Kardu
Europa · DORA

Digital compliancefor fintech and financial firms

DORA (Regulation (EU) 2022/2554) requires digital operational resilience from European financial entities and their critical technology providers. It has been directly applicable since January 17, 2025.

This guide summarizes the regulation in plain language and does not replace legal advice. Always check the official text before making decisions.

What DORA is

It applies to European financial entities of any size and their technology providers, and rests on five pillars — these three are the ones that involve the most practical work.

ICT risk management

A governance framework to identify, protect, detect, respond to and recover from technology incidents.

Digital resilience testing

Periodic testing of your critical systems, with advanced penetration testing (TLPT) for the most significant entities.

ICT third-party risk

A register and oversight of your critical technology providers, with mandatory contractual clauses.

Timeline and deadlines

01 / December 2022

Regulation published

Regulation (EU) 2022/2554 (DORA) is published alongside its accompanying directive.

02 / 2023 – 2024

Adaptation period

Financial entities prepare while the European Supervisory Authorities (ESAs) publish the technical standards.

03 / January 17, 2025

Full application

DORA becomes directly applicable across the EU, with no national transposition needed.

By the numbers

Jan 2025

Full application

5

DORA pillars

72 hours

Major incident notification

1% daily

Max. penalty, critical ICT providers

Sanctions

DORA doesn’t set a single fine for financial entities — each national supervisor (or European, for the ESAs) applies its own regime. It’s different for critical ICT providers under direct EU oversight.

Entity typeSanctionExamples
Financial entitiesSanctions regime set by each national competent authorityBanks, insurers, fund managers, investment firms, payment institutions and licensed fintechs.
Critical ICT providersUp to 1% of average daily global turnover, per day, for up to 6 monthsTechnology providers designated as critical, under direct oversight of the European Supervisory Authorities (ESAs).

82.8%

How much ISO 27001 covers of DORA

According to Kardu’s internal control mapping, implementing the 93 controls of ISO 27001:2022 covers 82.8% of DORA requirements (77 of 93 controls) — higher than typical industry estimates (50-60%), because those usually reference ISO 27001:2013, which doesn’t include the digital resilience controls added in the 2022 revision.

What it means for your SME

If you’re a licensed financial entity (bank, insurer, fund manager, payments fintech), DORA applies to you directly, regardless of size, though the principle of proportionality reduces requirements for smaller ones.

If you’re a technology provider serving a financial entity, you’ll likely be asked to meet DORA contractual clauses, even if you’re not directly regulated.

6 minimum requirements

  • A register of critical ICT providers
  • An ICT risk management policy
  • A digital resilience testing plan
  • An ICT continuity plan
  • A major incident notification procedure
  • DORA contractual clauses with your ICT providers

Official sources

This guide is a summary. For the legal detail, consult the regulation’s text directly.

Official DORA text on EUR-Lex →
How Kardu helps

ISO 27001 as the base, DORA included

Kardu organizes your compliance evidence around ISO 27001 and maps it to DORA and any other frameworks that apply to you, so you don’t duplicate work across regulations.