|8 min read|Yvann Lièvre

DORA: What the Financial Sector Needs to Know in 2026

The 5 pillars of the Digital Operational Resilience Act, incident reporting within 4h/72h, and ICT third-party management. A practical DORA compliance guide.

DORAFinance

The Digital Operational Resilience Act (DORA) has been fully applicable since January 17, 2025. Yet in March 2026, many financial entities still struggle to achieve compliance. Early enforcement checks by European authorities reveal critical gaps, particularly in ICT third-party management and incident reporting.

The 5 Pillars of DORA

DORA rests on five fundamental requirements applicable to over 22,000 financial entities across the EU: banks, insurers, asset managers, payment service providers, and their critical ICT suppliers.

1. ICT Risk Management

Every entity must maintain a documented ICT risk management framework, reviewed annually by the management body. This is no longer delegated to IT: the board is directly accountable. The framework must include asset identification, risk classification, and proportionate protection measures.

2. Incident Reporting: The 4h/72h Rule

This is the major friction point. DORA requires an initial notification within 4 hours after classifying a major ICT incident, followed by an intermediate report within 72 hours and a final report within one month. In practice, this means:

  • An automated and tested classification process

  • Pre-filled, legally validated report templates

  • A functional 24/7 escalation chain

  • Regular incident simulation exercises

A tool like ThreatClaw automates detection, classification, and report generation in the format required by supervisory authorities.

3. Digital Operational Resilience Testing

DORA requires threat-led penetration testing (TLPT) every three years for significant entities. These tests must cover critical functions and be conducted by qualified teams. Basic testing (vulnerability scans, scenario testing) is required annually.

4. ICT Third-Party Risk Management

This is the most complex pillar. Every entity must maintain a comprehensive information register of all ICT providers, assess concentration risks, and include specific contractual clauses (audit rights, exit plans, data localization). Critical ICT providers designated by the ESAs are subject to direct oversight.

5. Information Sharing

DORA encourages cyber threat intelligence sharing among financial entities within a trust framework. Sharing arrangements must comply with GDPR and confidentiality rules.

Most Common Mistakes

  • Underestimating ICT third-party scope: cloud, SaaS, third-party APIs, everything is in scope

  • Confusing DORA with NIS2: DORA is the lex specialis for financial services. NIS2 compliance does not equal DORA compliance

  • Insufficient documentation: regulators want evidence, not statements of intent

  • Lack of testing: an untested continuity plan is not a plan

How ThreatClaw Accelerates DORA Compliance

The ThreatClaw platform natively covers several DORA requirements:

  • Continuous monitoring of ICT assets and real-time anomaly detection

  • Automatic classification of incidents per DORA criteria

  • Pre-formatted reports for regulatory reporting

  • ICT dependency mapping to identify concentration risks

Explore our cybersecurity expertise and plans tailored for financial services.

FAQ

Who does DORA apply to?

All regulated financial entities in the EU: banks, insurers, investment firms, payment institutions, and their critical ICT providers.

What is the difference between DORA and NIS2?

DORA is the sector-specific regulation for financial services (lex specialis). NIS2 is broader. Financial entities must comply with DORA, which takes precedence over NIS2 for covered requirements.

What are the penalties for DORA non-compliance?

National authorities can impose administrative sanctions and corrective measures. For critical ICT providers, ESAs can levy periodic penalty payments of up to 1% of average daily worldwide turnover.

How long does it take to become DORA compliant?

For a mid-sized entity, expect 6 to 12 months of full compliance work, depending on existing ICT risk management maturity.

Related articles