EU Digital Operational Resilience Act
EU regulation ensuring financial entities can withstand, respond to, and recover from ICT-related disruptions. Effective January 2025 for all EU financial institutions.
What DORA draws on
This framework pulls on all three pillars — which is why running them as three separate tools means reconciling three sets of evidence at audit time.
Compliance
Security
What your auditor cites,
and what produces the evidence
The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.
ICT Risk Management
Financial entities MUST have ICT risk management framework including monitoring of ICT systems.
An assessment is only defensible if the findings in it are observed rather than asserted. Discovery supplies what regulated data exists and where, scanning supplies the configuration and exposure posture, and the audit trail supplies who has actually been reaching it — so the assessment describes the estate as measured. Our advisory engagements then map each finding to the specific mandate it touches and sequence the remediation.
ICT Incident Classification
MUST classify ICT-related incidents and report major incidents to competent authorities.
Findings route by severity to Slack, Teams, email, PagerDuty, or your SIEM, and escalate automatically when nobody acknowledges them and again when nobody resolves them. Every alert arrives with the query, the identity, and the data classification already attached, so the response starts with context rather than with an investigation. The acknowledge-to-resolve history is retained, which is what evidences that the procedure was followed. Your ticketing system stays where it is — what this produces is a finding worth opening a ticket for.
Incident Reporting
Major ICT incidents MUST be reported within specified timeframes with root cause analysis.
Notification clocks start when you become aware, so detection latency is the whole exposure. Behavioural baselines score each deviation as it happens and flag it in under a second, rather than surfacing it in a weekly review. Severity is decided at the collector and routed immediately, so the window between the access and someone knowing about it is measured in seconds — and the audit trail behind it already holds what was reached, by whom, and when.
Third-Party Risk
MUST maintain register of third-party ICT service providers and monitor their access.
A supplier-risk requirement has two halves and they are not equally hard. The register of providers, the contractual clauses, and the assessment of each supplier as an organisation are yours to maintain — nothing in the platform produces them. The half that is usually undocumented is what those suppliers, their tooling, and their service accounts are actually reaching inside your estate. Scanning surfaces the shared and vendor-default accounts, the credentials with no owner, and the standing privileges nobody has exercised; the query trail then shows which of those grants were used, against which classified tables, from which client host. So the review reflects observed third-party access rather than an attestation, and an integrator session that steps outside its usual pattern is scored as it happens rather than found at the next annual review.
The register of ICT providers is maintained by you. What is produced against the monitoring half is the observed access record per third-party identity — granted versus used, against classified objects, with the client host attached.
What DORA covers
This instrument defines no data category of its own. Regulates ICT risk management and operational resilience at the level of the ENTITY. Scope follows the financial entity and its critical functions, not any category of data.
How DORA is enforced
Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by National financial regulators; the ESAs directly, for designated critical ICT providers.
| Published maximum | Charged | As at |
|---|---|---|
| 1% of average daily worldwide turnover | charged daily against a designated critical ICT provider until it complies, for up to six months | 2026-08 |
Article 35 lets the Lead Overseer impose a periodic penalty payment of 1% of the average daily worldwide turnover of the preceding business year, levied daily until the provider complies, for up to six months. For financial entities themselves, penalties are set by each Member State rather than by the Regulation.
The daily mechanism is designed to compel compliance rather than to punish, so it stops the moment the deficiency is remedied.
Uncapped exposure that sits outside this instrument
These come from company law rather than from DORA, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.
Duty of oversight
Delaware, and followed in most US corporate jurisdictions. It is a rule of company law, not of any privacy or security statute.
Triggered by. A sustained or systematic failure by the board to establish a reporting system for a mission-critical risk — or, having one, consciously disregarding what it reported. The second limb is what a documented, unremediated finding goes to.
Who. Directors, in their personal capacity, in a derivative action brought on behalf of the company.
This is liability for the loss the company suffered, not a statutory penalty, so nothing caps it at a published maximum. A bad-faith finding also takes the conduct outside the exculpation and indemnification the charter would otherwise provide.
In re Caremark Int’l Deriv. Litig. (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019); In re Boeing Co. Deriv. Litig. (Del. Ch. 2021).
Who the instrument makes accountable
Article 5 puts the ICT risk management framework on the management body of the financial entity and makes it accountable, with Article 5(4) adding a training obligation.
The insurance position
Operational resilience failures typically fall inside cyber and professional wordings for the loss itself; supervisory penalties are commonly excluded.
How this class of policy is commonly written. Only your own policy answers what it covers.
Enforcement data reviewed August 2026. Several figures are indexed annually and move.
Built for DORA,
not configured for it afterwards
ICT System Monitoring
Comprehensive monitoring of all database access and changes
DORA Incident Report
Incident classification and timeline for regulatory reporting
Critical Data Assets
Identify and classify critical financial data assets
Third-Party Access Monitoring
Track and alert on third-party service provider database access
Other Financial frameworks
Walk into the DORA audit knowing the answer
228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.