Regulation

DORA and Digital Operational Resilience

DORA advisory for banks, insurers, investment firms and their critical ICT providers: ICT risk, incidents, testing and third-party risk.

ICT risk managementIncident reportingResilience testingThird-party riskRegister of information

The Digital Operational Resilience Act (DORA) has applied since 17 January 2025 to financial entities in the EU. ICT third-party providers designated as critical are additionally placed under direct oversight by the European supervisory authorities. We help you move from the regulation’s text to working governance: an ICT risk framework, incident classification and reporting, digital operational resilience testing, third-party risk with a register of information and contractual requirements – and a management body that can show it is in control.

We often start with a gap analysis against DORA and then take the role of project manager for the regulatory programme, as in the DORA implementation at an insurance company and the third-party risk work at a financial institution. How DORA relates to NIS2 and FFFS is covered under financial regulations.

In brief

Who
Banks, insurers, investment firms, payment service providers and other financial entities in the EU. ICT third-party providers formally designated as critical (CTPPs) also fall under the European oversight framework
What
The five pillars of DORA: ICT risk management, reporting of ICT incidents, digital operational resilience testing, third-party risk and information sharing
How
Readiness assessment and gap analysis, ICT risk and governance framework, incident reporting and testing, supplier risk register and contracts, documentation, training and ongoing follow-up

DORA’s Five Pillars

DORA is usually described in terms of five pillars. The first four carry binding requirements; the fifth, information sharing, is a voluntary arrangement under Article 45 rather than an obligation. Below is an overview of each and what it entails.

ICT Risk Management

Firms must take full accountability for managing Information and Communication Technology (ICT) risks by establishing a robust governance and control framework for digital operational resilience. This includes continuous identification, assessment, and mitigation of cyber and technology risks, with defined risk tolerance levels. Organizations are expected to prevent and detect ICT incidents proactively and be prepared to respond and recover from disruptions, learning and evolving from past incidents.

ICT-Related Incident Reporting

DORA standardizes how significant ICT incidents are classified and reported across the EU. Financial entities need formal processes to detect incidents, categorize their severity (by impact, duration, services affected), and promptly report major incidents to regulators. The goal is to improve transparency and enable swift responses to systemic issues. Firms will likely need to enhance how they assess incident impacts and root causes to meet DORA’s reporting criteria. Internally, this pillar also means having clear incident response plans and communication workflows to escalate issues to leadership and notify affected stakeholders.

Digital Operational Resilience Testing

Regular testing of ICT systems and security controls is mandated to ensure firms can withstand and bounce back from adverse events. DORA requires comprehensive scenario-based resilience testing (e.g. cyberattack simulations, disaster recovery drills, etc.) and prompt remediation of any vulnerabilities identified. In addition, financial entities identified by their competent authority on the basis of risk profile and criticality must undergo advanced threat-led penetration testing (TLPT) by independent experts at least every three years for critical systems and services. These testing programs help validate that defenses and backup plans work effectively under real-world conditions.

ICT Third-Party Risk Management

Financial institutions remain responsible for risks posed by their technology vendors and service providers. DORA therefore insists on rigorous third-party risk management practices. Firms need to conduct due diligence when selecting ICT providers, ensure contracts include required resilience and security clauses, and continuously monitor vendor performance and risk throughout the relationship. The regulation aims to prevent a weak link in a cloud or IT provider from threatening a firm’s (or the broader system’s) stability. This includes strategies for avoiding over-reliance on single critical providers and having exit plans if a vendor cannot meet DORA’s standards.

Information Sharing

DORA encourages financial entities to share cyber threat information and best practices as part of a collective resilience effort. By establishing trusted information-sharing arrangements (e.g. within industry groups or through regulators), firms can raise awareness of emerging ICT risks, limit the spread of cyber attacks, and support coordinated responses across the sector. While this pillar is more about fostering collaboration than prescriptive rules, it underlines that no institution operates in isolation – sharing threat intelligence and lessons learned ultimately strengthens the entire financial ecosystem’s defenses.

Common Challenges

Adapting to DORA’s requirements can be challenging for organizations, as compliance demands new capabilities and cross-functional effort. Some common DORA compliance challenges include:

Cross-Functional Coordination

DORA sets high expectations for collaboration across IT, security, risk management, compliance, and business units. Firms often struggle to break down silos, for example, aligning cybersecurity teams with risk and continuity planning, yet a unified approach is needed to meet DORA’s broad operational resilience goals. Gaining board-level support and engaging all stakeholders (from executives to technical staff) in resilience efforts is critical but can be difficult in practice.

New Testing Requirements

The Act introduces advanced testing obligations (like threat-led penetration tests and regular scenario exercises) that many institutions have not performed before at required scale or frequency. Conducting these resource-intensive tests every year, and for critical systems, hiring certified independent testers, requires specialized expertise and budget. Firms with legacy IT or limited in-house cybersecurity capabilities may find it challenging to develop realistic test scenarios, fix all identified vulnerabilities, and obtain necessary approvals within DORA’s timelines.

Vendor Dependencies

Ensuring third-party ICT providers (such as cloud services, core banking software vendors, etc.) comply with DORA’s resilience standards presents a complex challenge. Financial entities must inventory all tech suppliers, assess their risks, and likely update a large number of contracts to include DORA-mandated provisions. Managing these contractual changes and oversight duties can be overwhelming, especially given the volume and diversity of vendors many firms use. There’s also a dependency on vendors’ cooperation – if a critical provider falls short on security or refuses contract amendments, the financial institution still bears the compliance risk.

Policy Alignment

DORA’s requirements need to be integrated into existing risk management, cybersecurity, and governance frameworks without creating gaps or redundancies. Many organizations already follow guidelines (like EBA ICT risk guidelines, ISO 27001, or national regulations); mapping DORA’s new rules onto these can be complex. Internal policies for areas like incident response, business continuity, and outsourcing may all require updates to meet DORA’s specific standards. Achieving consistency and clarity across all these policies and procedures, while training staff on the changes – is a non-trivial task under tight compliance deadlines.

Helping you to comply

Kristensson i Skåne AB is an independent consulting partner specializing in information security, IT governance, and regulatory compliance. We help financial organizations navigate DORA readiness and build long-term operational resilience through a structured, practical approach.

DORA Readiness Assessments & Gap Analysis

We begin by reviewing your current ICT risk and continuity practices against DORA’s requirements. This gap analysis pinpoints where you already comply and what needs improvement. You receive a clear roadmap of remediation steps prioritized by risk, so you can address the most critical gaps first.

Risk Management Framework & Governance

Kristensson assists in developing or enhancing your ICT risk management framework to meet DORA’s standards. We help establish governance structures (e.g. defined roles, oversight committees) and processes for identifying, preventing, detecting, responding to, and recovering from ICT risks in line with regulatory expectations. This may include updating policies for incident response, business continuity, disaster recovery, and integrating them into an enterprise-wide resilience program.

Incident Reporting & Resilience Testing Implementation

Our team guides you in implementing the incident management and reporting capabilities DORA mandates. We help design internal incident escalation workflows and alignment with the new EU reporting templates and timelines for major incidents. Additionally, we assist in establishing a digital operational resilience testing program – from regular vulnerability assessments and tabletop exercises to coordinating threat-led penetration tests. We follow testing through to remediation, so that the vulnerabilities found are dealt with and the lessons learned are fed back into your risk management cycle rather than filed.

Third-Party Risk Management Support

Kristensson provides expertise in strengthening your oversight of ICT third-party providers. We can help build a comprehensive vendor risk register and due diligence process to identify critical suppliers and concentration risks. Our consultants will review and recommend updates to vendor contracts to include DORA-required clauses (for security, continuity, audit rights, etc.), simplifying what can otherwise be a daunting contractual remediation effort. We also advise on continuous monitoring strategies for key vendors and help develop contingency plans (exit strategies or backup providers) if a third-party can’t meet resilience expectations.

Documentation & Training

Achieving DORA compliance involves substantial documentation and awareness across your organization. We assist in drafting or revising necessary documentation – such as ICT risk policies, incident response playbooks, recovery plans, and governance charters – tailored to DORA’s criteria. Just as importantly, we provide training sessions and workshops to ensure your teams (including IT staff, risk managers, and executives) understand their responsibilities under DORA. By raising internal awareness and competence, we help embed a culture of operational resilience that goes beyond mere compliance checklists.

Continuous Improvement & Ongoing Compliance

Kristensson’s support doesn’t stop at initial implementation. We help you establish mechanisms for continuous monitoring and improvement so that digital resilience becomes an ongoing program rather than a one-time project. This includes periodic reviews and audits of your controls, updates for regulatory changes or new threat intelligence, and guidance on maintaining compliance documentation over time. Our goal is to enable your organization to not only meet DORA by the deadline, but to sustain and enhance resilience practices as a strategic advantage going forward.

DORA compliance can be complex, but with the right partner it is an opportunity to strengthen your organization’s operational foundation. Kristensson i Skåne AB is here to support you at every step, from initial readiness assessments to full program implementation and continuous improvement. If your bank, insurance company, or financial firm wants to ensure DORA readiness or boost its digital operational resilience, don’t hesitate to reach out.

Want to know what it would look like for you? Contact us and we will tell you more.

Frequently asked questions

Which organisations are affected by DORA?

DORA mainly applies to EU financial entities, but it also affects ICT providers that deliver services to those entities. Organisations should assess both direct scope and indirect requirements through customer or supplier contracts.

What is the purpose of DORA?

DORA aims to strengthen digital operational resilience in the financial sector. Organisations need to be able to prevent, manage and recover from ICT-related disruptions and incidents.

Which areas need to be addressed under DORA?

Typical areas include ICT risk management, incident reporting, digital operational resilience testing, ICT third-party risk and documentation of contracts and dependencies.

What is a DORA register of information?

A register of information contains details of contractual arrangements with ICT third-party providers. It supports oversight of dependencies, critical functions and supervisory reporting.

How should we start a DORA gap assessment?

Start by mapping services, systems, suppliers, critical functions and existing controls. Then compare the current state with DORA requirements and prioritise actions based on risk and supervisory expectations.

Reviewed by Kristensson i Skåne AB. .

Sources: European Commission: DORA implementing and delegated acts · EUR-Lex: Regulation (EU) 2022/2554 · European Banking Authority: DORA

Want to know where you stand against DORA?

Contact us