• Cybersecurity Glossary
What is DORA (Digital Operational Resilience Act)?
The Digital Operational Resilience Act (DORA), Regulation (EU) 2022/2554, is a European Union law that establishes a uniform framework for Information and communication technology (ICT) risk management across the financial sector. Fully applicable since 17 January 2025, it requires financial entities and their critical ICT third party providers to manage ICT risk, report incidents, test operational resilience, oversee third party risk and share threat information. DORA rests on Five pillars and applies to more than 22,000 financial entities across the EU. This page explains what DORA is, who it affects, its five pillars, timeline and penalties, and how Teldat’s European infrastructure supports digital operational resilience.
DORA defined
The Digital Operational Resilience Act (DORA) is a European Union regulation, formally Regulation (EU) 2022/2554, that requires financial organizations to withstand, respond to and recover from all kinds of ICT disruption, from cyber attacks to system failures and supplier outages. It gives the entire EU financial sector a single, harmonized standard for managing technology risk.
Before DORA, digital resilience requirements were fragmented across different national rules and sector frameworks. DORA replaces that patchwork with one directly applicable law, meaning it takes effect across every member state without needing to be turned into separate national legislation. The result is a consistent baseline for how financial entities and their technology suppliers build and prove operational resilience.
DORA has been fully applicable since 17 January 2025 and rests on five pillars covering ICT risk management, incident reporting, resilience testing, third party risk and information sharing. It reaches more than 22,000 financial entities and, for the first time, brings their critical technology providers under direct European supervision. For a European infrastructure manufacturer like Teldat, DORA reinforces the value of resilient, sovereign network and security solutions.
Why DORA was created?
DORA exists because the financial sector now depends on technology as much as on capital, and that dependence created risks the old rules did not fully address. These are the pressures that drove the regulation.
Who DORA applies to?
DORA has a deliberately broad scope, reaching both financial entities and the technology suppliers that serve them. Article 2 lists around 20 categories of entity, and the regulation also extends to ICT third parties.
Proportionality: DORA scales its requirements to the size and risk profile of each entity. Microenterprises and certain smaller firms follow a simplified ICT risk management framework under Article 16, so the obligations remain proportionate while still achieving the core goal of digital resilience across the whole sector.
The five pillars of DORA
DORA’s requirements are organized into five pillars, each covering a different aspect of digital operational resilience. Together they form a complete lifecycle, from preventing and detecting problems to testing, governing suppliers and sharing intelligence. The table summarizes them.
| Pillar | Articles | What it requires? |
|---|---|---|
| ICT risk management | 5 to 16 | A documented ICT risk framework governed by the management body |
| Incident management and reporting | 17 to 23 | Classify incidents and report major ones within set timelines |
| Resilience testing | 24 to 27 | Regular testing, plus threat led penetration testing for significant entities |
| ICT third party risk | 28 to 30 | Register of information, contractual controls and concentration risk |
| Information sharing | 45 to 49 | Voluntary exchange of cyber threat intelligence between entities |
Where the pressure sits: the fourth pillar, ICT third party risk, carries some of the highest rates of compliance gaps, because it requires financial entities to map, classify and contractually control every technology supplier. This is exactly where the choice of resilient, European infrastructure partners such as Teldat becomes part of the compliance picture.
DORA timeline and key dates
DORA moved from adoption to full application over roughly two years, and is now in an active enforcement phase. The table sets out the milestones that matter.
| Date | Milestone |
|---|---|
| 14 December 2022 | DORA adopted by the European Parliament and Council |
| 27 December 2022 | Published in the Official Journal of the EU |
| January 2023 | Entered into force, opening a two year preparation window |
| 17 January 2025 | Became fully applicable, all obligations in force, no phase in |
| 2026 onward | Active supervision and enforcement, evidence of resilience required |
No deadline left to wait for: because DORA has been fully applicable since January 2025, it is not a future obligation but a present one. Through 2026, regulators have moved from accepting remediation plans to demanding demonstrable resilience, so financial entities and their ICT providers need infrastructure that is resilient and auditable today.
Penalties and enforcement
DORA is backed by significant penalties, and enforcement is active. Because it is directly applicable but leaves specific amounts to member states, the exact figures vary by country, but the framework is consistent. These are the main consequences of non compliance.
DORA vs NIS2
DORA is often mentioned alongside NIS2, the EU’s other major cybersecurity regulation. They are complementary but distinct, and knowing the difference matters for organizations that may fall under both. The table clarifies it.
| Dimension | DORA | NIS2 |
|---|---|---|
| Type | Regulation, directly applicable | Directive, transposed into national law |
| Scope | Financial sector and its ICT providers | Essential and important entities across many sectors |
| Focus | Digital operational resilience of finance | Broad network and information security |
| Relationship | Lex specialis for finance, takes precedence | General baseline where DORA does not apply |
How they fit together: for the financial sector DORA acts as the specialized, more detailed rulebook, while NIS2 sets a broader cybersecurity baseline across the wider economy. Many organizations must consider both, and resilient European infrastructure helps satisfy the technical demands they share, from secure connectivity to monitoring and incident response.
DORA resilience with Teldat
Teldat is not a compliance consultancy; it is a European manufacturer of the network and security infrastructure that financial entities rely on. Its portfolio, spanning SD-WAN and the be.Safe security suite, supports the technical pillars of DORA and the digital sovereignty that underpins them.
Teldat’s role in DORA readiness: DORA requires financial entities to build resilience into their technology and to manage the suppliers behind it. Teldat contributes on both counts, delivering resilient, self healing connectivity and integrated security as a European manufacturer under European jurisdiction. It does not certify compliance, but it provides sovereign infrastructure that helps financial entities meet DORA’s technical demands.
Frequently asked questions – FAQ’s about DORA
❯ What is DORA in simple terms?
DORA, the Digital Operational Resilience Act, is a European Union regulation that makes financial organizations prove they can keep running through technology problems, whether a cyber attack, a system failure or an outage at a supplier. Formally Regulation (EU) 2022/2554, it sets one common set of rules across the whole EU for managing technology risk in the financial sector. Instead of each country having its own patchwork of requirements, DORA gives banks, insurers, investment firms and their technology providers a single standard for building, testing and reporting on their digital resilience. It has been fully applicable since 17 January 2025.
❯ Who does DORA apply to?
DORA applies to more than 22,000 financial entities across the European Union, spanning around 20 categories defined in Article 2. These include banks and credit institutions, investment firms, insurance and reinsurance undertakings, payment and electronic money institutions, crypto asset service providers and crowdfunding platforms. Crucially, DORA also reaches their ICT third party service providers: cloud platforms, data centers, software and network suppliers. Those judged systemically important can be designated critical ICT third party providers and are then supervised directly by European authorities, extending the regulation beyond the financial firms themselves to the technology supply chain that supports them.
❯ What are the five pillars of DORA?
DORA is built on five pillars. First, ICT risk management (Articles 5 to 16), requiring a documented framework governed by the management body. Second, ICT incident management and reporting (Articles 17 to 23), classifying incidents and reporting major ones within set timelines. Third, digital operational resilience testing (Articles 24 to 27), including regular testing and, for significant entities, threat led penetration testing. Fourth, ICT third party risk management (Articles 28 to 30), covering a register of information, contractual controls and concentration risk. Fifth, information sharing (Articles 45 to 49), encouraging the voluntary exchange of cyber threat intelligence between entities.
❯ When did DORA come into force?
DORA was adopted on 14 December 2022 and published in the Official Journal of the EU on 27 December 2022. It entered into force in January 2023, opening a roughly two year implementation window, and became fully applicable on 17 January 2025. There was no phase in period beyond that date: all obligations applied at once, and national competent authorities began supervising compliance immediately. Through 2026 enforcement has intensified, with regulators moving from reviewing remediation plans to demanding evidence of resilience, so the regulation is not a future deadline but a current, actively supervised obligation.
❯ What are the penalties for DORA non compliance?
Financial entities that breach DORA can face administrative fines of up to 2% of total annual worldwide turnover for serious violations, with member states setting specific amounts as the regulation is directly applicable but leaves penalties to national law. Individual senior managers can be held personally liable, with fines up to around 1 million euros in some jurisdictions. Critical ICT third party providers face a separate regime: the lead overseer can impose periodic penalty payments of up to 1% of average daily worldwide turnover for each day of non compliance, for up to six months. Regulators can also require remediation, restrict services or publicly name non compliant firms.
❯ How does Teldat help with DORA?
Teldat supports DORA compliance as a European provider of the network and security infrastructure that financial entities depend on. Its portfolio, spanning SD-WAN and the be.Safe security suite, contributes to the technical pillars of DORA: resilient, self healing connectivity supports ICT risk management and operational resilience, integrated security and monitoring support incident detection and reporting, and Teldat’s status as a European manufacturer operating under European jurisdiction helps address ICT third party and concentration risk. Rather than a compliance consultancy, Teldat is a technology partner whose sovereign European infrastructure helps financial entities build the digital resilience DORA requires.
Build DORA resilience with Teldat
Teldat delivers resilient SD-WAN connectivity and the be.Safe security suite as a European manufacturer under European jurisdiction, helping financial entities meet the technical pillars of DORA with sovereign infrastructure.







