Digital compliancefor fintech and financial firms
DORA (Regulation (EU) 2022/2554) requires digital operational resilience from European financial entities and their critical technology providers. It has been directly applicable since January 17, 2025.
This guide summarizes the regulation in plain language and does not replace legal advice. Always check the official text before making decisions.
What DORA is
It applies to European financial entities of any size and their technology providers, and rests on five pillars — these three are the ones that involve the most practical work.
ICT risk management
A governance framework to identify, protect, detect, respond to and recover from technology incidents.
Digital resilience testing
Periodic testing of your critical systems, with advanced penetration testing (TLPT) for the most significant entities.
ICT third-party risk
A register and oversight of your critical technology providers, with mandatory contractual clauses.
Timeline and deadlines
01 / December 2022
Regulation published
Regulation (EU) 2022/2554 (DORA) is published alongside its accompanying directive.
02 / 2023 – 2024
Adaptation period
Financial entities prepare while the European Supervisory Authorities (ESAs) publish the technical standards.
03 / January 17, 2025
Full application
DORA becomes directly applicable across the EU, with no national transposition needed.
Jan 2025
Full application
5
DORA pillars
72 hours
Major incident notification
1% daily
Max. penalty, critical ICT providers
Sanctions
DORA doesn’t set a single fine for financial entities — each national supervisor (or European, for the ESAs) applies its own regime. It’s different for critical ICT providers under direct EU oversight.
| Entity type | Sanction | Examples |
|---|---|---|
| Financial entities | Sanctions regime set by each national competent authority | Banks, insurers, fund managers, investment firms, payment institutions and licensed fintechs. |
| Critical ICT providers | Up to 1% of average daily global turnover, per day, for up to 6 months | Technology providers designated as critical, under direct oversight of the European Supervisory Authorities (ESAs). |
82.8%
How much ISO 27001 covers of DORA
According to Kardu’s internal control mapping, implementing the 93 controls of ISO 27001:2022 covers 82.8% of DORA requirements (77 of 93 controls) — higher than typical industry estimates (50-60%), because those usually reference ISO 27001:2013, which doesn’t include the digital resilience controls added in the 2022 revision.
What it means for your SME
If you’re a licensed financial entity (bank, insurer, fund manager, payments fintech), DORA applies to you directly, regardless of size, though the principle of proportionality reduces requirements for smaller ones.
If you’re a technology provider serving a financial entity, you’ll likely be asked to meet DORA contractual clauses, even if you’re not directly regulated.
6 minimum requirements
- A register of critical ICT providers
- An ICT risk management policy
- A digital resilience testing plan
- An ICT continuity plan
- A major incident notification procedure
- DORA contractual clauses with your ICT providers
Official sources
This guide is a summary. For the legal detail, consult the regulation’s text directly.
Official DORA text on EUR-Lex →ISO 27001 as the base, DORA included
Kardu organizes your compliance evidence around ISO 27001 and maps it to DORA and any other frameworks that apply to you, so you don’t duplicate work across regulations.