DORA: What the Financial Sector Needs to Know in 2026
The 5 pillars of the Digital Operational Resilience Act, incident reporting within 4h/72h, and ICT third-party management. A practical DORA compliance guide.
The Digital Operational Resilience Act (DORA) has been fully applicable since January 17, 2025. Yet in March 2026, many financial entities still struggle to achieve compliance. Early enforcement checks by European authorities reveal critical gaps, particularly in ICT third-party management and incident reporting.
The 5 Pillars of DORA
DORA rests on five fundamental requirements applicable to over 22,000 financial entities across the EU: banks, insurers, asset managers, payment service providers, and their critical ICT suppliers.
1. ICT Risk Management
Every entity must maintain a documented ICT risk management framework, reviewed annually by the management body. This is no longer delegated to IT: the board is directly accountable. The framework must include asset identification, risk classification, and proportionate protection measures.
2. Incident Reporting: The 4h/72h Rule
This is the major friction point. DORA requires an initial notification within 4 hours after classifying a major ICT incident, followed by an intermediate report within 72 hours and a final report within one month. In practice, this means:
-
An automated and tested classification process
-
Pre-filled, legally validated report templates
-
A functional 24/7 escalation chain
-
Regular incident simulation exercises
A tool like ThreatClaw automates detection, classification, and report generation in the format required by supervisory authorities.
3. Digital Operational Resilience Testing
DORA requires threat-led penetration testing (TLPT) every three years for significant entities. These tests must cover critical functions and be conducted by qualified teams. Basic testing (vulnerability scans, scenario testing) is required annually.
4. ICT Third-Party Risk Management
This is the most complex pillar. Every entity must maintain a comprehensive information register of all ICT providers, assess concentration risks, and include specific contractual clauses (audit rights, exit plans, data localization). Critical ICT providers designated by the ESAs are subject to direct oversight.
5. Information Sharing
DORA encourages cyber threat intelligence sharing among financial entities within a trust framework. Sharing arrangements must comply with GDPR and confidentiality rules.
Most Common Mistakes
-
Underestimating ICT third-party scope: cloud, SaaS, third-party APIs, everything is in scope
-
Confusing DORA with NIS2: DORA is the lex specialis for financial services. NIS2 compliance does not equal DORA compliance
-
Insufficient documentation: regulators want evidence, not statements of intent
-
Lack of testing: an untested continuity plan is not a plan
How ThreatClaw Accelerates DORA Compliance
The ThreatClaw platform natively covers several DORA requirements:
-
Continuous monitoring of ICT assets and real-time anomaly detection
-
Automatic classification of incidents per DORA criteria
-
Pre-formatted reports for regulatory reporting
-
ICT dependency mapping to identify concentration risks
Explore our cybersecurity expertise and plans tailored for financial services.
FAQ
Who does DORA apply to?
All regulated financial entities in the EU: banks, insurers, investment firms, payment institutions, and their critical ICT providers.
What is the difference between DORA and NIS2?
DORA is the sector-specific regulation for financial services (lex specialis). NIS2 is broader. Financial entities must comply with DORA, which takes precedence over NIS2 for covered requirements.
What are the penalties for DORA non-compliance?
National authorities can impose administrative sanctions and corrective measures. For critical ICT providers, ESAs can levy periodic penalty payments of up to 1% of average daily worldwide turnover.
How long does it take to become DORA compliant?
For a mid-sized entity, expect 6 to 12 months of full compliance work, depending on existing ICT risk management maturity.
Related articles
We detonated a live Phobos sample. Here is what it does, deleting shadow copies, killing the firewall, and the Sigma rule that catches it, validated across multiple samples with zero false positives.
Emotet, a notorious botnet and malware loader, remains a critical threat to SMBs. Learn how ThreatClaw’s new YARA rules help MSSPs detect and mitigate this persistent adversary.
Drokbk, a remote access trojan, evades defenses with keylogging and screen capture. ThreatClaw now detects it with zero false positives—protect SMBs and MSSP clients.
Dosia malware targets SMBs with obfuscation and tool transfer tactics. Learn how ThreatClaw’s new YARA rules help MSSPs detect and mitigate this threat effectively.