Book an Appointment
Digital Operational Resilience Act

DORA Compliance for the Financial Sector

The Digital Operational Resilience Act (DORA) requires financial institutions and ICT service providers to establish comprehensive cyber resilience. VamiSec guides you from gap analysis to full DORA compliance.

DORA

Digital Operational Resilience Act — cyber resilience in the financial sector

With the Digital Operational Resilience Act (DORA), the EU establishes a unified legal framework for the digital resilience of banks, insurers, payment service providers, financial service providers and their IT service providers. From January 2025 the regulation becomes binding — and affects both large financial institutions and their supply chains.

DORA requires companies to systematically strengthen their cyber resilience, manage risks transparently and design IT services securely. Violations can lead to significant sanctions and reputational damage.

OUR SERVICES FOR YOUR DORA COMPLIANCE

Determination of your current compliance status and definition of a clear implementation plan.
Build-up of a complete ICT risk management system per DORA requirements.
Processes for detection, classification and reporting of ICT-related incidents to authorities.
Execution of penetration tests, red teaming and TLPT simulations per EU specifications.
Assessment and monitoring of ICT third-party providers across the entire supply chain.
Audience-specific DORA training for management, IT and compliance teams.
Our experience

DORA expertise & track record

Rely on an experienced team that has successfully guided financial institutions through the DORA compliance process.

20+DORA projects
100%Compliance rate
Jan 17, 2025Binding from

Frequently Asked Questions about DORA

Scope, reporting deadlines, TLPT and the register of information — answered concisely.

What is DORA and since when does it apply?

DORA (Digital Operational Resilience Act, Regulation (EU) 2022/2554) is the EU framework for digital operational resilience in the financial sector. It has applied directly in all member states since 17 January 2025 — no national transposition required; in Germany, supervisory responsibilities are flanked by the Financial Market Digitalisation Act.

Who falls under DORA?

DORA covers more than 20 categories of financial entities — including banks, insurers, investment firms, payment and e-money institutions, asset managers and crypto-asset service providers. In addition, ICT third-party providers designated as critical (such as cloud providers) are subject to a dedicated EU oversight framework.

What are the five pillars of DORA?

DORA rests on five pillars: ICT risk management, handling and reporting of ICT-related incidents, digital operational resilience testing (up to TLPT), management of ICT third-party risk including the register of information and the contractual provisions of Art. 30, and voluntary cyber threat information sharing.

Which reporting deadlines apply to major ICT incidents?

Once an incident is classified as major, the initial notification is due no later than four hours after classification and in any case within 24 hours of becoming aware. An intermediate report follows within 72 hours and the final report no later than one month after the intermediate report. In Germany, reports are submitted via BaFin’s MVP platform.

What is TLPT and who must perform it?

TLPT (threat-led penetration testing) under Art. 26/27 DORA is intelligence-driven testing on live production systems, methodologically aligned with TIBER-EU. It is mandatory for financial entities designated by their supervisor — at least every three years, with a threat-intelligence phase and an external red team.

What belongs in the register of information?

The register of information documents all contractual arrangements for ICT services with third-party providers, based on the ESA templates. It is submitted to the supervisor annually; for 2026, BaFin set the submission window from 9 to 30 March via its MVP platform, either as an xBRL file following the ESA taxonomy or via BaFin’s Excel template.

How does DORA relate to NIS2?

For the financial sector DORA is lex specialis: where DORA applies, its requirements take precedence over NIS2 obligations — financial entities therefore align their programme primarily with DORA. Groups with entities outside the financial sector need to delineate both regimes cleanly and leverage synergies, for example in risk management.

How does VamiSec support DORA compliance?

We deliver the DORA building blocks end to end: gap analysis and ICT risk management framework, building and maintaining the register of information, contract reviews under Art. 30, incident reporting processes, and resilience testing up to TLPT — with VamiRedTeam, methodologically TIBER-EU-ready.

DORA readiness check

Determine your current DORA maturity level and receive a prioritized roadmap to full DORA compliance.

Check DORA readiness