All articles
ComplianceGovernance

DORA in Depth: How Finance Turned Resilience Into Law

Most digital regulation asks "is your data safe?" DORA asks a harder question of the financial sector: "when your technology fails (not if), can you keep operating?" It's the clearest example in EU law of turning resilience into a legal obligation, and it's a template for how a sector law layers on top of general frameworks.

Ilke Tosunoğlu
Ilke TosunoğluJune 11, 20266 min readUpdated July 20, 2026
The five DORA pillars shown as columns standing on a financial-resilience base.

Part of the pillar series Europe's Digital Dependence, Explained.

This is practical guidance for compliance and risk teams, not legal advice. Current as of July 2026.

Why finance got its own law

Banks, insurers, and market infrastructure now depend on technology, and on a small number of tech vendors, to deliver services across borders. When that ICT fails or is attacked, the disruption is systemic. Before DORA, the rules for managing this were fragmented across directives and national regimes. The Digital Operational Resilience Act (Regulation (EU) 2022/2554) replaced that patchwork with one harmonized regime. In force 16 January 2023; applicable from 17 January 2025 (EIOPA).

It applies to 20 types of financial entities, banks, payment and e-money institutions, investment firms, crypto-asset service providers, central securities depositories, central counterparties, trading venues, (re)insurers, credit-rating agencies, crowdfunding providers and more (Art. 2(1)–(2), EUR-Lex), plus the critical ICT third-party providers they rely on.

The five pillars

Pillar What it requires
1. ICT risk management A documented ICT risk-management framework (Chapter II)
2. Incident management & reporting Classify and report major ICT-related incidents to authorities (Chapter III)
3. Resilience testing Basic and advanced testing, including threat-led penetration testing (TLPT) (Chapter IV)
4. ICT third-party risk Monitor providers; mandatory contractual provisions (Chapter V)
5. Information sharing Exchange cyber-threat intelligence (Chapter VI)

(A quick myth-buster on Pillar 3: DORA requires entities using internal testers to bring in external testers "every three tests," not "every three years." Baseline TLPT runs at least every three years for significant entities.)

The two genuinely new obligations

Most of DORA restates good ICT practice. Two parts are new work for almost everyone.

The Register of Information. Every in-scope entity must maintain a register of all its ICT third-party contractual arrangements. It's not busywork: these registers feed the regulators' assessment of which providers are systemically critical. The first submission to the European Supervisory Authorities was due 30 April 2025; the 2024 voluntary dry run drew 1,039 entities from all 27 Member States, of which 93.5% failed at least one data-quality check (ESAs Dry Run report, 17 December 2024).

Oversight of Critical ICT Third-Party Providers. On 18 November 2025, the ESAs designated the first 19 critical ICT third-party providers. And the list is broader than the hyperscalers everyone expects. It spans cloud (AWS EMEA, Microsoft Ireland, Google Cloud EMEA, Oracle Netherlands), IT services (IBM, Accenture, Capgemini, Kyndryl, NTT DATA, TCS), market data (Bloomberg, LSEG, FIS), telecoms (Deutsche Telekom, Orange, Colt) and colocation (Equinix, InterXion), with SAP rounding it out. Each now has a Lead Overseer (ESAs).

And the board owns it. DORA Article 5 makes the management body bear ultimate, non-delegable responsibility for the ICT risk-management framework: approving the resilience strategy, continuity and recovery plans, and critical third-party arrangements, and keeping its own knowledge current through training.

Which frameworks map to DORA

DORA is also the sharpest case for the overlap dividend: most of it maps to security and continuity work you already run. DORA is deliberately framework-agnostic: it mandates no ISO or NIST standard. But its pillars map cleanly onto frameworks a mature financial entity likely already runs, which is how you make it manageable.

Pillar 1ICT risk mgmt
ISO 27001 + ISO 27005
ISO 22301continuity
Pillar 2Incidents
NIST CSF 2.0
Pillar 3Testing
TIBER-EUthreat-led pen testing
Pillar 4Third-party risk
ISO 20000service mgmt
  • ISO/IEC 27001 + ISO/IEC 27005 anchor Pillar 1 (security controls + risk methodology).
  • ISO 22301 covers the continuity, response, and recovery requirements (Articles 11–12).
  • NIST CSF 2.0 cross-cuts Pillars 1–3, and its Govern function aligns with the Article 5 board duties.
  • ISO/IEC 20000-1 supports Pillar 4 third-party and service management; the ECB's TIBER-EU framework directly supports Pillar 3 testing.

(These are industry alignments that help you demonstrate DORA compliance, not legal requirements.)

Where Soveryne fits

DORA is the sharpest illustration of the series thesis: most of it is evidence you may already have, in the wrong shape. Command enrolls DORA and maps its five pillars to the ISO 27001, 22301, and 27005 controls behind them, so your existing security and continuity evidence is counted toward DORA rather than rebuilt. And its continuous validation keeps that evidence current for the resilience-testing and reporting obligations. The Register of Information is exactly the kind of living, auditable artifact Command is built to maintain rather than assemble in a panic before a supervisory request. DORA sits in the Growth plan alongside every other framework, with continuous validation included.

And for the interpretation questions that DORA generates in volume (is this incident "major"? what must this third-party contract include? does this vendor's designation change our obligations?), Counsel answers from the DORA text and the ESAs' technical standards with citations, so your first line of coverage is the regulation itself.

FAQ

When did DORA start applying? DORA entered into force on 16 January 2023 and became applicable on 17 January 2025.

What are DORA's five pillars? ICT risk management, incident management and reporting, digital operational resilience testing, ICT third-party risk management, and information sharing.

What is the DORA Register of Information? A register every in-scope entity must maintain of all its ICT third-party contractual arrangements. It feeds the regulators' assessment of which providers are critical; the first ESA submission was due 30 April 2025.

Which frameworks help with DORA compliance? ISO/IEC 27001 and 27005 (risk), ISO 22301 (continuity), NIST CSF 2.0 (cross-cutting), ISO/IEC 20000 (third-party/service), and TIBER-EU (testing). DORA mandates none of them, but they map to its pillars.


Most of DORA is evidence you already have, in the wrong shape. Map the five pillars to controls and keep the Register live with Command; resolve incident-classification and third-party questions with cited answers from Counsel.

Sources