Securance logo

DORA explained: what European organisations need to know in 2026

DORA has been in force since January 2025, covering ~22,000 EU financial entities. Learn the 5 pillars, who's affected, penalties, and how to prepare.

Linkedin sales solutions 46bom4l Obs A unsplash

If you work in or alongside Europe's financial sector, DORA is no longer a future concern — it's already here. The Digital Operational Resilience Act entered application on 17 January 2025, and since then around 22,000 EU-regulated financial entities have been expected to demonstrate compliance. Regulators are watching, enforcement regimes are taking shape, and as a January 2026 report by QA Financial noted, many organisations are still grappling with the practical demands of resilience testing.

So what exactly does DORA require, who does it affect, and what should your organisation be doing about it?


What DORA actually is (and why it exists)

DORA — Regulation (EU) 2022/2554 — is an EU-wide framework designed to ensure that financial entities can withstand, respond to, and recover from ICT-related disruptions and threats. Before DORA, each EU member state handled digital resilience requirements differently, creating a patchwork of rules that was difficult to navigate and even harder to enforce consistently.

DORA changes that by setting uniform requirements across the entire financial sector. According to the European Insurance and Occupational Pensions Authority (EIOPA), it covers banks, insurers, investment firms, payment institutions, crypto-asset service providers, and more — essentially any entity that keeps financial services running digitally.

DORA

The 5 pillars your organisation must address

DORA organises its requirements around five core areas. Each one demands real, documented effort — not just policy documents gathering dust.

1. ICT risk management and governance Your board and senior leadership must take direct ownership of ICT risk. That means approving budgets for cybersecurity, defining risk tolerance, and ensuring a governance framework exists that maps and protects your critical ICT assets. Executives can no longer delegate this entirely to IT teams.

2. ICT incident detection and reporting Organisations must have processes in place to detect, classify, and log cyber incidents. Major incidents need to be reported to your national competent authority using standardised templates. Timelines are tight — initial reports are required within 24 hours of a major incident being classified.

3. Digital operational resilience testing This is where many organisations are still finding their footing. All in-scope entities must run annual vulnerability assessments and network security reviews. Significant financial entities face an additional requirement: regular threat-led penetration testing (TLPT), which simulates sophisticated real-world attack scenarios. These testing standards now form a regulatory necessity, not just good practice. Securance's network penetration testing service is designed exactly for this kind of rigorous, compliance-aligned testing.

4. ICT third-party risk management If your operations depend on cloud providers, software vendors, or any other ICT supplier — and they almost certainly do — DORA puts strict obligations on how you manage those relationships. Contracts with providers of critical functions must include guaranteed service levels, audit rights, incident notification obligations, and exit strategies. The European Banking Authority designated the first wave of Critical Third-Party Providers (CTPPs) in November 2025, bringing those suppliers under direct ESA oversight. Good risk management processes are now inseparable from vendor management.

5. Information sharing DORA encourages (though doesn't mandate) organisations to share cyber threat intelligence with peers to strengthen collective resilience across the EU financial ecosystem. Voluntary participation in information-sharing arrangements is worth considering as part of your broader security culture.


What the penalties look like

Non-compliance isn't an abstract risk. Financial entities can face fines of up to 2% of their total annual worldwide turnover or €10 million — whichever is higher. Even individuals, including board members, can be personally fined up to €1 million. In extreme cases, national authorities can suspend business activities or revoke operating licences entirely.

Beyond the financial hit, public reprimands can cause serious reputational damage — particularly for firms that rely on client trust as a competitive differentiator.


DORA and your existing compliance frameworks

Here's the reassuring part: if your organisation already holds ISO 27001 certification or has completed a SOC 2 audit, you're not starting from scratch. DORA shares significant ground with these frameworks — particularly around ICT risk governance, incident management, and access controls.

The key difference is that DORA is a legally binding regulation, not a voluntary standard. You can't simply point to an ISO 27001 certificate and call it done. But the control frameworks you've already built are a solid foundation. Our blog post on ISO 27001 and SOC 2 comparisons walks through how these standards relate, which may help you spot the gaps.

It's also worth noting DORA's relationship with NIS2, the EU's broader cybersecurity directive. For most financial entities, DORA takes precedence — but if you're navigating both, our NIS2 directive explained guide covers the overlap in detail.


Practical steps to take now

If your DORA readiness programme isn't fully in place yet, these are the areas worth prioritising:

  • Map your ICT assets and dependencies — you can't govern what you haven't documented, and DORA requires a register of all third-party ICT contracts
  • Assess your testing programme — does it meet DORA's annual requirements? Do you qualify for TLPT obligations?
  • Review third-party contracts — check whether your current supplier agreements include the mandatory clauses DORA requires
  • Clarify board accountability — make sure senior leadership understands their personal responsibilities under DORA's governance requirements
  • Run a gap analysis — compare your current controls against DORA's five pillars to identify what still needs work

At Securance, we work with SaaS and tech teams across Europe to make compliance less painful and more strategic. Our compliance services help organisations build frameworks that satisfy DORA's requirements while also strengthening their overall security posture — so compliance becomes an asset rather than a burden.

DORA isn't a one-time project. Resilience is an ongoing discipline, and the organisations that treat it that way will be far better positioned — both with regulators and with the clients who trust them with sensitive financial data.