Operational Resilience

DORA Compliance: ICT Risk & Operational Resilience

The Digital Operational Resilience Act sets one EU standard for how financial entities manage ICT risk, report incidents and test their resilience. This guide summarises what DORA requires — and how ReguShield turns those obligations into audit-ready decisions.

What DORA is

DORA is a directly-applicable EU regulation that consolidates digital operational resilience requirements for the financial sector into one framework. Rather than leaving ICT security to sector-specific rules and national interpretation, it sets common expectations for risk management, incident handling, resilience testing and the governance of technology dependencies — with the management body held accountable for the outcome.

The five pillars

Pillar 1

ICT risk management

Financial entities must run a documented ICT risk-management framework — identifying critical systems, protecting and detecting against ICT threats, and maintaining response and recovery capabilities under the management body’s accountability.

Pillar 2

ICT-related incident reporting

Major ICT-related incidents must be classified and reported to competent authorities on a defined timeline, with an initial notification followed by intermediate and final reports as the situation develops.

Pillar 3

Digital operational resilience testing

Entities test their resilience regularly, and the most significant entities perform advanced threat-led penetration testing (TLPT) that simulates realistic attacks against live production systems on a multi-year cycle.

Pillar 4

ICT third-party risk

Reliance on ICT service providers — including cloud — must be governed through a register of information, contractual safeguards and monitoring. Critical third-party providers fall under a dedicated EU oversight regime.

Pillar 5

Information sharing

Entities may share cyber-threat intelligence within trusted communities to strengthen collective resilience, on a voluntary basis and within the bounds of data-protection rules.

Key thresholds & obligations

Who is in scope

DORA applies to a broad set of financial entities — banks, payment and e-money institutions, investment firms, crypto-asset service providers, insurers and more — and, through the oversight regime, to the critical ICT third parties that serve them.

Major-incident notification

For a major ICT-related incident, an initial notification is expected promptly — commonly cited as within four hours of classifying the incident as major (and no later than a short outer window after becoming aware) — followed by intermediate and final reports on defined timelines.

Threat-led penetration testing

Entities identified as significant must carry out TLPT on a recurring basis — typically referenced as a three-year cycle — covering critical functions and, where relevant, the ICT third parties supporting them.

Register of information

Entities maintain a register of all contractual arrangements for ICT services, which supervisors can request, supporting oversight of concentration and third-party dependency risk.

Precise deadlines and testing scope are set by DORA and its regulatory technical standards, and depend on how an entity is classified. Treat the figures above as orientation, not a substitute for the legal text and your supervisor’s guidance.

How ReguShield helps

ReguShield is a compliance intelligence layer that maps your operational data against the DORA obligations in scope and produces decisions a compliance or resilience owner can stand behind:

  • Obligation mapping. Each DORA obligation in scope — risk management, incident reporting, testing, third-party risk — is mapped to your posture.
  • Inherent & residual risk scoring. Deterministic ICT risk scores before and after controls, so residual exposure is explicit.
  • Control-effectiveness assessment. How well existing controls reduce inherent ICT risk, surfaced as a measurable input.
  • Evidence lifecycle & audit lineage. Evidence tracked against each obligation, with a complete trail of the reasoning behind every decision.
  • Explainable decision support. Every conclusion traces back to the signal and the rule that produced it — deterministic and explainable, never a black box.
  • Board-ready executive reporting. Audit-ready reports with resilience posture, regulatory basis and recommended actions, built for supervisory scrutiny.

Analysis runs on demand over the data you provide. ReguShield does not claim a live regulator feed or any regulatory certification — it is a decision-support tool.

Frequently asked

What is DORA and who does it apply to?

DORA — the Digital Operational Resilience Act — is an EU regulation setting uniform requirements for the security of network and information systems across the financial sector. It applies to a wide range of financial entities, including banks, payment and e-money institutions, investment firms, insurers and crypto-asset service providers, as well as the critical ICT third-party providers that serve them.

What is the DORA incident-reporting timeline?

For major ICT-related incidents, DORA requires a staged report to the competent authority: an initial notification promptly after the incident is classified as major — widely referenced as within four hours of that classification and a short outer window from awareness — followed by an intermediate report and a final report on defined timelines. Exact deadlines are set out in the regulation and its technical standards.

What is TLPT under DORA?

Threat-led penetration testing is advanced resilience testing that simulates realistic, intelligence-driven attacks against an entity’s live production systems. Entities identified as significant must perform it on a recurring cycle — commonly cited as every three years — covering critical functions and, where relevant, the ICT third parties supporting them.

How does DORA treat third-party ICT providers such as cloud?

DORA requires entities to govern ICT third-party risk through a register of information, contractual safeguards and ongoing monitoring, and to manage concentration risk. Providers designated as critical — often large cloud and infrastructure vendors — are placed under a dedicated EU oversight framework led by the European Supervisory Authorities.

How does ReguShield support DORA readiness?

ReguShield maps operational data against DORA obligations on demand, scores inherent and residual ICT risk, assesses control effectiveness, tracks evidence against each obligation with full audit lineage, and produces explainable, board-ready reporting. It is deterministic decision-support: every conclusion is traceable and final decisions remain with qualified staff — ReguShield does not claim a live regulator integration or certification.

ReguShield provides compliance decision-support — not legal advice; final decisions require human review and sign-off.

View the guided demoTrust CenterBack to Resources