Suspect a breach? Report it immediately — response within 1 hour.Report an incident

DORA (Digital Operational Resilience Act)

European regulation imposing digital operational resilience requirements on financial entities and their critical ICT third-party providers within the European Union.

Last updatedAugust 22, 2026

Who's affected

Financial entities established in the European Union (banks, insurers, investment firms, among others) as well as their third-party ICT providers considered critical. Non-EU providers supplying services to these entities are concerned through contractual pass-down.

What the framework requires

DORA requires ICT risk management, notification of major incidents, digital operational resilience testing, and contractual oversight and monitoring of third-party ICT providers, particularly those designated as critical.

Compliance steps

01

Determine whether the organization is a regulated financial entity or an ICT provider to one

02

Map third-party ICT providers and their criticality level

03

Implement an ICT risk management framework

04

Structure the notification process for major incidents

05

Organize digital operational resilience testing

Common mistakes

  • Treating DORA as a simple extension of GDPR compliance
  • Failing to map all third-party ICT providers, including indirect subcontractors
  • Underestimating requirements passed down to non-EU providers through the contractual chain

Cross-mapping to other frameworks (UCM)

FrameworkCovered
nis2
iso-27001

Downloadable resource

Get the checklist by email.

Frequently asked questions

Who is subject to DORA?

Financial entities established in the European Union and their third-party ICT providers, particularly those designated as critical.

Can a Moroccan company be concerned by DORA?

A Moroccan company is not directly regulated, but may be concerned if it provides ICT services to a European financial entity, which then passes down contractual requirements originating from DORA.

What is the difference between DORA and NIS2?

DORA specifically targets the financial sector and its digital operational resilience, while NIS2 covers a broader sectoral scope. Both texts share similar logic regarding risk management and incident notification.

Does DORA impose direct requirements on non-EU ICT providers?

The European financial entity remains responsible and passes down requirements contractually to its providers. For ICT providers designated as critical, a specific European oversight framework may apply.

Is a specific certification required to comply with DORA?

The regulation does not make a particular certification mandatory for all providers. Alignment with recognized frameworks such as ISO/IEC 27001 helps demonstrate a level of risk management maturity consistent with DORA's expectations.