Why Nexovern
Support Request a demo

Home  /  Resources  /  Frameworks  /  DORA

Digital operational resilience for financial services, enforced since January 2025.

The EU's Digital Operational Resilience Act (Regulation (EU) 2022/2554) is the first regulation to create a unified ICT risk management framework across the entire European financial sector. It covers 21 categories of financial entities, imposes mandatory incident reporting within four hours of classification, and establishes direct EU-level oversight of critical ICT third-party providers. For any organization deploying AI in financial services, every model, agent, and inference pipeline qualifies as ICT under DORA's technology-neutral scope.

What DORA requires, and why it matters now

DORA addresses the financial sector's increasing dependence on information and communication technology for service delivery. Before DORA, EU ICT risk requirements were fragmented across sectoral directives (CRD, Solvency II, PSD2, MiFID II) and varied by member state. DORA harmonises these into a single, directly applicable regulation that applies uniformly across all 27 EU member states without national transposition. As a lex specialis, it takes precedence over the general NIS2 Directive for financial entities, while DORA, NIS2, and GDPR penalties remain cumulative: a single ICT incident can trigger obligations and fines under all three regulations simultaneously.

21

categories of financial entities within DORA's scope, from banks and insurers to crypto-asset providers and ICT third-party vendors

DORA Article 2(1)(a)-(u)

4 hrs

deadline for the initial notification to competent authorities after classifying an ICT incident as major

DORA Article 19; Regulation (EU) 2025/301

19

ICT providers designated as critical by the ESAs in November 2025, including AWS, Microsoft Azure, Google Cloud, Oracle, and SAP

ESA Critical Designation, November 2025

Who must comply

Credit institutions and payment providers

Banks, savings banks, cooperative banks, payment institutions (including those exempt under PSD2), electronic money institutions, and account information service providers. These entities must maintain complete ICT risk management frameworks, report major incidents within four hours of classification, and conduct annual resilience testing.

DORA Article 2(1)(a)-(d)

Investment firms and market infrastructure

Investment firms, central securities depositories, central counterparties, trading venues, trade repositories, and data reporting service providers. Entities designated as systemically significant face mandatory threat-led penetration testing (TLPT) at least every three years.

DORA Article 2(1)(e), (g)-(m)

Insurance, reinsurance, and pensions

Insurance and reinsurance undertakings, insurance intermediaries, reinsurance intermediaries, ancillary insurance intermediaries, and institutions for occupational retirement provision. All face the same core ICT risk management and incident reporting obligations.

DORA Article 2(1)(n)-(p)

Crypto, crowdfunding, and benchmarks

Crypto-asset service providers, issuers of asset-referenced tokens, crowdfunding service providers, credit rating agencies, administrators of critical benchmarks, and securitisation repositories. These newer financial sector participants carry the same DORA obligations as established institutions.

DORA Article 2(1)(f), (q)-(t)

ICT third-party service providers

All ICT vendors serving EU financial entities are within scope. Providers designated as critical face direct oversight from a Lead Overseer (EBA, ESMA, or EIOPA), including on-site inspections, remediation demands, and penalty payments of up to 1% of average daily worldwide turnover per day of non-compliance. AI vendors are classified as ICT third-party service providers.

DORA Article 2(1)(u); Articles 31-44

Extraterritorial reach

DORA is directly applicable across all 27 EU member states. ICT third-party providers based outside the EU that serve EU financial entities are indirectly covered through mandatory contractual requirements (Article 30) and the critical provider oversight framework. There is no geographic exemption for providers operating from outside European jurisdiction.

DORA Articles 28-30; Critical Provider Designation Framework

The five pillars of DORA

"The management body bears ultimate responsibility for defining, approving, overseeing, and being responsible for the ICT risk management framework."

Pillar 1: ICT Risk Management (Articles 5-16) Financial entities must maintain a complete, up-to-date inventory of all ICT assets, including AI systems, cloud services, and third-party integrations. The framework requires systematic risk identification, documented risk appetite levels, protection and prevention measures, detection capabilities (SIEM, IDS, anomaly detection), and response and recovery plans tested at least annually. Board members must maintain adequate knowledge of ICT risks through specific training. Detailed specifications are set out in Commission Delegated Regulation (EU) 2024/1774.

→ Nexovern discovers and inventories every AI system across your environment, providing the asset-level visibility and continuous risk evidence that Article 5 assigns to the management body, without relying on manual cataloguing that misses shadow deployments.

"Initial notification within four hours of classification as major. Intermediate report within 72 hours. Final report with root cause analysis within one month."

Pillar 2: ICT Incident Reporting (Articles 17-23) Major incidents trigger a mandatory three-stage reporting timeline: initial notification within four hours of classification (hard outer limit: 24 hours after detection), intermediate report within 72 hours, and a final report including root cause analysis within one month. Incidents are classified by severity, impact, duration, geographic spread, data losses, and criticality of affected services, per Commission Delegated Regulation (EU) 2024/1772. Financial entities must also voluntarily report significant cyber threats, even when no incident has yet occurred. Standardised reporting formats took effect February 20, 2025.

→ Nexovern's correlated app-layer and OS-layer telemetry provides the prompt-level visibility into AI operations needed to classify an incident and assemble the initial notification within the four-hour window, rather than reconstructing events after the deadline has passed.

"Threat-led penetration testing on live production systems, using external testers, at least every three years for significant entities."

Pillar 3: Digital Operational Resilience Testing (Articles 24-27) All in-scope entities must maintain a comprehensive testing programme conducted at least annually, covering vulnerability assessments, network security assessments, scenario-based testing, and penetration testing. Entities identified by competent authorities as systemically significant must undergo TLPT at least every three years, following the TIBER-EU framework, conducted on live production systems by external, independent testers. AI systems supporting critical or important functions fall within TLPT scope. The first mandatory TLPT cycle must be completed by January 17, 2028. Technical standards are defined in Commission Delegated Regulation (EU) 2025/1190.

→ Nexovern provides the runtime evidence and AI system mapping that resilience testing teams need to scope their engagements accurately, ensuring that AI red teaming, prompt injection testing, and adversarial assessments cover every critical AI component.

"Maintain a Register of Information documenting all contractual arrangements with ICT third-party service providers."

Pillar 4: ICT Third-Party Risk Management (Articles 28-44) Financial entities must conduct thorough due diligence on all ICT providers, assess concentration risk, and maintain a Register of Information covering every contractual arrangement with ICT third-party providers. Contracts supporting critical functions must include service-level descriptions, data location requirements, encryption standards, incident notification aligned to Article 19 timelines, audit and inspection rights, exit strategies with tested transition plans, and subcontracting conditions. AI vendors must disclose their subcontracting chains, including foundation-model providers and hosting infrastructure, per Regulation (EU) 2025/532. Exit strategies must be operationally tested, not merely documented.

→ Nexovern's automated discovery identifies which AI vendors your organization relies on in production, mapping inference dependencies and subcontracting chains so your Register of Information reflects what is actually deployed, not what procurement records suggest.

"Financial entities may exchange cyber threat intelligence and information among themselves."

Pillar 5: Information Sharing (Article 45) DORA establishes a voluntary framework for financial entities to share cyber threat intelligence, including indicators of compromise (IoCs), tactics, techniques, and procedures (TTPs), vulnerability assessments, and configuration tools. Sharing must respect confidentiality, data protection under GDPR, competition law, and intellectual property. For AI-driven financial services, this extends to sharing new prompt injection techniques, observed agent compromise patterns, AI-specific indicators of compromise, and model vulnerability disclosures through trusted communities and sector-wide intelligence platforms.

→ Nexovern's telemetry generates the structured, shareable threat intelligence that information-sharing arrangements require, converting raw AI interaction data into indicators of compromise and behavioral patterns that peer institutions can act on.

Penalties and enforcement

Financial entities: up to 2% of annual turnover

Member states must establish administrative penalties that are effective, proportionate, and dissuasive. Penalty ranges vary by jurisdiction, from EUR 100,000 (Finland) to EUR 5 million (Germany/BaFin) as national absolute ceilings. Some member states have set penalties up to 2% of total annual worldwide turnover or EUR 10 million, whichever is higher.

DORA Article 50; Member state implementations

Critical ICT providers: 1% of daily turnover per day

Lead Overseers can impose periodic penalty payments of up to 1% of the provider's average daily worldwide turnover for each day of non-compliance, sustained for up to six months. A cloud provider with EUR 20 billion in annual revenue faces a daily ceiling of approximately EUR 548,000, potentially exceeding EUR 100 million over the full enforcement period.

DORA Articles 35-36; ESA oversight powers

Individual liability: up to EUR 1 million

Management body members and individuals responsible for breaches face personal fines of up to EUR 1 million in certain jurisdictions. Competent authorities may also impose public censure, identifying violators and describing breaches publicly. Member states may additionally choose to impose criminal penalties for DORA breaches.

DORA Articles 50, 52

Cumulative exposure with NIS2 and GDPR

DORA, NIS2, and GDPR penalties are cumulative and not mutually exclusive. A single ICT incident involving personal data can trigger obligations and fines under all three regulations simultaneously: up to 2% under DORA, up to 2% under NIS2, and up to 4% under GDPR, alongside the distinct penalties for critical ICT providers.

DORA recital; NIS2 Directive (EU) 2022/2555; GDPR

Key dates

01

January 17, 2025: DORA fully applicable

After a two-year implementation period, all DORA requirements became enforceable across 27 EU member states. Penalty powers activated, and all financial entities must have their ICT risk management frameworks, incident reporting processes, and third-party contractual arrangements in place.

02

February-July 2025: Technical standards in force

Standardised incident reporting formats (Regulations 2025/301 and 2025/302) took effect February 20. TLPT technical standards (Regulation 2025/1190) activated July 8. Subcontracting disclosure requirements (Regulation 2025/532) took effect July 22, requiring ICT providers to disclose foundation-model dependencies and hosting infrastructure.

03

November 2025: Critical ICT providers designated

The ESAs (EBA, ESMA, EIOPA) designated 19 ICT providers as critical, including AWS, Microsoft Azure, Google Cloud, Oracle, and SAP. Each was assigned a Lead Overseer with powers to request documentation, conduct inspections, issue recommendations, and impose daily penalty payments.

04

Q1 2026: Register of Information submission

Financial entities submitted their first full Register of Information, documenting all contractual arrangements with ICT third-party service providers. Competent authorities forwarded data to the ESAs by March 31, 2026. First oversight inspections of critical ICT providers commenced in 2026.

05

January 17, 2028: First TLPT deadline

Initially designated significant entities must complete their first mandatory threat-led penetration testing (TLPT) exercise, conducted on live production systems following the TIBER-EU framework. AI systems supporting critical or important functions fall within the TLPT scope. Testing is required every three years thereafter.

How Nexovern helps

DORA compliance starts with knowing what you have. Build the evidence before the overseer asks.

Every AI system in your financial services environment is ICT under DORA. A Nexovern demo maps your current AI deployments against the five pillars and identifies the gaps in your ICT risk management framework, incident readiness, and third-party register.