RegTech

DORA Regulation 2025: Compliance Guide for Financial Entities and Fintech

Gerard Maymó
June 17, 2026
9 min read
DORA Regulation 2025: Compliance Guide for Financial Entities and Fintech
RegTech · DORA · Financial Entities · Fintech

DORA Regulation 2025: Compliance Guide for Financial Entities and Fintech

The Digital Operational Resilience Act (Regulation (EU) 2022/2554, DORA) has applied to all EU financial entities since 17 January 2025. Covering approximately 22,000 entities across banking, insurance, investment management, payments and crypto-assets, DORA introduces five binding pillars of digital operational resilience that are now being actively supervised by national competent authorities across the EU.

DORA — Digital Operational Resilience Act: Regulation (EU) 2022/2554 of the European Parliament and of the Council, of 14 December 2022. Applicable from 17 January 2025 across all EU Member States without need for national transposition. DORA is lex specialis for the financial sector, superseding sector-specific cybersecurity rules under prior directives and harmonising ICT risk requirements across more than 20 categories of financial entities.

~22,000

"Financial entities in the EU subject to DORA compliance. National supervisors (Banco de España, CNMV, BaFin, ACPR, etc.) began active supervisory assessments from Q1 2025."

— European Commission, DORA Impact Assessment, 2020

Which entities must comply with DORA?

DORA Article 2 defines the scope. Covered entities include: credit institutions (banks, credit cooperatives), payment institutions and e-money institutions, investment firms and UCITS management companies, alternative investment fund managers, insurance and reinsurance undertakings, crowdfunding service providers, crypto-asset service providers (CASPs) under MiCA, and credit rating agencies. ICT third-party service providers that serve these entities are also subject to DORA's oversight framework when designated as critical by the European Supervisory Authorities (EBA, ESMA, EIOPA).

DORA applies proportionality: microenterprises and small non-complex entities can apply the simplified ICT risk framework under Art. 16 for some Chapter II requirements. However, the incident notification framework (Chapter III) and the third-party risk management contracts (Art. 30) apply to all entities without simplification.

What are the 5 DORA pillars?

  1. ICT Risk Management (Chapter II, Arts. 5–15): A documented ICT risk management framework approved by the management body. Covers asset inventory classified by criticality, information security policy, protection controls (MFA for critical systems, encryption, patch management with SLAs), continuous detection (SIEM), business continuity (BCP/DRP with annually tested RTO/RPO) and at least annual independent review.
  2. ICT Incident Management and Reporting (Chapter III, Arts. 17–23): Register of all ICT incidents, classification of major incidents per RTS criteria, and mandatory reporting to the national supervisor: initial alert within 4 hours, intermediate report within 72 hours, final report within 1 month.
  3. Digital Operational Resilience Testing (Chapter IV, Arts. 24–27): Annual basic testing (vulnerability assessments, penetration tests) for all entities. Systemically important entities identified by supervisors: Threat-Led Penetration Testing (TLPT) every 3 years.
  4. ICT Third-Party Risk Management (Chapter V, Arts. 28–44): Register of all ICT contracts. Mandatory contractual clauses (Art. 30) for providers supporting important or critical functions. Enhanced oversight of ICT third-party providers designated as critical by the ESAs.
  5. Information Sharing Arrangements (Chapter VI, Art. 45): Voluntary participation in sector-level cyber threat intelligence sharing platforms.

What are the DORA incident notification timelines?

Report typeDeadlineContent
Initial alert4 hoursIncident classification, systems affected, initial impact estimate
Intermediate report72 hoursUpdate: provisional root cause, measures taken, updated impact
Final report1 monthPost-incident analysis, definitive root cause, lessons learned, action plan

How does DORA apply proportionality for small fintech firms?

A small payment institution or a crowdfunding platform does not face the same requirements as a systemically important bank. DORA Article 4 establishes the proportionality principle. Article 16 and Delegated Regulation 2024/1773 (RTS on the simplified ICT risk framework) define the conditions under which smaller entities can apply reduced requirements for Chapter II. However, the following apply without simplification to all entities regardless of size: incident classification and reporting (Arts. 17–23), mandatory contractual clauses with ICT providers (Art. 30), and submission of the ICT third-party register to the supervisor (ITS 2024/2956).

Entity typeDORA regimeKey additional obligations
Systemic banks, large insurersFull DORATLPT every 3 years mandatory
Mid-size banks, fund managersFull DORAAnnual basic tests; TLPT if designated
Small fintech, microenterprisesSimplified Art. 16Incident reporting and Art. 30 contracts still mandatory
Critical ICT providers (AWS, Azure)ESA direct oversightOn-site inspections; fines up to €5M/month

How IgeraLegal handles it

Query from a compliance officer at a fintech:

"We are a crowdlending platform supervised by CNMV. Can we use the simplified DORA framework under Art. 16?"

IgeraLegal answers:

"Under DORA Art. 16(1) and Delegated Regulation 2024/1773 (RTS on simplified ICT risk framework), crowdfunding service providers may apply the simplified regime if they qualify as a small non-complex entity per the RTS criteria. However, Arts. 17–23 (incident notification) and Arts. 28–30 (ICT third-party contracts) apply in full without simplification. I can generate the eligibility analysis and the adapted compliance checklist for your entity."

⏱ 3 seconds📄 Source cited: Art. 16 DORA + RTS 2024/1773

Summary: DORA Regulation for financial entities and fintech

  • Applicable from 17 January 2025. EU regulation with direct effect — no national transposition needed.
  • Covers ~22,000 EU financial entities including fintech, CASPs and crowdfunding platforms.
  • 5 pillars: ICT risk management, incident notification, resilience testing, third-party ICT risk and information sharing.
  • Major incidents: 4h initial alert, 72h intermediate report, 1 month final report.
  • Proportionality: small fintech may apply simplified Art. 16 regime for Chapter II only.
  • Sanctions: up to €10M or 2% of global turnover. Personal liability for management body.
  • IgeraLegal generates eligibility analysis, 5-pillar checklists and ICT policy templates.

Frequently asked questions about DORA

Does DORA replace NIS2 for financial entities?

Largely yes. DORA is lex specialis for the financial sector and supersedes NIS2 requirements in the area of digital operational resilience for in-scope entities. NIS2 remains relevant for financial entities that also operate non-financial critical infrastructure or digital services. Entities should check with legal counsel whether their specific activities trigger dual obligations.

When did supervisory inspections under DORA begin?

National competent authorities began DORA supervisory assessments from Q1 2025. Systemically important entities were the first to receive information requests. On-site inspections are expected to materialise during 2026 for entities unable to demonstrate documentary compliance. The EBA, ESMA and EIOPA have published supervisory expectations and Q&A guidance.

How are "major" ICT incidents defined under DORA?

The classification criteria for major incidents are set in the joint EBA/EIOPA/ESMA RTS. They include: number of clients affected, financial impact (direct and indirect losses), duration of service disruption, geographic scope, type and sensitivity of data compromised, and whether a critical service is involved. Entities must document their real-time incident classification process internally.

Can AWS, Azure or Google Cloud be designated as critical ICT providers?

Yes. The ESAs (EBA, ESMA, EIOPA) have the authority to designate ICT third-party service providers as critical (CTPP) if their systemic importance to EU financial markets exceeds certain concentration thresholds. Designated providers are subject to direct ESA oversight, including on-site inspections, and face recurring fines of up to €5 million per month for non-compliance with ESA recommendations.

What are the DORA RTS and why do they matter?

The Regulatory Technical Standards (RTS) are delegated regulations that flesh out DORA's technical requirements. The main ones are: RTS 2024/1774 (ICT risk management tools — asset register fields, patch SLAs, cryptography), RTS 2024/1773 (simplified framework for small entities), and ITS 2024/2956 (standardised templates for the ICT third-party register). They are directly binding and came into force with DORA on 17 January 2025.

How does IgeraLegal support DORA compliance?

IgeraLegal is a RAG compliance assistant that answers DORA questions by citing the exact article of the Regulation and applicable RTS. It generates 5-pillar implementation checklists tailored to entity type and size, ICT risk management policy templates, contractual clause models for ICT providers, and the third-party ICT register in ITS 2024/2956 format. Each answer is delivered in under 5 seconds, with the source article clearly cited.

Is your entity ready for a DORA inspection?

IgeraLegal generates the 5-pillar checklist, ICT policies and third-party register in minutes, citing the exact DORA article.

Try free for 14 days

Published: June 2026 · Sources: Regulation (EU) 2022/2554 (DORA); CDR 2024/1774; CDR 2024/1773; CIR 2024/2956; EBA/ESMA/EIOPA joint RTS on incident classification · Author: Igera Solutions Editorial Team · Not legal advice.

#DORA reglamento 2025#DORA cumplimiento fintech#DORA ICT risk management#DORA notificación incidentes#reglamento UE 2022/2554#DORA entidades financieras España

COMPARTIR

Comparte el conocimiento con tu red