Skip to main content
← All posts·
Regulatory Compliance

What Is DORA? Digital Operational Resilience Act Explained for 2026

DORA (Digital Operational Resilience Act) explained in plain language. Who it applies to, what it requires, key deadlines, penalties, and how it affects AI and IT infrastructure in financial services. Updated for 2026 enforcement.

Luca Berton9 min read

DORA in 60 Seconds

The Digital Operational Resilience Act (DORA) is an EU regulation that requires financial entities to manage their ICT (Information and Communication Technology) risks systematically. It entered into force on 16 January 2023 and applies from 17 January 2025.

In simple terms: DORA makes financial institutions responsible for the resilience of their digital systems — not just their own, but also those of their critical third-party providers.

Who Does DORA Apply To?

21 Types of Financial Entities

  • Banks and credit institutions
  • Investment firms
  • Insurance and reinsurance undertakings
  • Payment institutions and e-money institutions
  • Crypto-asset service providers
  • Central securities depositories
  • Trading venues
  • Fund managers (UCITS and AIFMs)
  • Credit rating agencies
  • Crowdfunding service providers
  • Pension funds
  • And their critical ICT third-party service providers (cloud, SaaS, managed services)

Proportionality principle: Requirements scale with entity size and complexity. Microenterprises have simplified obligations.

The 5 Pillars of DORA

  1. ICT Risk Management (Articles 5-16): Establish and maintain a comprehensive ICT risk management framework with identification, protection, detection, response, and recovery capabilities.
  2. ICT Incident Management (Articles 17-23): Classify, report, and learn from ICT-related incidents. Major incidents must be reported to supervisory authorities within strict timelines.
  3. Digital Operational Resilience Testing (Articles 24-27): Regular testing including vulnerability assessments, network security testing, and advanced threat-led penetration testing (TLPT) for significant entities.
  4. ICT Third-Party Risk Management (Articles 28-44): Due diligence, contractual requirements, and ongoing monitoring of ICT service providers. Critical providers subject to EU-level oversight.
  5. Information Sharing (Article 45): Voluntary sharing of cyber threat intelligence between financial entities.
📘 Book

Kubernetes Recipes

Practical guide for container orchestration and deployment — hands-on patterns you can use today.

View on Amazon →

DORA and AI Systems

DORA doesn't mention "AI" explicitly, but AI systems are ICT systems. If your financial institution uses AI for credit scoring, fraud detection, algorithmic trading, or customer service, those AI systems fall under DORA's ICT risk management requirements:

  • AI model risk → ICT risk management framework (Pillar 1)
  • AI system failures → Incident classification and reporting (Pillar 2)
  • AI resilience → Operational resilience testing (Pillar 3)
  • AI cloud providers → Third-party risk management (Pillar 4)

Key Deadlines

  • 17 January 2025: DORA applies — all requirements are enforceable
  • 2025-2026: Regulatory Technical Standards (RTS) and Implementing Technical Standards (ITS) being finalised by ESAs
  • Ongoing: Critical ICT third-party provider oversight framework being established
🎓 Course with Starweaver

Back-End Infrastructure: Servers, Secure APIs and Data

Build secure back-end infrastructure from the ground up. In collaboration with Starweaver.

Start on Coursera →

Penalties

DORA penalties are determined by national competent authorities (NCAs) in each EU member state. Penalties can include:

  • Administrative fines
  • Periodic penalty payments (up to 1% of average daily worldwide turnover per day for up to 6 months)
  • Public statements identifying the entity and the violation
  • Orders to cease conduct
  • Temporary bans on management body members
DORA
Digital Operational Resilience Act
financial services
compliance
regulation
explained

Related Solution

Navigating AI adoption in a regulated environment? Our readiness assessment maps infrastructure, governance, and compliance gaps in 3-4 weeks.

Explore AI Readiness for Regulated Enterprises →

Need help applying this in your organization?

Get a free 30-minute assessment with actionable recommendations — whether we work together or not.

Book Your Free AI Platform Assessment

Or see AI readiness assessment scope & pricing

18+ years experience · Ex-Red Hat & Dell · Speaker at KubeCon EU 2026

Luca Berton

Written by

Luca Berton

CEO at Open Empower. 18+ years building enterprise infrastructure at JPMorgan Chase, Red Hat & Dell. Author of 9 technical books. Speaker at Red Hat Summit and KubeCon EU 2026. Instructor on Coursera, Pluralsight & Udemy.

Get more insights like this

Practical AI infrastructure and platform engineering guides — delivered to your inbox.

Subscribe to Newsletter →