What is DORA?
DORA (the Digital Operational Resilience Act), Regulation (EU) 2022/2554, is a directly applicable EU regulation that requires financial entities to withstand, respond to, and recover from ICT-related disruptions and cyberattacks. It became enforceable on 17 January 2025 and applies to approximately 22,000 EU financial entities and their ICT third-party service providers.
The financial sector lost over $12 billion to cyberattacks across two decades [IMF Global Financial Stability Report, 2024]. The majority of those incidents had a third-party vector. DORA was designed to close that gap at scale. It does not replace NIS2, Solvency II, or MiFID II — it sits alongside them and is more prescriptive than any prior operational resilience framework.
The regulation's most demanding section is its third-party chapter. The average EU financial institution manages 147 ICT third-party arrangements [EBA survey, 2024]. Every one of those relationships now has to satisfy DORA's requirements for due diligence, contracts, monitoring, and exit planning.
Who DORA applies to
DORA applies to financial entities operating in the EU across 21 entity categories, and to their ICT service providers regardless of where those providers are headquartered. A US-based cloud platform serving a German bank falls under DORA for that service relationship.
- Banking — credit institutions, payment institutions, electronic money institutions
- Investment and markets — investment firms, trading venues, central counterparties
- Insurance — insurance and reinsurance undertakings and intermediaries
- Crypto and digital assets — crypto-asset service providers, issuers of asset-referenced tokens
- ICT third-party providers — any ICT service provider serving in-scope EU financial entities, regardless of location
- Data and ratings — data reporting service providers, credit rating agencies, audit firms
Key figures
| 22,000+ EU financial entities subject to DORA |
147 avg ICT third-party arrangements per institution |
50% of institutions estimated fully compliant in 2026 |
10% of annual turnover — maximum fine for non-compliance |
The five pillars of DORA
DORA organizes its requirements across five pillars. Pillar 4 — ICT third-party risk management — has the highest rate of supervisory findings in 2025–2026 assessments.
- Pillar 1 — ICT risk management (Articles 5–16)
- Pillar 2 — ICT incident management and reporting (Articles 17–23)
- Pillar 3 — Digital operational resilience testing (Articles 24–27)
- Pillar 4 — ICT third-party risk management (Articles 28–44) ← highest rate of supervisory findings
- Pillar 5 — Information sharing arrangements (Articles 45–49)
DORA's third-party risk management obligations
Articles 28 to 44 set out a structured regime for how financial entities must select, contract with, monitor, and exit relationships with ICT third-party service providers. A gap at any link in the chain — from the Register of Information to contract provisions to board reporting — generates a supervisory finding.
Article 28: general principles
Art. 28(1)(a) Full accountability stays with you You remain fully responsible for DORA compliance even when a third party discharges an obligation on your behalf. Outsourcing a function does not outsource the regulatory accountability.
Art. 28(1)(b) Proportionality principle Your TPRM must be proportionate to the nature, scale, and criticality of the ICT dependency. Apply depth where it matters. Automate where it does not.
Art. 28(2) Board-approved TPRM strategy A written strategy on ICT third-party risk must be approved by the management body and reviewed at least annually. A strategy in draft form that has not reached the board does not satisfy this obligation.
Art. 28(3) Register of Information A machine-readable register of all ICT third-party arrangements must be submitted to your NCA annually in xBRL-CSV format. 34% of financial entities had not completed a full ICT third-party inventory by the DORA application date [EIOPA, 2025].
Art. 28(4) Pre-contractual due diligence Documented, independent due diligence must cover: security capabilities, business continuity, financial stability, data location, and concentration risk. A vendor-completed questionnaire is self-reported data. DORA requires independent verification.
Art. 28(8) Exit strategies Exit strategies must be documented and regularly tested for all material ICT arrangements. A document that has never been validated against operational reality does not meet this requirement.
How Site24x7 DRA addresses Article 28
- Continuous outside-in vendor monitoring — Art. 28(4) — continuous monitoring throughout the vendor relationship, not just at onboarding
- Structured security questionnaires — Art. 28(3) — Register of Information maintenance; Art. 28(6) — documented vendor assessments
- Automated risk scoring across 50+ signals — Art. 28(2) — documented TPRM strategy with risk-based methodology
- One-click DORA compliance reports — Art. 28(3) — Register of Information; Art. 28(6) — audit rights and reporting to NCAs and ESAs
- 130+ global monitoring locations — Art. 28(4) — data location assessment, including transfers outside the EU
Article 29: ICT concentration risk
Article 29 requires portfolio-level concentration risk assessment — not individual vendor scorecards. The ECB found that over 30% of significant banks' outsourcing budgets concentrate on just 10 providers [ECB, 2025]. DORA treats that systemic concentration as a risk category in its own right.
- Assess concentration before entering new critical or important function arrangements
- Develop exit strategies for high-concentration functions
- Report findings to the management body with documented evidence
- Map sub-outsourcing chains — when the same sub-contractor supplies multiple critical ICT providers, systemic dependency arises
How Site24x7 DRA addresses Article 29
- Automated risk scoring at portfolio level — Art. 29 — concentration risk monitoring across your full vendor portfolio
- Fourth-party and sub-outsourcing discovery — Art. 29(2) — automatic mapping of sub-vendor chains behind tier-1 providers
Article 30: mandatory contract clauses
Every ICT contract must contain the provisions listed in Article 30. Contracts predating January 2025 that lack these clauses are non-compliant today. A 2025 Deloitte analysis found 58% of existing ICT outsourcing contracts required amendment [Deloitte, 2025].
All contracts: Service description, data processing locations, incident notification obligations, termination rights, and data return or deletion on exit.
Critical functions: Quantitative SLA targets, unrestricted audit and inspection rights, 4-hour major incident notification, GDPR-equivalent data protection, and explicit sub-outsourcing controls.
Exit provisions: Adequate transition periods, data portability, and contractual support during exit — without operational disruption.
How Site24x7 DRA addresses Article 30
- Real-time risk alerts — Art. 30(3) — shortens time-to-awareness ahead of the 4-hour critical incident notification obligation
- Sub-outsourcing chain discovery — Art. 30 — surfaces sub-contractor dependencies that must be covered by contractual controls
The Register of Information
The Register of Information (RoI) is DORA's most operationally demanding single requirement and the starting point for every supervisory examination. Your register is not just a compliance document — it feeds directly into systemic risk oversight at EU level.
What your register must include:
- Provider details, contract scope and duration, service locations
- Subcontractors and sub-outsourcing chains
- Criticality classification — critical or important function vs. non-critical
- Concentration risk flags
Attention: A register that is accurate at the point of filing but not maintained operationally is a compliance gap within months. The RoI is a live obligation — treat it as an operational system, not an annual report.
Critical ICT third-party providers (CTPPs)
In November 2025, the ESAs published the first list of 19 designated CTPPs, including AWS, Microsoft Azure, Google Cloud, IBM, Salesforce, and Oracle. Each is assigned a Lead Overseer — EBA, EIOPA, or ESMA — who supervises through Joint Examination Teams.
What CTPPs face
- Report major ICT incidents to their Lead Overseer within 2 hours
- Periodic penalties of up to 1% of average daily worldwide turnover per day of non-compliance [DORA, Article 35(6)]
- Subject to inspections, resilience testing, and corrective measure requirements
What you must do if you use a CTPP
- Document CTPP dependencies in your Register of Information
- Ensure contracts include all Article 30 mandatory clauses
- Produce a concentration risk analysis
- Maintain and test exit strategies annually
Where DORA third-party programs are failing
Most organizations focused their DORA preparation on documentation. The supervisory findings from 2025–2026 show that documentation alone is not enough.
Gap 1
Incomplete Register of Information
34% of financial entities had not completed a full ICT third-party inventory by the DORA application date [EIOPA, 2025]. Missing sub-outsourcing data and incorrect criticality classifications are most common.
Gap 2
Self-reported questionnaires as due diligence
DORA requires independent verification. A vendor-attested SOC 2 and a self-completed questionnaire are not the same as independent assessment. Supervisors ask what external evidence you gathered.
Gap 3
Article 30 contractual gaps in legacy contracts
58% of existing ICT outsourcing contracts required amendment [Deloitte, 2025]. Missing audit rights and absent exit strategy provisions are the two most common clause gaps.
Gap 4
Board not receiving third-party risk reporting
DORA requires management body oversight. If your board is not receiving reporting on concentration risk, critical provider assessments, and third-party incidents, the governance obligation is not met.
Gap 5
Exit strategies that exist on paper only
Supervisors ask for test records, not Word documents. If your exit strategy has never been stress-tested against a realistic transition scenario, it does not satisfy the requirement.
How to build a DORA-compliant third-party risk program
DORA compliance is not a point-in-time exercise. These are the steps that distinguish firms passing supervisory reviews from those generating findings.
- Build and maintain your Register of Information as a live system Map every ICT third-party arrangement. Classify each by criticality. Capture service locations, subcontractors, and contract scope. Update operationally — not annually.
- Conduct independent pre-contractual due diligence For critical or important function providers: independently verify security capabilities, business continuity, financial stability, data location, and concentration risk before signing. Document your evidence.
- Audit and remediate ICT contracts against Article 30 Review all ICT contracts against the mandatory clause list. Prioritize contracts supporting critical or important functions. There is no grace period.
- Implement continuous monitoring Point-in-time assessments create a snapshot. Continuous monitoring creates a live feed. A vendor with a clean assessment today can introduce a critical vulnerability tomorrow.
- Report concentration risk to the board Produce a portfolio-level concentration risk assessment. Identify providers supporting multiple critical functions. Report to the management body with documented evidence.
- Test exit strategies — do not just document them Create operationally realistic exit strategies for all material ICT arrangements. For critical providers, run a test at least annually. Supervisors ask for test records, not strategy documents.
DORA, NIS2, and GDPR — Europe's cybersecurity trifecta
Financial entities in the EU must navigate three overlapping regulatory frameworks. Here is how they relate:
| DORA | NIS2 | GDPR | |
|---|---|---|---|
| Scope | All EU financial entities | Essential and important entities across EU sectors | Any organization globally that processes personal data of EU residents |
| Purpose | Digital operational resilience for the financial sector | Raise cybersecurity standards across the EU | Protect personal data and privacy rights of EU residents |
| Relation to DORA | — | DORA acts as lex specialis — financial entities covered by DORA are exempt from NIS2 cybersecurity and incident reporting obligations | Applies alongside DORA — DORA Article 30 requires GDPR-equivalent data protection in ICT contracts; both apply simultaneously to financial entities |
| Third-party risk | Prescriptive obligations — Articles 28–44, Register of Information, CTPP oversight | Article 21(2)(d) supply chain security — less prescriptive than DORA | Data processor agreements (Article 28) required for any vendor handling personal data |
| Max penalty | 10% of total annual worldwide turnover | €10 million or 2% of global turnover (essential entities) | €20 million or 4% of global turnover (severe violations) |
FAQ
1. When did DORA become enforceable?
DORA entered into force on 16 January 2023 and became applicable on 17 January 2025. All obligations, including third-party risk management under Articles 28 to 44, have been binding since January 2025.
2. Does DORA apply to non-EU companies?
Yes. DORA applies to any ICT third-party service provider that provides services to in-scope EU financial entities, regardless of where the provider is headquartered. A US-based cloud provider serving EU banks must comply with DORA's requirements for those service relationships.
3. What is the Register of Information and who must submit it?
The Register of Information is a machine-readable record of all contractual arrangements with ICT third-party service providers, submitted annually to national competent authorities in xBRL-CSV format. All in-scope financial entities must maintain and submit it. The first submission cycle was Q1 2026.
4. What are Critical ICT Third-Party Providers (CTPPs)?
CTPPs are ICT providers designated by the European Supervisory Authorities as systemically important to the EU financial sector. 19 providers were designated in November 2025, including AWS, Microsoft Azure, Google Cloud, IBM, Salesforce, and Oracle. CTPPs face direct ESA oversight, 2-hour incident reporting, and potential penalties of up to 1% of daily worldwide turnover per day of non-compliance.
5. Do legacy ICT contracts need to be updated for DORA?
Yes. DORA does not provide a grace period for legacy contract compliance. Contracts predating January 2025 that lack mandatory Article 30 clauses are non-compliant today. A 2025 Deloitte analysis found 58% of existing ICT outsourcing contracts required amendment.
6. What is the maximum penalty for DORA non-compliance?
Financial entities can face fines of up to 10% of total annual worldwide turnover for non-compliance. For critical ICT third-party providers, periodic penalty payments can reach 1% of average daily worldwide turnover for each day of ongoing non-compliance.
7. Is an annual vendor questionnaire sufficient for DORA compliance?
No. DORA requires documented, independent due diligence. For critical or important function providers, the assessment must cover security capabilities, business continuity, financial stability, and data location — all verified independently, not just attested by the vendor.
8. How does Site24x7 DRA help with DORA compliance?
Site24x7 Digital Risk Analyzer provides continuous outside-in monitoring of vendor security posture, automated risk scoring, sub-outsourcing chain discovery, and one-click compliance reports mapped to DORA's Article 28 obligations. It addresses the continuous monitoring requirement that questionnaire-based programs cannot meet — and generates the timestamped evidence trail supervisors expect to see.
9. What DORA obligations does Site24x7 DRA directly address?
DRA maps to DORA's Article 28 requirements — covering ICT third-party risk management, continuous monitoring of critical vendors, and sub-outsourcing chain visibility. It generates timestamped compliance reports that give financial entities the audit-ready evidence regulators expect.
10. Why aren't questionnaire-based assessments enough for DORA?
DORA mandates ongoing oversight, not point-in-time snapshots. Questionnaires capture a vendor's self-reported posture at one moment — DRA monitors it continuously from the outside, flagging changes in real time before they become reportable incidents.
11. How does DRA handle sub-outsourcing visibility under DORA?
DORA requires financial entities to understand their full ICT supply chain, including fourth and fifth parties. DRA's sub-outsourcing chain discovery maps dependencies beyond your direct vendors, so concentration risks and hidden exposure points don't go undetected.
12. What does "outside-in monitoring" mean in the context of DORA compliance?
Outside-in monitoring means DRA assesses your vendors the way an attacker would — without relying on vendor cooperation or self-disclosure. It continuously scans for exposed assets, misconfigurations, and risk signals, giving you an independent, verifiable view that satisfies DORA's requirement for objective third-party risk assessment.
