Skip to Content

DORA: understanding the regulation

The European regulation DORA (Digital Operational Resilience Act) strengthens the digital operational resilience of financial institutions against cyber threats and incidents related to information and communication technologies (TIC).

BCIT Formation logo
BCIT Formation is rated Excellent
4,7 · Trustpilot
🎓 +1000 learners trained

What is DORA?

Published in late 2022 and applicable since January 2025, DORA aims to ensure that the financial sector can withstand, respond to and recover from TIC-related incidents. While cybersecurity focuses on preventing attacks, operational resilience ensures that business activity continues even when an incident occurs.

The regulation follows on from the directive NIS2 but specifically targets the financial sector. It harmonizes, at European level, requirements that were previously scattered: a real step change for the entities concerned and their providers.

The pillars of DORA

TIC risk management

A governance and risk management framework for technology-related risks, under the responsibility of the management body.

Incident management & notification

Classify, handle and notify major TIC incidents according to harmonized procedures and deadlines.

Resilience testing

Regularly test resilience, up to advanced threat-led testing for the most critical entities.

TIC third-party provider risk

Manage dependency on providers, including cloud providers, with enhanced monitoring of critical providers.

Who is concerned?

DORA applies to a wide range of financial entities: credit, payment and electronic money institutions, investment firms, crypto-asset service providers, management companies, insurance and reinsurance undertakings, intermediaries, and many others. The regulation also indirectly concerns their TIC service providers. Beyond finance, its resilience logic is aligned with that of a business continuity and disaster recovery plan.

From compliance to real resilience

DORA is not just about ticking boxes: the challenge is demonstrable resilience. This requires clear TIC risk governance, an incident management process linked to incident response), regular testing, including penetration testing) and control of supplier risk. Many of these building blocks can be shared with an SMSI ISO 27001 and an EBIOS risk analysis.

Achieving DORA compliance, step by step

1

Confirm your scope

Check whether you are subject to the regulation and identify the entities and activities concerned within the group.

2

Assess the gap

Compare the current state with the requirements DORA to build a prioritized compliance plan.

3

Structure TIC risk

Put in place the governance and risk management framework for technology-related risks.

4

Equip incident management

Define classification, handling and notification of major TIC incidents within the required deadlines.

5

Test resilience

Schedule regular testing and, for critical entities, advanced threat-led testing.

6

Control TIC providers

Map dependencies, strengthen contractual clauses and monitor critical providers.

Why get support from BCIT?

An operational interpretation

We translate the pillars DORA into concrete, prioritized workstreams for your organization.

Shared foundations

We build on your existing initiatives ISO 27001 and EBIOS .

Resilience & continuity

From incident response to PCA/PRA, we embed real resilience.

Turn DORA into a controlled project 🚀

Let's take 15 minutes to assess where your organization stands with respect to DORA and define a compliance roadmap.