European regulation imposing digital operational resilience requirements on financial entities and their critical ICT third-party providers within the European Union.
Last updated — August 22, 2026
Financial entities established in the European Union (banks, insurers, investment firms, among others) as well as their third-party ICT providers considered critical. Non-EU providers supplying services to these entities are concerned through contractual pass-down.
DORA requires ICT risk management, notification of major incidents, digital operational resilience testing, and contractual oversight and monitoring of third-party ICT providers, particularly those designated as critical.
Deadlines
The regulation has been directly applicable across all member states since it took effect, with enforcement modalities specific to each competent national authority and, for designated critical ICT providers, a dedicated European oversight framework.
Sanctions
Applicable sanctions fall under the competent supervisory authorities of each member state and, for designated critical ICT providers, the European oversight framework provided for by the regulation. Their nature and amount are set by the applicable texts.
Determine whether the organization is a regulated financial entity or an ICT provider to one
Map third-party ICT providers and their criticality level
Implement an ICT risk management framework
Structure the notification process for major incidents
Organize digital operational resilience testing
| Framework | Covered |
|---|---|
| nis2 | ✓ |
| iso-27001 | ✓ |
Get the checklist by email.
Financial entities established in the European Union and their third-party ICT providers, particularly those designated as critical.
A Moroccan company is not directly regulated, but may be concerned if it provides ICT services to a European financial entity, which then passes down contractual requirements originating from DORA.
DORA specifically targets the financial sector and its digital operational resilience, while NIS2 covers a broader sectoral scope. Both texts share similar logic regarding risk management and incident notification.
The European financial entity remains responsible and passes down requirements contractually to its providers. For ICT providers designated as critical, a specific European oversight framework may apply.
The regulation does not make a particular certification mandatory for all providers. Alignment with recognized frameworks such as ISO/IEC 27001 helps demonstrate a level of risk management maturity consistent with DORA's expectations.