In force now
DORA
The Digital Operational Resilience Act has applied since 17 January 2025 to almost every financial entity in the EU. It is the strictest of the three regimes, and the only one that writes penetration testing into law.
Who it catches
Banks, insurers and reinsurers, investment firms, brokers, payment and electronic money institutions, crypto-asset service providers, fund managers, audit firms and the ICT providers that serve them. Unlike NIS2 there is no comfortable size threshold to hide behind — a small payment institution is in scope. If you supply software or hosting to any of these, DORA reaches you through your customer's register of information whether or not you consider yourself a financial firm.
THE DATES
Where this stands today
-
DORA applies in full
-
First register of information due to supervisors
What it actually requires
- An ICT risk-management framework with the management body accountable for it by name
- Classification and reporting of major ICT incidents, on a clock measured in hours
- Digital operational resilience testing, and threat-led penetration testing at least every three years for significant entities
- A register of information listing every ICT third-party arrangement, submitted to the supervisor
- Contractual terms with ICT providers that cover audit rights, exit and subcontracting
- Participation in threat-intelligence sharing arrangements
What it costs to get wrong
Supervisors can inspect, order remediation and fine up to 2% of global annual turnover; critical ICT third-party providers face up to €5 million personally as an entity. In practice the sharper risk for a smaller firm is commercial rather than regulatory — a bank that cannot evidence your arrangements in its register has a straightforward reason to replace you.
WHAT WE DO ABOUT IT
The services that close this gap
Not the whole catalogue — these are the ones that map onto the obligations above. If something here is already covered internally, say so and we will scope around it.
Chief Information Security Officer
A security executive on subscription: policy, risk register, board reporting and the evidence an auditor asks for — without a six-figure hire.
Read more PenTestPenetration testing
A real attack, run by people who have done it for a living, ending in a report your engineers can act on and your auditor will accept.
Read more TPRMaaSThird-party risk management
Your suppliers are your attack surface, and under NIS2 they are also your legal responsibility. We inventory them, rate them and keep watching.
Read moreNot sure whether DORA applies to you?
Tell us your sector, your headcount and what you sell. We will tell you which regimes catch you and what the first three things to do are — in writing, at no charge, because half the organisations that ask turn out not to be in scope and we would rather say so.