Jump to

DORA (Digital Operational Resilience Act)

What is DORA (Digital Operational Resilience Act)?

DORA, Regulation (EU) 2022/2554, sets uniform rules on digital operational resilience for the EU financial sector and has applied since January 2025. It covers banks, investment firms, payment and e-money institutions, insurers and crypto-asset service providers authorised under MiCA, together with the critical ICT third-party providers — cloud platforms, data centres, software vendors — on which those firms depend. The premise is blunt: a financial entity is only as resilient as the technology chain behind it.

The five pillars

DORA organises its requirements under five headings:

  • ICT risk management: a documented framework owned by the management body, covering identification, protection, detection, response and recovery.
  • Incident reporting: classification of ICT-related incidents and mandatory notification of major incidents to the competent authority within set timeframes.
  • Resilience testing: a proportionate testing programme, extending to threat-led penetration testing for significant entities.
  • Third-party risk: a register of information covering all ICT contracts, plus mandatory contractual provisions where critical functions are supported.
  • Information sharing: voluntary exchange of cyber threat intelligence between financial entities.

The legal dimension

Much of DORA’s practical weight lands in contracts. Agreements with ICT providers must describe the service and data locations, secure audit and access rights, set incident assistance and exit terms, and address sub-outsourcing. Providers designated as critical at EU level fall under a direct oversight framework with inspection powers. DORA operates alongside horizontal cybersecurity legislation such as the Cyber Resilience Act (CRA), but as the sector-specific regime it takes precedence within finance.

Turkish context

DORA does not apply directly in Turkey, yet Turkish fintech, SaaS and infrastructure companies feel it through their contracts. An EU bank or a MiCA-licensed CASP buying services from a Turkish provider must flow DORA’s contractual requirements down the chain: audit rights, incident notification deadlines, data-location disclosure, exit plans. Refusing those clauses increasingly means losing the client. Reviewing service agreements against DORA’s third-party provisions before an EU counterparty raises them is far cheaper than renegotiating under pressure.

Do: map which of your EU clients are financial entities and pre-draft DORA-aligned contract annexes. Don’t: treat DORA as an IT-department matter — the obligations sit with management and surface in every service contract you sign.

If this is on your desk

Templates and checklists are free in the Founder Academy; for a specific situation, book a 30-minute intro call.

Founder AcademyBook an intro call