1. Home
  2. Resources
  3. DORA guide
Resources · Practical guide · Financial sector

A quick guide to DORA

Digital operational resilience for financial entities and their ICT providers: what it requires, by when, and how to demonstrate it.

Practical guide · Updated 2026-10-04 · Reading time: 15 minutes

Regulation (EU) 2022/2554, known as DORA (Digital Operational Resilience Act), is the European law that harmonises how financial entities and their ICT service providers must manage technology risk. It applies from 17 January 2025 and, being a regulation, is directly applicable without national transposition. This guide summarises the essentials so you can tell whether it affects you and what you need to demonstrate.

Guidance prepared by Jaquers Ciberseguridad from the Regulation and its technical standards. It is not legal advice: specific deadlines and thresholds depend on the type of entity and the technical standards in force, which you should verify with your legal advisers and your supervisor.

1. Who DORA applies to

DORA covers around twenty types of financial entities: credit institutions, payment and electronic money institutions, investment firms, crypto-asset service providers, fund managers, insurance and reinsurance undertakings and intermediaries, occupational pension funds, credit rating agencies, data reporting service providers, crowdfunding platforms and central counterparties, among others.

It also reaches the third-party ICT service providers that work for them (cloud, software, data centres, managed security services, data analytics), indirectly through their customers’ contractual requirements and, for providers designated as critical by the European Supervisory Authorities, through direct oversight. The Regulation applies the principle of proportionality: smaller entities have a simplified framework.

2. The five pillars

ICT risk management

A framework approved and overseen by the management body, which identifies assets and dependencies, protects and prevents, detects anomalies, responds and recovers, and learns from every incident and every test. Management is personally accountable for its implementation.

ICT-related incident management, classification and reporting

A process to detect, manage and log all incidents, classify them using the common European criteria and report major ones to the supervisor within the deadlines in the next section.

Digital operational resilience testing

An annual testing programme (vulnerability assessments, penetration tests, configuration reviews, scenario tests) and, for the entities the supervisor designates, threat-led penetration testing (TLPT) every three years.

Managing ICT third-party risk

A register of information covering all contractual arrangements with ICT providers, minimum contractual clauses, assessment of concentration risk and exit strategies for critical or important functions.

Cyber threat information sharing

Voluntary arrangements between entities to share threat intelligence, indicators of compromise and tactics within trusted communities.

3. Major incident reporting: 4 hours, 72 hours and one month

ICT-related incidents are classified using common criteria (clients affected, duration, geographical spread, data losses, criticality of services and economic impact). Those classified as major must be reported to the competent authority in three stages:

DeadlineWhat must be sent
4 hours from classifying the incident as major and, in any case, within 24 hours of becoming aware of itInitial notification: what happened, services and clients affected, whether other Member States are affected and whether the continuity plan has been activated.
72 hours from the initial notificationIntermediate report: situation update, changes in classification, measures taken and a provisional impact assessment.
One month from the intermediate reportFinal report: root cause, actual impact, mitigation measures and lessons learned.

Besides notifications to the supervisor, affected clients must be informed when the incident affects their financial interests and, if personal data is involved, the GDPR must be complied with in parallel. Significant cyber threats may be reported voluntarily.

4. Resilience testing and TLPT

All entities (except microenterprises) must maintain a proportionate testing programme, documented and performed by independent parties, with a procedure to prioritise and fix what is found. Entities the supervisor identifies as systemically important must carry out, at least every three years, threat-led penetration testing (TLPT) following the TIBER-EU framework: entity-specific threat intelligence, simulation of a real attacker against live production systems supporting critical functions, a red team with proven experience and the involvement of the ICT providers concerned.

In practice this turns one-off pentesting into a continuous obligation: every test must be documented, every finding tracked to its fix and every fix verified.

5. Third-party ICT service providers

DORA requires financial entities to keep a register of information covering all their ICT contractual arrangements, distinguishing those supporting critical or important functions, available to the supervisor on request. Contracts must include, as a minimum, a description of the services and their location, service levels, incident notification obligations, audit and access rights, cooperation with authorities and a realistic exit strategy. If you are a provider to a financial entity, be ready to answer detailed questionnaires, accept these clauses and demonstrate your own security testing.

6. Readiness checklist

We know whether DORA applies to us as an entity or as a provider

And which regime (full or simplified) applies to us.

The management body has approved the ICT risk management framework

With periodic review, an allocated budget and training for its members.

We have incident classification criteria and templates for the three notifications

And we have rehearsed the procedure with a drill.

There is an annual testing programme performed by independent parties

With findings tracked to their fix and evidence retained.

We know whether we are required to perform TLPT

And, if so, the three-year cycle is planned.

The register of ICT provider information is complete and up to date

With critical or important functions identified and the minimum clauses in the contracts.

There are exit strategies for critical providers

Tested, not just written down.

7. How Jaquers helps

Our services fit the resilience testing pillar and incident management: tests performed by an independent team, with reproducible evidence, every finding tracked to its fix and a documented retest, all exportable for the supervisor and for your customers’ questionnaires.

If you want to know where your organisation stands on DORA, request an initial assessment: a 30-minute conversation to understand your systems and what worries you.

Talk to usCall