
The Digital Operational Resilience Act (DORA) is a European Union regulation designed to strengthen the digital resilience of financial entities. It became applicable on January 17, 2025, ensuring that banks, insurance companies, investment firms, and other in-scope financial organizations can withstand, respond to, and recover from Information and Communication Technology (ICT) disruptions such as cyberattacks or system failures. DORA brings harmonized rules for operational resilience across the EU financial sector, applying to about 20 categories of financial institutions as well as their critical ICT service providers.
Modern financial services are highly dependent on technology and third-party tech providers, which makes them vulnerable to cyber incidents and outages. If not managed properly, ICT risks can disrupt critical services across borders and even threaten broader economic stability. DORA was introduced to address these vulnerabilities – it compels firms to elevate their operational robustness so that digital disruptions do not undermine financial stability. In short, DORA marks a new era of regulatory focus on operational resilience, with comprehensive requirements that financial entities must meet to maintain trust and stability in today’s tech-driven financial system.
DORA’s Five Key Pillars
DORA centers around five key pillars that define its core requirements for digital resilience. Below is an overview of each pillar and what it entails.
- ICT Risk Management
Firms must take full accountability for managing Information and Communication Technology (ICT) risks by establishing a robust governance and control framework for digital operational resilience. This includes continuous identification, assessment, and mitigation of cyber and technology risks, with defined risk tolerance levels. Organizations are expected to prevent and detect ICT incidents proactively and be prepared to respond and recover from disruptions, learning and evolving from past incidents. - ICT-Related Incident Reporting
DORA standardizes how significant ICT incidents are classified and reported across the EU. Financial entities need formal processes to detect incidents, categorize their severity (by impact, duration, services affected), and promptly report major incidents to regulators. The goal is to improve transparency and enable swift responses to systemic issues. Firms will likely need to enhance how they assess incident impacts and root causes to meet DORA’s reporting criteria. Internally, this pillar also means having clear incident response plans and communication workflows to escalate issues to leadership and notify affected stakeholders. - Digital Operational Resilience Testing
Regular testing of ICT systems and security controls is mandated to ensure firms can withstand and bounce back from adverse events. DORA requires comprehensive scenario-based resilience testing (e.g. cyberattack simulations, disaster recovery drills, etc.) and prompt remediation of any vulnerabilities identified. In addition, the largest or most important institutions must undergo advanced threat-led penetration testing (TLPT) by independent experts at least every three years for critical systems and services. These testing programs help validate that defenses and backup plans work effectively under real-world conditions. - ICT Third-Party Risk Management
Financial institutions remain responsible for risks posed by their technology vendors and service providers. DORA therefore insists on rigorous third-party risk management practices. Firms need to conduct due diligence when selecting ICT providers, ensure contracts include required resilience and security clauses, and continuously monitor vendor performance and risk throughout the relationship. The regulation aims to prevent a weak link in a cloud or IT provider from threatening a firm’s (or the broader system’s) stability. This includes strategies for avoiding over-reliance on single critical providers and having exit plans if a vendor cannot meet DORA’s standards. - Information Sharing
DORA encourages financial entities to share cyber threat information and best practices as part of a collective resilience effort. By establishing trusted information-sharing arrangements (e.g. within industry groups or through regulators), firms can raise awareness of emerging ICT risks, limit the spread of cyber attacks, and support coordinated responses across the sector. While this pillar is more about fostering collaboration than prescriptive rules, it underlines that no institution operates in isolation – sharing threat intelligence and lessons learned ultimately strengthens the entire financial ecosystem’s defenses.
Common Challenges
Adapting to DORA’s requirements can be challenging for organizations, as compliance demands new capabilities and cross-functional effort. Some common DORA compliance challenges include:
- Cross-Functional Coordination
DORA sets high expectations for collaboration across IT, security, risk management, compliance, and business units. Firms often struggle to break down silos, for example, aligning cybersecurity teams with risk and continuity planning, yet a unified approach is needed to meet DORA’s broad operational resilience goals. Gaining board-level support and engaging all stakeholders (from executives to technical staff) in resilience efforts is critical but can be difficult in practice. - New Testing Requirements
The Act introduces advanced testing obligations (like threat-led penetration tests and regular scenario exercises) that many institutions have not performed before at required scale or frequency. Conducting these resource-intensive tests every year, and for critical systems, hiring certified independent testers, requires specialized expertise and budget. Firms with legacy IT or limited in-house cybersecurity capabilities may find it challenging to develop realistic test scenarios, fix all identified vulnerabilities, and obtain necessary approvals within DORA’s timelines. - Vendor Dependencies
Ensuring third-party ICT providers (such as cloud services, core banking software vendors, etc.) comply with DORA’s resilience standards presents a complex challenge. Financial entities must inventory all tech suppliers, assess their risks, and likely update a large number of contracts to include DORA-mandated provisions. Managing these contractual changes and oversight duties can be overwhelming, especially given the volume and diversity of vendors many firms use. There’s also a dependency on vendors’ cooperation – if a critical provider falls short on security or refuses contract amendments, the financial institution still bears the compliance risk. - Policy Alignment
DORA’s requirements need to be integrated into existing risk management, cybersecurity, and governance frameworks without creating gaps or redundancies. Many organizations already follow guidelines (like EBA ICT risk guidelines, ISO 27001, or national regulations); mapping DORA’s new rules onto these can be complex. Internal policies for areas like incident response, business continuity, and outsourcing may all require updates to meet DORA’s specific standards. Achieving consistency and clarity across all these policies and procedures, while training staff on the changes – is a non-trivial task under tight compliance deadlines.
Frequently asked questions
Which organisations are affected by DORA?
DORA mainly applies to EU financial entities, but it also affects ICT providers that deliver services to those entities. Organisations should assess both direct scope and indirect requirements through customer or supplier contracts.
What is the purpose of DORA?
DORA aims to strengthen digital operational resilience in the financial sector. Organisations need to be able to prevent, manage and recover from ICT-related disruptions and incidents.
Which areas need to be addressed under DORA?
Typical areas include ICT risk management, incident reporting, digital operational resilience testing, ICT third-party risk and documentation of contracts and dependencies.
What is a DORA register of information?
A register of information contains details of contractual arrangements with ICT third-party providers. It supports oversight of dependencies, critical functions and supervisory reporting.
How should we start a DORA gap assessment?
Start by mapping services, systems, suppliers, critical functions and existing controls. Then compare the current state with DORA requirements and prioritise actions based on risk and supervisory expectations.
Helping you to comply
Kristensson i Skåne AB is an independent consulting partner specializing in information security, IT governance, and regulatory compliance. We help financial organizations navigate DORA readiness and build long-term operational resilience through a structured, practical approach.
- DORA Readiness Assessments & Gap Analysis
We begin by reviewing your current ICT risk and continuity practices against DORA’s requirements. This gap analysis pinpoints where you already comply and what needs improvement. You receive a clear roadmap of remediation steps prioritized by risk, so you can address the most critical gaps first. - Risk Management Framework & Governance
Kristensson assists in developing or enhancing your ICT risk management framework to meet DORA’s standards. We help establish governance structures (e.g. defined roles, oversight committees) and processes for identifying, preventing, detecting, responding to, and recovering from ICT risks in line with regulatory expectations. This may include updating policies for incident response, business continuity, disaster recovery, and integrating them into an enterprise-wide resilience program. - Incident Reporting & Resilience Testing Implementation
Our team guides you in implementing the incident management and reporting capabilities DORA mandates. We help design internal incident escalation workflows and alignment with the new EU reporting templates and timelines for major incidents. Additionally, we assist in establishing a digital operational resilience testing program – from regular vulnerability assessments and tabletop exercises to coordinating threat-led penetration tests. We ensure that testing is not only done to “tick the box,” but that vulnerabilities found are remediated and lessons learned are fed back into your risk management cycle. - Third-Party Risk Management Support
Kristensson provides expertise in strengthening your oversight of ICT third-party providers. We can help build a comprehensive vendor risk register and due diligence process to identify critical suppliers and concentration risks. Our consultants will review and recommend updates to vendor contracts to include DORA-required clauses (for security, continuity, audit rights, etc.), simplifying what can otherwise be a daunting contractual remediation effort. We also advise on continuous monitoring strategies for key vendors and help develop contingency plans (exit strategies or backup providers) if a third-party can’t meet resilience expectations. - Documentation & Training
Achieving DORA compliance involves substantial documentation and awareness across your organization. We assist in drafting or revising necessary documentation – such as ICT risk policies, incident response playbooks, recovery plans, and governance charters – tailored to DORA’s criteria. Just as importantly, we provide training sessions and workshops to ensure your teams (including IT staff, risk managers, and executives) understand their responsibilities under DORA. By raising internal awareness and competence, we help embed a culture of operational resilience that goes beyond mere compliance checklists. - Continuous Improvement & Ongoing Compliance
Kristensson’s support doesn’t stop at initial implementation. We help you establish mechanisms for continuous monitoring and improvement so that digital resilience becomes an ongoing program rather than a one-time project. This includes periodic reviews and audits of your controls, updates for regulatory changes or new threat intelligence, and guidance on maintaining compliance documentation over time. Our goal is to enable your organization to not only meet DORA by the deadline, but to sustain and enhance resilience practices as a strategic advantage going forward.
DORA compliance can be complex, but with the right partner it is an opportunity to strengthen your organization’s operational foundation. Kristensson i Skåne AB is here to support you at every step, from initial readiness assessments to full program implementation and continuous improvement. If your bank, insurance company, or financial firm wants to ensure DORA readiness or boost its digital operational resilience, don’t hesitate to reach out.
Contact us to discuss a tailored DORA compliance roadmap and take the next step toward fortifying your business against the evolving threat landscape. We look forward to helping you turn regulatory requirements into real resilience and long-term success.
Selected official sources: European Commission: DORA implementing and delegated acts; EUR-Lex: Regulation (EU) 2022/2554; European Banking Authority: DORA.
