety of other companies into the crosshairs:

  • Crypto-Asset Service Providers (CASPs): Crypto exchanges, custodial wallet providers, and token issuers operating in Europe are fully subject to the same operational resilience mandates as legacy banks.
  • Crowdfunding Platforms & Alternative Lenders: Peer-to-peer lending portals and digital capital-raising platforms.
  • Credit Rating Agencies & Benchmark Administrators: Firms providing economic index data or credit scores that markets rely on daily.
  • Institutions for Occupational Retirement Provision (IORPs): Workplace pension schemes managing employee nest eggs.
  • Data & Analytics Vendors: Smaller firms providing trade reporting and market data feeds to financial clients.
  • Cloud & Software Vendors (ICT Third Parties): If you build software, host cloud servers (like AWS, Azure, niche fintech apps) or offer cybersecurity services to a firm in DORA’s scope, you are indirectly or directly subject to DORA.

How DORA is Enforced: What Fines Look Like

Global Fines

DORA imposes strict fines for any entity that fails to comply with the regulations. Below is a breakdown of how these fines affect different businesses on a daily remedial basis. 

  • For Financial Entities: Non-compliance can result in corporate fines of up to 2% of annual global turnover (or local administrative maximums up to €20M+). Ongoing violations attract daily periodic penalties of up to 1% of average daily global turnover.
  • For Critical ICT Tech Vendors (CTPPs): Major cloud or software providers directly designated as “Critical” by EU authorities can be fined up to 1% of their average daily worldwide turnover per day, accumulating daily for up to 6 months until they fix security flaws.
  • Personal C-Suite Liability: DORA places legal responsibility directly on the Board of Directors and senior executives. Individuals can face personal fines (reaching €1M to €5M under specific national frameworks) and be banned from holding executive roles.

How the UK Fits In: Regulators, Audits, and Compliance

Since the UK is no longer an EU member state, DORA does not automatically apply to UK law. However, choosing to ignore DORA in the UK is a costly mistake.

How DORA Affects UK Businesses

If you are based in the UK and your business has an EU subsidiary, serves European clients or acts as a tech supplier (SaaS, cloud, payment gateway) to an EU financial firm, it must comply with DORA. European clients will legally demand DORA-compliant contractual terms, security audits, and incident reporting capabilities from their UK suppliers.

How Businesses Can Comply: A Step-by-Step Approach

  1. Conduct a Genuine Scope Assessment: Identify your “Critical or Important Functions”. Map out every person, software tool, data feed, and cloud server necessary to keep those core services running.
  2. Audit Your Third-Party Supply Chain: Create a complete “Register of Information”. Catalogue every external ICT vendor, check their security credentials, identify their subcontractors, and update contracts to include DORA-mandated audit and exit clauses.
  3. Upgrade Executive Governance: Ensure the board of directors actively reviews, allocates funds, and signs off on any cyber security strategies.
  4. Formalise 4-Hour Incident Reporting: Set up continuous automated monitoring so that if a major breach or system outage occurs, your team can detect, classify, and notify regulators within strict initial windows.
  5. Test and Remediate: Perform realistic scenario pen testing and, if required by your size, engage certified red-team ethical hackers to test your defences under pressure.

How can Sencode help?

Sencode provides CREST-accredited penetration testing and advanced red teaming services to businesses of all sizes in the financial sector. We have a wealth of experience dealing with SaaS products, internal and external infrastructure and web and mobile applications. If you need to validate your critical applications or meet regulatory audit requirements, our certified pen testers deliver practical, clear, and actionable security reports, along with a complimentary re-test to validate your fixes. 

If you’re exploring testing options, feel free to schedule a scoping call with the Sencode team today or use our scoping quote tool for a quick quote sent directly to your email. You will get a quote within 24 hours and in as little as a few minutes, straight to your inbox.