Blog · Automation
DORA Regulation: Who is affected and what are the obligations

On this page
The European DORA regulation has applied since January 2025 to financial entities. IT risk management, incidents, resilience testing, provider oversight: what it mandates, and how it changes your contracts.
DORA, or Digital Operational Resilience Act, is the European Regulation 2022/2554 on the digital operational resilience of the financial sector. It has applied directly, without national transposition, since 17 January 2025.
Its starting point is straightforward: the strength of a financial entity is no longer measured solely by its capital, but also by its ability to withstand an outage, a cyberattack, or the failure of an IT provider.
Who is affected?
Around twenty categories of financial entities: credit institutions, investment firms, management companies, insurance companies and intermediaries, payment and electronic money institutions, digital asset service providers, among others.
The regulation also indirectly affects all IT providers serving these entities: software publishers, hosts, managed service providers, agencies. Their contract clauses, the auditability of their services, and their exit strategies now fall under regulatory scrutiny for their clients. ICT providers deemed critical at the European level are also subject to direct supervision.
DORA applies a principle of proportionality: requirements are scaled according to the size and risk profile of the entity. A ten-person broker does not have the same obligations as a systemic bank, but it does have obligations.
The five pillars of DORA
1. Governance and IT risk management
A formalised framework for managing information technology risks, under the responsibility of the governing body: asset mapping, security policies, business continuity, tested recovery plans.
2. Reporting of major incidents
IT incidents are classified according to common criteria. Major incidents must be reported to the competent authority (in France, the ACPR or AMF) following a precise timeline: initial notification, interim report, final report.
3. Digital operational resilience testing
A programme of regular tests, from vulnerability scans to penetration tests. The most significant entities must also conduct threat-led penetration tests (TLPT) every three years.
4. Management of risks related to third-party providers
This is the pillar with the greatest impact on providers. Entities must record all their IT contracts in an information register, assess the criticality of each service, include mandatory contractual clauses, and plan exit strategies for critical or important functions.
5. Information sharing
The regulation encourages the exchange of threat intelligence between financial entities within protected frameworks.
The information register and your contracts
The information register lists all contractual agreements relating to IT services, including their criticality, subcontracting chains, and exit conditions. It is continuously updated and submitted annually to supervisory authorities.
In practice, every new contract with an IT service provider must document: the precise description of the service, the data processing locations, the service levels, the access and audit rights of the entity and its supervisor, the termination conditions, and reversibility.
What DORA changes with a development service provider
For a financial entity commissioning a tool, DORA does not say “do not outsource.” It says: choose providers you can document, audit, and leave. Three elements make the relationship easier:
Code ownership and its documentation, which make the service auditable. Transferable hosting, in France or the European Union, which addresses location requirements. Reversibility planned from the start, which directly supports the exit strategy required by the regulation.
This is how we build our projects, from sovereign applications to KYC and LCB-FT compliance automation projects: a non-critical tooling scope, delivered and documented code, and the ability to exit at any time. For the anti-money laundering system itself, see our article LCB-FT: obligations and framework.
Does DORA apply directly to IT service providers?
No, except for providers designated as critical at the EU level, which are subject to direct supervision. For others, DORA applies through contracts: their financial clients must include specific clauses and be able to document the service in their information register.
What is the difference between DORA and NIS 2?
NIS 2 is the general directive on cybersecurity for essential sectors. DORA is the financial sector’s specific regulation: for financial entities, it takes precedence over NIS 2 for all matters related to digital operational resilience.
What is the information register?
The inventory of all IT service contracts of a financial entity: provider, service, criticality, subcontracting, and exit conditions. It is continuously updated and submitted annually to the supervisor.
Are small financial institutions affected?
Yes, with a proportionality principle. Requirements are scaled according to size and risk, and some micro-entities benefit from exemptions, but the core (risk management, incidents, provider register) applies broadly.
Related articles
Aug 11, 2026
AML-CFT: obligations, regulated entities and required framework
AML-CFT imposes a comprehensive framework on banks, insurers, brokers, financial advisors, and many other professions: risk classification, customer due diligence, Tracfin reports, and internal controls. An overview of the obligations.
Aug 11, 2026
KYC: definition, obligations, and practical verification
KYC (Know Your Customer) refers to the identity and status verification of clients, mandated by the AML-CFT framework. Who is affected, which documents to collect, how often to update files: a comprehensive overview.
Jun 11, 2026
n8n vs Make vs Zapier: which tool to automate your processes?
Zapier for quick starts, Make for complex visual scenarios, n8n for sovereignty and control. An honest comparison to help you choose.