DORA - Digital Operational Resilience Act
DORA (Digital Operational Resilience Act) is an EU regulation (Regulation (EU) 2022/2554) that entered into force on 17 January 2025 and applies directly in all EU Member States. Its goal is to strengthen the digital operational resilience of financial entities and ensure they can withstand, respond to, and recover from ICT disruptions.
Why does DORA matter? In an increasingly digital financial world, cyberattacks and system outages pose existential threats. DORA harmonizes requirements for digital operational resilience across the EU and creates uniform standards for ICT risk management in the financial sector.
Special relevance for Germany: As of 17 January 2025, BaFin-regulated institutions are obliged to implement DORA. The regulation gradually replaces existing German IT circulars (BAIT/VAIT/ZAIT/KAIT) and, via the Finanzmarktdigitalisierungsgesetz (FinmadiG), will be extended to additional institutions.
The 5 Pillars of the DORA Regulation
Section titled “The 5 Pillars of the DORA Regulation”DORA structures digital operational resilience into five core areas, all tied to robust governance.
1) ICT Risk Management
Section titled “1) ICT Risk Management”Comprehensive, proactive risk management for all ICT systems and processes.
Governance and organization
Section titled “Governance and organization”- Management is responsible for defining and overseeing ICT risk management frameworks.
- Clear roles and responsibilities must be defined and documented.
- Regular reporting to the management body is required.
Protection and prevention
Section titled “Protection and prevention”- Implement policies and procedures to protect critical ICT systems.
- Regularly update security measures.
- Continuous risk analysis and staff awareness.
- Asset management and classification of critical systems.
Detection, response, and recovery
Section titled “Detection, response, and recovery”- Early detection of ICT incidents through monitoring systems.
- Defined response plans and escalation procedures.
- Backup and recovery processes for business continuity.
- Regular testing of recovery procedures.
Simplified requirements for small financial entities
Section titled “Simplified requirements for small financial entities”DORA permits simplified ICT risk management under Article 16 and related technical standards (CDR 2024/1774) for smaller institutions.
Pro tip: Many German institutions already have BAIT/VAIT-aligned risk management. Perform a gap analysis to identify differences between your current framework and DORA requirements.
2) Reporting and Classification of ICT Incidents
Section titled “2) Reporting and Classification of ICT Incidents”Standardized incident management for all financial entities.
Incident management process
Section titled “Incident management process”- Implement processes to log, monitor, and classify ICT incidents.
- Structured documentation of all incidents and threats.
- Clear categorization by severity and impact.
Reporting obligations
Section titled “Reporting obligations”- Initial notification: Within 4 hours after identifying a major incident.
- Interim reports: Regular updates during handling.
- Final report: Full analysis with lessons learned.
- Customer notification: Inform affected customers in case of major incidents.
Report contents
Section titled “Report contents”- Time and duration of the incident.
- Affected systems and services.
- Impact on business operations.
- Immediate actions taken.
- Estimated recovery time.
Pro tip: Ensure incident data is captured in a structured way and that your reporting processes align with supervisory deadlines. Train staff for rapid escalation.
3) Digital Operational Resilience Testing
Section titled “3) Digital Operational Resilience Testing”Regular testing to verify ICT resilience.
Comprehensive testing program
Section titled “Comprehensive testing program”- Annual testing of all critical ICT systems.
- Vulnerability assessments and penetration tests.
- Performance and capacity tests.
- Scenario-based exercises and disaster-recovery tests.
Threat-Led Penetration Testing (TLPT)
Section titled “Threat-Led Penetration Testing (TLPT)”- At least every three years for larger institutions.
- Simulates real attacker tactics and techniques.
- Conducted by qualified external providers.
- Comprehensive documentation and follow-up actions.
Documentation and follow-up
Section titled “Documentation and follow-up”- Detailed documentation of all test results.
- Derive concrete improvement measures.
- Integrate insights into risk management.
- Regularly review implementation progress.
Pro tip: Plan resilience tests on a multi-year basis and align them with internal and external auditors. Systematically integrate lessons learned into your risk management.
4) ICT Third-Party Risk Management
Section titled “4) ICT Third-Party Risk Management”Strict requirements for managing external ICT service providers.
Strategy and governance
Section titled “Strategy and governance”- Develop a strategy and policy for ICT third parties.
- Risk assessment and classification of providers.
- Define exit strategies and contingency plans.
- Regular review of the third-party landscape.
Due diligence and contracting
Section titled “Due diligence and contracting”- Pre-contract assessment before onboarding.
- Evaluate security certifications and reliability.
- Minimum contractual clauses per Article 30, including:
- Access security and data classification
- Audit rights and compliance oversight
- SLAs and performance indicators
- Exit arrangements and data return
- Sub-contractor management
Register of information
Section titled “Register of information”- Maintain an up-to-date register of all ICT third parties.
- Document services and contract terms.
- Classify critical functions.
- Update and validate regularly.
EU-wide oversight of critical third parties
Section titled “EU-wide oversight of critical third parties”- A Lead Overseer may conduct investigations.
- Sanctions possible in case of violations.
- Harmonized supervision of systemic providers.
Pro tip: Compare existing outsourcing contracts to DORA’s minimum requirements. Maintain a central third-party register and define clear exit strategies.
5) Information Sharing and Cooperation
Section titled “5) Information Sharing and Cooperation”Promoting secure exchange of cyber threat information.
Threat intelligence sharing
Section titled “Threat intelligence sharing”- Exchange cyber-threat information between financial institutions.
- Build a shared situational picture.
- Coordination by national and European bodies.
- Observe data protection rules and internal processes.
Applicability and Enforcement in Germany
Section titled “Applicability and Enforcement in Germany”Timeline
Section titled “Timeline”- Effective: 17 January 2025 – directly applicable.
- Withdrawal of national circulars: BaFin withdraws VAIT/ZAIT/KAIT on 16 January 2025.
- BAIT transition: Remains in effect until end of 2026, gradually replaced by DORA.
- Extension: FinmadiG extends scope to additional institutions from 2027.
Affected entities
Section titled “Affected entities”- Banks and credit institutions
- Insurance companies
- Investment firms and asset managers
- Payment institutions and e-money institutions
- From 2027: also non-CRR institutions such as development banks
Sanctions and fines
Section titled “Sanctions and fines”- Financial entities: Up to 2% of worldwide annual turnover.
- Critical third parties: Up to €5 million or 1% of annual turnover.
- Enforcement by European supervisory authorities.
Implementation Aids and Best Practices
Section titled “Implementation Aids and Best Practices”Organizational preparation
Section titled “Organizational preparation”1) Perform a gap analysis
Section titled “1) Perform a gap analysis”- Compare existing IT rules (BAIT/VAIT/KAIT) with DORA requirements.
- Identify necessary adjustments.
- Develop a structured implementation plan.
- Prioritize critical measures.
2) Ensure management commitment
Section titled “2) Ensure management commitment”- Make the management body aware of DORA requirements.
- Clarify management responsibilities.
- Provide sufficient resources.
- Establish regular reporting.
3) Define responsibilities
Section titled “3) Define responsibilities”- Appoint a DORA program lead.
- Define roles for risk, incident, and compliance management.
- Clarify third-party responsibilities.
- Set up coordination mechanisms.
Implement ICT risk management
Section titled “Implement ICT risk management”Establish the framework
Section titled “Establish the framework”- Leverage existing ISO 27001 structures.
- Adapt risk methodology to DORA.
- Integrate protection, detection, response, and recovery.
- Consider simplified provisions for smaller entities.
Optimize documentation
Section titled “Optimize documentation”- Maintain current policies and processes.
- Create and maintain an asset register.
- Document risk analyses and measures.
- Use BaFin documentation expectations as guidance.
Continuous improvement
Section titled “Continuous improvement”- Establish a PDCA cycle.
- Use lessons learned from incidents and tests.
- Regular reviews and process adjustments.
- Integrate feedback from audits and examinations.
Optimize incident management
Section titled “Optimize incident management”Define processes
Section titled “Define processes”- Set clear reporting paths and escalation levels.
- Define responsibilities and authorities.
- Ensure ability to report to supervisors and customers.
- Integrate with existing ISMS processes.
Technical monitoring
Section titled “Technical monitoring”- Implement SIEM systems.
- Deploy monitoring tools.
- Automate incident detection.
- Integrate diverse data sources.
Training and exercises
Section titled “Training and exercises”- Regular staff training.
- Incident-response exercises.
- Training on reporting obligations and procedures.
- Awareness of emerging threats.
Conduct resilience testing
Section titled “Conduct resilience testing”Test planning
Section titled “Test planning”- Build a multi-year test plan.
- Align scope with BaFin.
- Integrate into the audit calendar.
- Coordinate with business units.
Test execution
Section titled “Test execution”- Use realistic scenarios.
- Employ automated tools.
- Document all results.
- Track remediation actions.
Integration with risk management
Section titled “Integration with risk management”- Use test results to update risks.
- Adjust controls based on findings.
- Regularly review test effectiveness.
- Benchmark against industry standards.
Strengthen third-party management
Section titled “Strengthen third-party management”Intensify due diligence
Section titled “Intensify due diligence”- Conduct security and compliance checks.
- Evaluate certifications and standards.
- Review financial stability.
- Assess contingency and business continuity plans.
Optimize contracting
Section titled “Optimize contracting”- Add DORA minimum clauses.
- Define clear service-level agreements.
- Agree audit rights.
- Set exit strategies and handover procedures.
Register and monitoring
Section titled “Register and monitoring”- Build a central third-party register.
- Automate monitoring of contract changes.
- Perform regular risk assessments.
- Conduct supplier audits.
Relation to Other Standards and Frameworks
Section titled “Relation to Other Standards and Frameworks”Integration with ISO 27001
Section titled “Integration with ISO 27001”- DORA complements existing ISMS structures.
- Risk management systems can be extended.
- Incident management processes are compatible.
- Continuous improvement approaches align.
Distinction from BAIT/VAIT
Section titled “Distinction from BAIT/VAIT”- DORA gradually replaces national circulars.
- Higher demands on third-party management.
- More detailed requirements for resilience testing.
- EU-wide harmonization of standards.
Interplay with NIS2
Section titled “Interplay with NIS2”- Overlaps in cybersecurity requirements.
- Complementary approaches for critical infrastructures.
- Coordinated reporting duties and incident response.
- Harmonized EU cybersecurity strategy.
Support with the fuentis Suite
Section titled “Support with the fuentis Suite”The fuentis Suite can comprehensively support DORA compliance:
Risk Management modules
Section titled “Risk Management modules”- Asset management: Record and classify all ICT assets.
- Risk register: Document threats, vulnerabilities, and controls.
- Action planning: Track risk-mitigation measures.
- Reporting: Automated reports for management and supervisors.
Incident Management system
Section titled “Incident Management system”- Incident capture: Structured documentation of ICT incidents.
- Classification: Automated categorization per DORA criteria.
- Regulatory reporting: Integrated interfaces for BaFin reporting.
- Workflow management: Automated escalation and processing.
Third-Party Management (Road map)
Section titled “Third-Party Management (Road map)”- Supplier register: Central management of all ICT third parties.
- Due diligence: Structured evaluation procedures.
- Contract management: Track DORA minimum clauses.
- Risk scoring: Ongoing monitoring of supplier risks.
Compliance Management (Road map)
Section titled “Compliance Management (Road map)”- DORA templates: Prebuilt documents and checklists.
- Gap analysis: Automated assessment of implementation status.
- Audit trails: Full traceability of all activities.
- Regulatory mapping: Link to other compliance requirements.
Testing and Audit modules (Road map)
Section titled “Testing and Audit modules (Road map)”- Test planning: Manage resilience tests and TLPT.
- Result tracking: Structured capture of test outcomes.
- Remediation tracking: Follow-up on improvements.
- Management review: Automated reporting for the management body.
Key Takeaways at a Glance
Section titled “Key Takeaways at a Glance”- DORA has applied directly since 17 January 2025 and is gradually replacing German IT circulars. BaFin-regulated institutions must implement it now.
- The 5 DORA pillars (ICT risk management, incident reporting, resilience testing, third-party management, information sharing) form a comprehensive framework for digital operational resilience.
- Management responsibility is central—the management body is accountable for ICT risks and must establish appropriate governance.
- Third-party risks receive heightened attention with strict due-diligence requirements, minimum contract clauses, and EU-level oversight of critical providers.
- Existing BAIT/VAIT frameworks can be extended—a gap analysis helps identify adjustments and leverage prior compliance investments.