The Digital Operational Resilience Act (DORA) — Regulation (EU) 2022/2554 — is the EU's framework for ensuring financial entities can withstand, respond to, and recover from ICT-related disruptions and threats. DORA entered into force on 17 January 2025, making it one of the newest compliance requirements for financial-sector websites and services operating in or serving the EU.
Unlike GDPR (which protects personal data) or NIS2 (which secures critical infrastructure), DORA focuses specifically on operational resilience — the ability to keep critical functions running during ICT failures, cyberattacks, or system outages.
DORA covers a broad range of financial entities under EU financial services legislation:
| Category | Examples | In scope? |
|---|---|---|
| Banks & credit institutions | Retail, investment, private banks | ✅ Yes |
| Payment institutions | Stripe, PayPal, Adyen, Wise | ✅ Yes |
| Investment firms | Brokers, wealth managers | ✅ Yes |
| Crypto-asset service providers | Exchanges, wallets, custodians | ✅ Yes (MiCA-licensed) |
| Insurance & reinsurance | Carriers, brokers | ✅ Yes |
| ICT third-party providers | Cloud services (AWS, Azure), data analytics, compliance SaaS | ✅ Yes — critical TPPs are designated by ESAs |
| Small / non-interconnected firms | Small investment advisors | ⚠️ Partial — simplified regime |
If your company provides ICT services to financial entities — even if you are not a financial entity yourself — DORA may apply to you through the third-party oversight framework.
Establish a framework for identifying, classifying, and managing ICT risks. This includes business continuity management, incident response capabilities, and regular risk assessments documented and reviewed by the board.
Classify and report major ICT incidents to competent authorities. Initial notification within 4 hours for major incidents, intermediate report within 24 hours, and a final report within one month. Your website should clearly communicate how stakeholders can report incidents.
Regular testing of ICT systems: vulnerability scans, penetration testing, and — for larger entities — threat-led penetration testing (TLPT) every 3 years. Testing scope includes web applications, APIs, and customer-facing digital services.
Manage risks arising from outsourcing and third-party ICT providers. Maintain a register of contractual arrangements, assess concentration risk, and ensure contracts include DORA-required clauses for audit, termination, and performance monitoring.
Participate in threat intelligence sharing arrangements among financial entities — sharing cyber threat information to improve collective resilience. Your site may need to reference participation in such arrangements.
While DORA is primarily an operational regulation (not a "put this on your website" regulation like GDPR), your public-facing website plays several important roles in DORA compliance:
DORA Article 17 requires financial entities to have and communicate a process for ICT incident reporting. While the formal reporting goes to national competent authorities, your website should clearly indicate how stakeholders can report security incidents or ICT disruptions — whether through a dedicated email, a secure portal, or a contact form with appropriate classification.
For larger financial entities, DORA expects published information about business continuity planning. This doesn't mean revealing your full DR plan, but your website should reference BC/DR capabilities and communicate expected service levels during disruptions.
If you use critical ICT third-party providers (cloud infrastructure, payment processing, core banking systems), customers and regulators expect your website to disclose concentration risks and your approach to third-party oversight.
Financial entities subject to DORA must demonstrate board-level oversight of ICT risk. Your website should reference your information security management system (ISMS), risk framework certifications (ISO 27001, SOC 2), and how you manage ICT-related risk.
Our free scanner now includes a DORA/resilience check that looks for six categories of operational resilience signals in any website's public HTML:
| Signal | What it looks for |
|---|---|
| DORA / resilience framework | Mentions of "Digital Operational Resilience Act" or "DORA regulation" |
| ICT incident reporting | Process for reporting ICT incidents or security breaches |
| Business continuity / DR | References to BCP, disaster recovery, or continuity plans |
| ICT risk management | Information security risk framework, risk assessments |
| Third-party / supply chain risk | Vendor risk management, outsourcing oversight |
| Resilience testing | Penetration testing, vulnerability scanning, red team exercises |
The scan works on any website — WordPress, custom-built, or enterprise platform. No installation, no registration, no cost.
Run a free scan →🛡️ Passed? Add a free compliance badge to your site — client trust plus a dofollow backlink.
| Date | Milestone |
|---|---|
| 16 Jan 2023 | DORA entered into force |
| 17 Jan 2025 | Application date — DORA became legally enforceable |
| 2025–2026 | National competent authorities begin supervisory assessments; first enforcement actions expected |
| 2026–2027 | ESAs designate critical ICT third-party providers; first TLPT cycles completed |
| 2027 | First comprehensive DORA reviews by European Supervisory Authorities (EBA, EIOPA, ESMA) |
If you're responsible for compliance across multiple EU frameworks, here is how DORA relates to the other big regulations:
| Regulation | Scope | Focus | Applies to websites? | Penalties |
|---|---|---|---|---|
| DORA | Financial entities + ICT TPPs | Operational resilience (ICT continuity, incident response, testing) | Yes — as a channel for disclosures | Up to 2% turnover |
| GDPR | All orgs processing EU personal data | Data protection, privacy, consent | Yes — cookies, forms, privacy notices | Up to €20M or 4% |
| NIS2 | Essential & important entities | Network & information security, incident reporting, supply chain | Yes — security headers, breach reporting | Up to €10M or 2% |
| EAA | Commerce/services websites | Digital accessibility (WCAG) | Yes — accessibility statement, alt text | Varies by member state |
DORA and NIS2 share some overlaps (both require incident reporting, risk management, and testing). The difference: NIS2 applies broadly to critical infrastructure (energy, transport, health, digital infrastructure), while DORA is specifically for financial-sector operational resilience.
Use this checklist to assess whether your financial-entity website meets DORA expectations:
Or start with our full EU compliance checklist covering GDPR, NIS2, DORA, and EAA in one document.