Financial Regulation

DORA Compliance for Fintech: Complete Guide for 2026

LowerPlane Team9 min read

TL;DR

  • • DORA (Digital Operational Resilience Act) became enforceable January 17, 2025 across the EU
  • • Applies to 20+ categories of financial entities and their critical ICT third-party service providers
  • • Five pillars: ICT risk management, incident reporting, digital resilience testing, third-party risk, and information sharing
  • • Penalties: up to 2% of global annual revenue for financial entities; up to 1% for critical third-party providers
  • • SaaS companies serving EU financial institutions as technology providers are directly in scope as "Critical ICT Third-Party Service Providers" (CTPPs)

If you sell technology to banks, insurance companies, investment firms, or any other financial institution operating in the EU, DORA is not an optional consideration — it's a legal obligation that your clients will enforce contractually. As of January 17, 2025, the EU's Digital Operational Resilience Act is fully in force, and financial institutions are already passing contractual obligations to their technology vendors. Here's what you need to know.

What Is DORA?

The Digital Operational Resilience Act (Regulation (EU) 2022/2554) is EU legislation requiring financial sector entities to build, assure, and review their digital operational resilience. In plain terms: regulators want to ensure that financial services can withstand, adapt, and recover from ICT (Information and Communication Technology) disruptions, whether caused by cyberattacks, system failures, or third-party outages.

DORA was born from a recognition that the financial sector increasingly depends on complex digital infrastructure — and that a failure in a single critical cloud provider or software vendor can cascade through the entire financial system. The 2021 outage at a major Irish financial messaging provider (that briefly disrupted interbank payments) was cited extensively in the legislative record.

DORA supersedes and harmonizes the patchwork of national IT risk management requirements that previously applied to financial entities across 27 EU member states. It also creates a new oversight framework for "Critical ICT Third-Party Service Providers" (CTPPs) — the technology vendors that financial institutions rely on most heavily.

Who Does DORA Apply To?

Financial Entities (Direct Obligation)

  • • Credit institutions (banks)
  • • Payment institutions and e-money institutions
  • • Investment firms
  • • Crypto-asset service providers (CASPs)
  • • Insurance and reinsurance undertakings
  • • Insurance intermediaries
  • • Pension funds (IORPS)
  • • Credit rating agencies
  • • Data reporting service providers
  • • Central counterparties and trade repositories
  • • Crowdfunding service providers

ICT Third-Party Service Providers (Indirect Obligation)

SaaS, cloud, and managed service providers that financial entities rely on are subject to DORA through:

  • • Contractual requirements imposed by their financial institution clients
  • • Direct oversight if designated as a "Critical Third-Party Provider" (CTPP) by ESAs (European Supervisory Authorities)
  • • Due diligence requirements financial entities must perform on all ICT vendors

Critical designations: Hyperscalers (AWS, Azure, GCP) and key financial infrastructure providers are expected to be among the first CTPP designations.

The 5 Pillars of DORA Compliance

Pillar 1: ICT Risk Management

Financial entities must have a comprehensive ICT risk management framework — a documented, board-approved set of policies and procedures covering identification, protection, detection, response, and recovery from ICT risks.

Key requirements:

  • • Maintain an updated ICT asset inventory mapping all hardware, software, and third-party services
  • • Classify assets by criticality and data sensitivity
  • • Implement multi-layer protection (network segmentation, IDS/IPS, endpoint controls)
  • • Establish detection mechanisms for anomalous activity (SIEM, logging)
  • • Maintain and test business continuity plans and ICT disaster recovery plans
  • • Establish a digital operational resilience strategy approved by the board

Pillar 2: ICT-Related Incident Reporting

Financial entities must classify, manage, and report major ICT-related incidents to their competent national authority within strict timeframes. The reporting cascade is:

4 hours
Initial notification to competent authority after classifying the incident as "major"
72 hours
Intermediate report with updated assessment of the incident's impact and first remediation steps
1 month
Final report with root cause analysis, impact assessment, and remediation measures implemented

The ESAs have published regulatory technical standards defining what constitutes a "major incident" — thresholds include incidents affecting more than 5% of clients or causing more than €100K in loss.

Pillar 3: Digital Operational Resilience Testing

All in-scope financial entities must conduct baseline digital resilience testing. Significant institutions face a more rigorous requirement: Threat-Led Penetration Testing (TLPT), also known as red team testing, at least every three years.

  • • Annual vulnerability assessments for all in-scope entities
  • • TLPT required for significant financial institutions (covers production systems)
  • • TLPT must involve external testers and follow the TIBER-EU methodology
  • • Results of TLPT must be shared with competent authorities
  • • Critical ICT third-party providers can participate in pooled TLPT exercises

Pillar 4: ICT Third-Party Risk Management

This is the pillar that directly impacts SaaS companies. Financial entities must implement a comprehensive third-party risk management strategy, including:

  • • Maintain a register of all ICT third-party service providers
  • • Classify providers by criticality to business operations
  • • Conduct pre-contractual due diligence on all critical ICT providers
  • • Ensure contracts include specific DORA-mandated clauses (see below)
  • • Monitor the performance and security of critical providers on an ongoing basis
  • • Implement exit strategies and transition plans for critical providers
  • • Report concentration risk (over-reliance on single providers)

Mandatory Contract Clauses for ICT Providers

If you're a SaaS vendor to EU financial institutions, your contracts will need to include: audit rights for the financial entity and regulators, data portability and exit assistance obligations, incident notification requirements, uptime/SLA commitments, subcontracting restrictions, and security standards specifications.

Pillar 5: Information and Intelligence Sharing

Financial entities may (and are encouraged to) share cyber threat information and intelligence among themselves through trusted networks. The EU is establishing formal frameworks for this sharing, aligned with existing ISAC (Information Sharing and Analysis Center) structures. Participation is voluntary but viewed favorably by regulators.

Penalties and Enforcement

DORA penalties are set at EU level but enforced by national competent authorities (NCAs) in each member state:

Entity TypeViolationMaximum Penalty
Financial entityDORA non-compliance2% of total annual worldwide turnover
Critical ICT third-party provider (CTPP)Non-compliance with ESA oversight1% of average daily worldwide turnover (per day, for up to 6 months)
Individuals (senior management)Personally responsible for breachesUp to €1M (member state discretion)

DORA and Your Existing Compliance Frameworks

Good news: if you're already SOC 2 or ISO 27001 compliant, you have a significant head start on DORA. Here's how the frameworks overlap:

DORA ICT Risk Management ↔ ISO 27001 ISMS

Both require documented risk management frameworks, asset inventories, and protection controls. ISO 27001 A.5 (Organizational Controls) maps closely to DORA Chapter II.

DORA Incident Reporting ↔ SOC 2 CC7.3–CC7.5

SOC 2 incident management controls align with DORA's classification and response requirements. The main gap is DORA's mandatory regulatory reporting obligation.

DORA Resilience Testing ↔ SOC 2 / ISO 27001 Penetration Testing

Annual pen testing in SOC 2 and ISO 27001 satisfies much of DORA's baseline testing pillar. TLPT (Threat-Led Penetration Testing) is more rigorous than standard pen testing.

DORA Third-Party Risk ↔ ISO 27001 A.5.19–A.5.22 / SOC 2 CC9.2

Vendor risk management controls overlap significantly. DORA adds formal contractual clause requirements and register obligations beyond what ISO 27001 and SOC 2 require.

The primary gaps when coming from ISO 27001 or SOC 2 to DORA are: the formal incident reporting cascade to regulators, TLPT requirements for significant institutions, and the detailed contractual clause obligations for ICT vendor relationships. These are additive requirements, not replacements of what you've already built.

Ready to Simplify Your Compliance?

LowerPlane automates up to 80% of your compliance work across multiple frameworks.

Book a Demo