Skip to main content

Compliance

What is the DORA regulation?

DORA sets EU requirements for digital resilience in the financial sector and reaches IT vendors too. See the 5 pillars, who is covered, and how it differs from NIS2.

In short

DORA (Digital Operational Resilience Act) is the EU regulation on digital operational resilience for the financial sector, Regulation (EU) 2022/2554, which has applied since 17 January 2025.

It sets uniform requirements for how banks, insurance and pension companies, payment institutions and a wide range of other financial entities manage their IT risks, and as a regulation it applies directly across the EU without national implementing law. DORA rests on five pillars: ICT risk management, handling and reporting of ICT incidents, digital operational resilience testing, management of ICT third-party risk, and voluntary sharing of cyber threat information.

The requirements reach beyond the financial entities themselves: IT vendors serving the sector face stricter contractual demands, and critical ICT providers come under a joint European oversight framework. In Denmark, the Danish FSA (Finanstilsynet) supervises compliance. MI Support IT helps both financial entities and their IT vendors turn the requirements into concrete security and documentation.

Back to the glossary

What is the DORA regulation?

DORA stands for Digital Operational Resilience Act: Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector. It has applied since 17 January 2025. The aim is to consolidate and harmonise the IT risk requirements that were previously scattered across sector legislation and guidelines, so the whole financial sector works to the same rules for cybersecurity and operational stability. Because DORA is a regulation rather than a directive, it applies directly in Denmark, and unlike much other regulation it also reaches the vendors behind the financial institutions.

Who is covered by DORA?

DORA applies to financial entities in a broad sense: credit institutions, payment and e-money institutions, investment firms, insurance and pension companies and a range of other actor types in the financial sector. In Denmark, the Danish FSA (Finanstilsynet) supervises compliance.

The regulation also covers ICT third-party service providers, that is, vendors of IT services to financial entities. Providers designated as critical to the sector come under a joint European oversight framework anchored with the European supervisory authorities. If you work as an IT vendor for customers in the financial sector, you will feel DORA through your customers' contractual and documentation requirements, whether or not you are designated as critical yourself.

The five pillars of DORA

  1. ICT risk management: A documented framework for managing IT risk with management accountable, from identifying critical systems to protection, detection and recovery.
  2. Handling and reporting of ICT incidents: Incidents must be classified against common criteria, and major incidents must be reported to the authorities through set processes.
  3. Digital operational resilience testing: Ongoing testing of systems and preparedness, from vulnerability scanning to advanced threat-led penetration testing for selected entities.
  4. Management of ICT third-party risk: Contracts with IT vendors must contain specific provisions, vendor relationships must be registered and monitored, and there must be an exit plan.
  5. Information sharing: Voluntary arrangements where financial entities share knowledge about cyber threats and vulnerabilities with each other.

What does DORA mean for your IT vendor?

If you are a financial entity, DORA moves part of the compliance burden into vendor management: your IT vendors must be able to accept the contractual terms the regulation requires, document their own security, and supply the information your risk management and register of ICT arrangements are built on. A vendor that cannot answer clearly on access management, backup, incident handling and subcontractors becomes a DORA risk in itself.

We know the requirements from practice: MI Support IT delivers security consulting to AP Pension, where the task is precisely to protect sensitive customer data in a heavily regulated financial sector.

DORA vs. NIS2: what is the difference?

The two frameworks share a purpose but not a form. NIS2 is a directive covering 18 critical sectors and implemented through national law, while DORA is a regulation targeted at the financial sector that applies directly. For financial entities, DORA is the specific rule that takes precedence over NIS2's general requirements in its field. In practice: if you are a bank or a pension company, DORA is your primary framework; if you are, say, a manufacturer, NIS2 is what you should be looking at.

How MI Support IT can help

We help financial entities and their IT vendors turn DORA into everyday practice: a gap analysis of your technical security, hardening, monitoring and documentation as part of a coherent IT security setup, and vendor documentation that stands up to your customers' DORA requirements. Contact us if you want to know where you stand before the supervisor or your customers ask.

Shall we talk about your business and your needs?

Real people talking to real people. We get back to you the same day.