DORA: understanding the regulation
The European regulation DORA (Digital Operational Resilience Act) strengthens the digital operational resilience of financial institutions against cyber threats and incidents related to information and communication technologies (TIC).
What is DORA?
Published in late 2022 and applicable since January 2025, DORA aims to ensure that the financial sector can withstand, respond to and recover from TIC-related incidents. While cybersecurity focuses on preventing attacks, operational resilience ensures that business activity continues even when an incident occurs.
The regulation follows on from the directive NIS2 but specifically targets the financial sector. It harmonizes, at European level, requirements that were previously scattered: a real step change for the entities concerned and their providers.
The pillars of DORA
TIC risk management
A governance and risk management framework for technology-related risks, under the responsibility of the management body.
Incident management & notification
Classify, handle and notify major TIC incidents according to harmonized procedures and deadlines.
Resilience testing
Regularly test resilience, up to advanced threat-led testing for the most critical entities.
TIC third-party provider risk
Manage dependency on providers, including cloud providers, with enhanced monitoring of critical providers.
Who is concerned?
DORA applies to a wide range of financial entities: credit, payment and electronic money institutions, investment firms, crypto-asset service providers, management companies, insurance and reinsurance undertakings, intermediaries, and many others. The regulation also indirectly concerns their TIC service providers. Beyond finance, its resilience logic is aligned with that of a business continuity and disaster recovery plan.
From compliance to real resilience
DORA is not just about ticking boxes: the challenge is demonstrable resilience. This requires clear TIC risk governance, an incident management process linked to incident response), regular testing, including penetration testing) and control of supplier risk. Many of these building blocks can be shared with an SMSI ISO 27001 and an EBIOS risk analysis.
Achieving DORA compliance, step by step
Confirm your scope
Check whether you are subject to the regulation and identify the entities and activities concerned within the group.
Assess the gap
Compare the current state with the requirements DORA to build a prioritized compliance plan.
Structure TIC risk
Put in place the governance and risk management framework for technology-related risks.
Equip incident management
Define classification, handling and notification of major TIC incidents within the required deadlines.
Test resilience
Schedule regular testing and, for critical entities, advanced threat-led testing.
Control TIC providers
Map dependencies, strengthen contractual clauses and monitor critical providers.
Why get support from BCIT?
An operational interpretation
We translate the pillars DORA into concrete, prioritized workstreams for your organization.
Resilience & continuity
From incident response to PCA/PRA, we embed real resilience.
Turn DORA into a controlled project 🚀
Let's take 15 minutes to assess where your organization stands with respect to DORA and define a compliance roadmap.
DORA: understanding the regulation
The European regulation DORA (Digital Operational Resilience Act) strengthens the digital operational resilience of financial institutions against cyber threats and incidents related to information and communication technologies (TIC).
What is DORA?
Published in late 2022 and applicable since January 2025, DORA aims to ensure that the financial sector can withstand, respond to and recover from TIC-related incidents. While cybersecurity focuses on preventing attacks, operational resilience ensures that business activity continues even when an incident occurs.
The regulation follows on from the directive NIS2 but specifically targets the financial sector. It harmonizes, at European level, requirements that were previously scattered: a real step change for the entities concerned and their providers.
The pillars of DORA
TIC risk management
A governance and risk management framework for technology-related risks, under the responsibility of the management body.
Incident management & notification
Classify, handle and notify major TIC incidents according to harmonized procedures and deadlines.
Resilience testing
Regularly test resilience, up to advanced threat-led testing for the most critical entities.
TIC third-party provider risk
Manage dependency on providers, including cloud providers, with enhanced monitoring of critical providers.
Who is concerned?
DORA applies to a wide range of financial entities: credit, payment and electronic money institutions, investment firms, crypto-asset service providers, management companies, insurance and reinsurance undertakings, intermediaries, and many others. The regulation also indirectly concerns their TIC service providers. Beyond finance, its resilience logic is aligned with that of a business continuity and disaster recovery plan.
From compliance to real resilience
DORA is not just about ticking boxes: the challenge is demonstrable resilience. This requires clear TIC risk governance, an incident management process linked to incident response), regular testing, including penetration testing) and control of supplier risk. Many of these building blocks can be shared with an SMSI ISO 27001 and an EBIOS risk analysis.
Achieving DORA compliance, step by step
Confirm your scope
Check whether you are subject to the regulation and identify the entities and activities concerned within the group.
Assess the gap
Compare the current state with the requirements DORA to build a prioritized compliance plan.
Structure TIC risk
Put in place the governance and risk management framework for technology-related risks.
Equip incident management
Define classification, handling and notification of major TIC incidents within the required deadlines.
Test resilience
Schedule regular testing and, for critical entities, advanced threat-led testing.
Control TIC providers
Map dependencies, strengthen contractual clauses and monitor critical providers.
Why get support from BCIT?
An operational interpretation
We translate the pillars DORA into concrete, prioritized workstreams for your organization.
Resilience & continuity
From incident response to PCA/PRA, we embed real resilience.
Turn DORA into a controlled project 🚀
Let's take 15 minutes to assess where your organization stands with respect to DORA and define a compliance roadmap.