Logo Teldat

• Cybersecurity Glossary

What is DORA (Digital Operational Resilience Act)?

The Digital Operational Resilience Act (DORA), Regulation (EU) 2022/2554, is a European Union law that establishes a uniform framework for Information and communication technology (ICT) risk management across the financial sector. Fully applicable since 17 January 2025, it requires financial entities and their critical ICT third party providers to manage ICT risk, report incidents, test operational resilience, oversee third party risk and share threat information. DORA rests on Five pillars and applies to more than 22,000 financial entities across the EU. This page explains what DORA is, who it affects, its five pillars, timeline and penalties, and how Teldat’s European infrastructure supports digital operational resilience.

DORA defined

The Digital Operational Resilience Act (DORA) is a European Union regulation, formally Regulation (EU) 2022/2554, that requires financial organizations to withstand, respond to and recover from all kinds of ICT disruption, from cyber attacks to system failures and supplier outages. It gives the entire EU financial sector a single, harmonized standard for managing technology risk.

Before DORA, digital resilience requirements were fragmented across different national rules and sector frameworks. DORA replaces that patchwork with one directly applicable law, meaning it takes effect across every member state without needing to be turned into separate national legislation. The result is a consistent baseline for how financial entities and their technology suppliers build and prove operational resilience.

DORA has been fully applicable since 17 January 2025 and rests on five pillars covering ICT risk management, incident reporting, resilience testing, third party risk and information sharing. It reaches more than 22,000 financial entities and, for the first time, brings their critical technology providers under direct European supervision. For a European infrastructure manufacturer like Teldat, DORA reinforces the value of resilient, sovereign network and security solutions.

Why DORA was created?

DORA exists because the financial sector now depends on technology as much as on capital, and that dependence created risks the old rules did not fully address. These are the pressures that drove the regulation.

1
Growing dependence on technology
Modern finance runs on ICT, from core banking to trading and payments. As that reliance deepened, a technology failure or cyber attack became capable of disrupting not just one firm but the stability of the whole financial system, making digital resilience a supervisory priority rather than an internal IT concern.
2
A fragmented regulatory landscape
Before DORA, operational resilience rules differed from country to country and sector to sector across the EU. This inconsistency left gaps and made compliance harder for firms operating in several member states. DORA harmonizes the requirements into one standard that applies uniformly everywhere.
3
Concentration in ICT third parties
Financial entities increasingly rely on a small number of large technology suppliers, especially for cloud services. This concentration means a problem at one provider could ripple across many institutions at once, so DORA extends supervision to critical ICT third parties themselves.
4
Rising cyber threats
The frequency and sophistication of cyber attacks against financial institutions kept climbing. DORA responds by requiring firms not only to defend against incidents but to test their resilience, report significant events quickly and demonstrate they can recover, shifting the emphasis from prevention alone to proven resilience.

Who DORA applies to?

DORA has a deliberately broad scope, reaching both financial entities and the technology suppliers that serve them. Article 2 lists around 20 categories of entity, and the regulation also extends to ICT third parties.

1
Banks and credit institutions
Traditional deposit taking banks and credit institutions sit at the center of DORA’s scope. As the backbone of the financial system, they must implement the full framework of ICT risk management, testing and reporting that the regulation defines.
2
Investment and insurance firms
Investment firms, insurance and reinsurance undertakings and related intermediaries are all in scope. These entities hold and move large volumes of sensitive financial data, so their operational resilience is central to protecting markets and policyholders alike.
3
Payment, E money and crypto providers
Payment institutions, electronic money institutions, crypto asset service providers and crowdfunding platforms are explicitly covered. Their inclusion reflects how much of modern finance now flows through newer digital channels that need the same resilience guarantees as established institutions.
4
Critical ICT third party providers
Most significantly, DORA reaches technology suppliers. Cloud platforms, data centers and other ICT providers judged systemically important can be designated critical and supervised directly by European authorities. This is the first time such providers face EU oversight in their own right, and it places a premium on sovereign, European infrastructure.

Proportionality: DORA scales its requirements to the size and risk profile of each entity. Microenterprises and certain smaller firms follow a simplified ICT risk management framework under Article 16, so the obligations remain proportionate while still achieving the core goal of digital resilience across the whole sector.

The five pillars of DORA

DORA’s requirements are organized into five pillars, each covering a different aspect of digital operational resilience. Together they form a complete lifecycle, from preventing and detecting problems to testing, governing suppliers and sharing intelligence. The table summarizes them.

Pillar Articles What it requires?
ICT risk management 5 to 16 A documented ICT risk framework governed by the management body
Incident management and reporting 17 to 23 Classify incidents and report major ones within set timelines
Resilience testing 24 to 27 Regular testing, plus threat led penetration testing for significant entities
ICT third party risk 28 to 30 Register of information, contractual controls and concentration risk
Information sharing 45 to 49 Voluntary exchange of cyber threat intelligence between entities

Where the pressure sits: the fourth pillar, ICT third party risk, carries some of the highest rates of compliance gaps, because it requires financial entities to map, classify and contractually control every technology supplier. This is exactly where the choice of resilient, European infrastructure partners such as Teldat becomes part of the compliance picture.

DORA timeline and key dates

DORA moved from adoption to full application over roughly two years, and is now in an active enforcement phase. The table sets out the milestones that matter.

Date Milestone
14 December 2022 DORA adopted by the European Parliament and Council
27 December 2022 Published in the Official Journal of the EU
January 2023 Entered into force, opening a two year preparation window
17 January 2025 Became fully applicable, all obligations in force, no phase in
2026 onward Active supervision and enforcement, evidence of resilience required

No deadline left to wait for: because DORA has been fully applicable since January 2025, it is not a future obligation but a present one. Through 2026, regulators have moved from accepting remediation plans to demanding demonstrable resilience, so financial entities and their ICT providers need infrastructure that is resilient and auditable today.

Penalties and enforcement

DORA is backed by significant penalties, and enforcement is active. Because it is directly applicable but leaves specific amounts to member states, the exact figures vary by country, but the framework is consistent. These are the main consequences of non compliance.

1
Fines for financial entities
Financial entities that breach DORA can face administrative fines of up to 2% of total annual worldwide turnover for serious violations. Member states set the precise amounts, but the ceiling is high enough to make non compliance a board level financial risk, not a minor operational matter.
2
Penalties for critical ICT providers
Critical ICT third party providers face a separate regime. The lead overseer can impose periodic penalty payments of up to 1% of average daily worldwide turnover for each day of non compliance, for up to six months, a mechanism designed to compel even the largest technology suppliers to remediate.
3
Personal liability for management
DORA holds the management body personally responsible for ICT risk governance. Individual senior managers can face personal fines, up to around one million euros in some jurisdictions, and in certain cases temporary bans from management roles, making resilience a direct concern for executives.
4
Non financial measures
Beyond fines, regulators can require specific remediation, restrict or suspend services, and publicly name non compliant firms. In financial markets this public disclosure often prompts faster action than a monetary penalty, since reputational damage can outweigh the fine itself.

DORA vs NIS2

DORA is often mentioned alongside NIS2, the EU’s other major cybersecurity regulation. They are complementary but distinct, and knowing the difference matters for organizations that may fall under both. The table clarifies it.

Dimension DORA NIS2
Type Regulation, directly applicable Directive, transposed into national law
Scope Financial sector and its ICT providers Essential and important entities across many sectors
Focus Digital operational resilience of finance Broad network and information security
Relationship Lex specialis for finance, takes precedence General baseline where DORA does not apply

How they fit together: for the financial sector DORA acts as the specialized, more detailed rulebook, while NIS2 sets a broader cybersecurity baseline across the wider economy. Many organizations must consider both, and resilient European infrastructure helps satisfy the technical demands they share, from secure connectivity to monitoring and incident response.

DORA resilience with Teldat

Teldat is not a compliance consultancy; it is a European manufacturer of the network and security infrastructure that financial entities rely on. Its portfolio, spanning SD-WAN and the be.Safe security suite, supports the technical pillars of DORA and the digital sovereignty that underpins them.

1
Resilient connectivity for operational resilience
Teldat SD-WAN provides self healing, redundant connectivity that keeps branches and services running through link failures and disruptions. This directly supports the ICT risk management and operational resilience pillars, where the ability to withstand and recover from disruption is exactly what DORA demands.
2
Integrated security and monitoring
The be.Safe security suite brings network security, threat detection and monitoring that support the incident management and reporting pillar. Visibility over the network helps entities detect, classify and report significant ICT incidents within the timelines DORA sets, turning monitoring into evidence of resilience.
3
European manufacturer and ICT third party risk
DORA’s third party pillar makes the choice of suppliers a compliance matter. As a European manufacturer operating under European jurisdiction, Teldat offers an infrastructure partner aligned with EU oversight, helping financial entities manage ICT third party and concentration risk with a sovereign alternative.
4
A complete portfolio under one roof
By combining SD-WAN and be.Safe in one European portfolio, Teldat lets financial entities source resilient connectivity and security from a single sovereign partner. This reduces the number of suppliers to govern under the third party pillar while keeping the whole stack within European jurisdiction.

Teldat’s role in DORA readiness: DORA requires financial entities to build resilience into their technology and to manage the suppliers behind it. Teldat contributes on both counts, delivering resilient, self healing connectivity and integrated security as a European manufacturer under European jurisdiction. It does not certify compliance, but it provides sovereign infrastructure that helps financial entities meet DORA’s technical demands.

Frequently asked questions – FAQ’s about DORA

❯ What is DORA in simple terms?

DORA, the Digital Operational Resilience Act, is a European Union regulation that makes financial organizations prove they can keep running through technology problems, whether a cyber attack, a system failure or an outage at a supplier. Formally Regulation (EU) 2022/2554, it sets one common set of rules across the whole EU for managing technology risk in the financial sector. Instead of each country having its own patchwork of requirements, DORA gives banks, insurers, investment firms and their technology providers a single standard for building, testing and reporting on their digital resilience. It has been fully applicable since 17 January 2025.

❯ Who does DORA apply to?

DORA applies to more than 22,000 financial entities across the European Union, spanning around 20 categories defined in Article 2. These include banks and credit institutions, investment firms, insurance and reinsurance undertakings, payment and electronic money institutions, crypto asset service providers and crowdfunding platforms. Crucially, DORA also reaches their ICT third party service providers: cloud platforms, data centers, software and network suppliers. Those judged systemically important can be designated critical ICT third party providers and are then supervised directly by European authorities, extending the regulation beyond the financial firms themselves to the technology supply chain that supports them.

❯ What are the five pillars of DORA?

DORA is built on five pillars. First, ICT risk management (Articles 5 to 16), requiring a documented framework governed by the management body. Second, ICT incident management and reporting (Articles 17 to 23), classifying incidents and reporting major ones within set timelines. Third, digital operational resilience testing (Articles 24 to 27), including regular testing and, for significant entities, threat led penetration testing. Fourth, ICT third party risk management (Articles 28 to 30), covering a register of information, contractual controls and concentration risk. Fifth, information sharing (Articles 45 to 49), encouraging the voluntary exchange of cyber threat intelligence between entities.

❯ When did DORA come into force?

DORA was adopted on 14 December 2022 and published in the Official Journal of the EU on 27 December 2022. It entered into force in January 2023, opening a roughly two year implementation window, and became fully applicable on 17 January 2025. There was no phase in period beyond that date: all obligations applied at once, and national competent authorities began supervising compliance immediately. Through 2026 enforcement has intensified, with regulators moving from reviewing remediation plans to demanding evidence of resilience, so the regulation is not a future deadline but a current, actively supervised obligation.

❯ What are the penalties for DORA non compliance?

Financial entities that breach DORA can face administrative fines of up to 2% of total annual worldwide turnover for serious violations, with member states setting specific amounts as the regulation is directly applicable but leaves penalties to national law. Individual senior managers can be held personally liable, with fines up to around 1 million euros in some jurisdictions. Critical ICT third party providers face a separate regime: the lead overseer can impose periodic penalty payments of up to 1% of average daily worldwide turnover for each day of non compliance, for up to six months. Regulators can also require remediation, restrict services or publicly name non compliant firms.

❯ How does Teldat help with DORA?

Teldat supports DORA compliance as a European provider of the network and security infrastructure that financial entities depend on. Its portfolio, spanning SD-WAN and the be.Safe security suite, contributes to the technical pillars of DORA: resilient, self healing connectivity supports ICT risk management and operational resilience, integrated security and monitoring support incident detection and reporting, and Teldat’s status as a European manufacturer operating under European jurisdiction helps address ICT third party and concentration risk. Rather than a compliance consultancy, Teldat is a technology partner whose sovereign European infrastructure helps financial entities build the digital resilience DORA requires.

Build DORA resilience with Teldat

Teldat delivers resilient SD-WAN connectivity and the be.Safe security suite as a European manufacturer under European jurisdiction, helping financial entities meet the technical pillars of DORA with sovereign infrastructure.