Blog · Automation

DORA Regulation: Who is affected and what are the obligations

Aug 11, 20267 min readby Scroll
DORA Regulation: Who is affected and what are the obligations
On this page

The European DORA regulation has applied since January 2025 to financial entities. IT risk management, incidents, resilience testing, provider oversight: what it mandates, and how it changes your contracts.

DORA, or Digital Operational Resilience Act, is the European Regulation 2022/2554 on the digital operational resilience of the financial sector. It has applied directly, without national transposition, since 17 January 2025.

Its starting point is straightforward: the strength of a financial entity is no longer measured solely by its capital, but also by its ability to withstand an outage, a cyberattack, or the failure of an IT provider.

Who is affected?

Around twenty categories of financial entities: credit institutions, investment firms, management companies, insurance companies and intermediaries, payment and electronic money institutions, digital asset service providers, among others.

The regulation also indirectly affects all IT providers serving these entities: software publishers, hosts, managed service providers, agencies. Their contract clauses, the auditability of their services, and their exit strategies now fall under regulatory scrutiny for their clients. ICT providers deemed critical at the European level are also subject to direct supervision.

DORA applies a principle of proportionality: requirements are scaled according to the size and risk profile of the entity. A ten-person broker does not have the same obligations as a systemic bank, but it does have obligations.

The five pillars of DORA

1. Governance and IT risk management

A formalised framework for managing information technology risks, under the responsibility of the governing body: asset mapping, security policies, business continuity, tested recovery plans.

2. Reporting of major incidents

IT incidents are classified according to common criteria. Major incidents must be reported to the competent authority (in France, the ACPR or AMF) following a precise timeline: initial notification, interim report, final report.

3. Digital operational resilience testing

A programme of regular tests, from vulnerability scans to penetration tests. The most significant entities must also conduct threat-led penetration tests (TLPT) every three years.

This is the pillar with the greatest impact on providers. Entities must record all their IT contracts in an information register, assess the criticality of each service, include mandatory contractual clauses, and plan exit strategies for critical or important functions.

5. Information sharing

The regulation encourages the exchange of threat intelligence between financial entities within protected frameworks.

The information register and your contracts

The information register lists all contractual agreements relating to IT services, including their criticality, subcontracting chains, and exit conditions. It is continuously updated and submitted annually to supervisory authorities.

In practice, every new contract with an IT service provider must document: the precise description of the service, the data processing locations, the service levels, the access and audit rights of the entity and its supervisor, the termination conditions, and reversibility.

What DORA changes with a development service provider

For a financial entity commissioning a tool, DORA does not say “do not outsource.” It says: choose providers you can document, audit, and leave. Three elements make the relationship easier:

Code ownership and its documentation, which make the service auditable. Transferable hosting, in France or the European Union, which addresses location requirements. Reversibility planned from the start, which directly supports the exit strategy required by the regulation.

This is how we build our projects, from sovereign applications to KYC and LCB-FT compliance automation projects: a non-critical tooling scope, delivered and documented code, and the ability to exit at any time. For the anti-money laundering system itself, see our article LCB-FT: obligations and framework.

Does DORA apply directly to IT service providers?

No, except for providers designated as critical at the EU level, which are subject to direct supervision. For others, DORA applies through contracts: their financial clients must include specific clauses and be able to document the service in their information register.

What is the difference between DORA and NIS 2?

NIS 2 is the general directive on cybersecurity for essential sectors. DORA is the financial sector’s specific regulation: for financial entities, it takes precedence over NIS 2 for all matters related to digital operational resilience.

What is the information register?

The inventory of all IT service contracts of a financial entity: provider, service, criticality, subcontracting, and exit conditions. It is continuously updated and submitted annually to the supervisor.

Are small financial institutions affected?

Yes, with a proportionality principle. Requirements are scaled according to size and risk, and some micro-entities benefit from exemptions, but the core (risk management, incidents, provider register) applies broadly.