DORA and Your Company: Everything You Need to Know About the New Legislation

6. 6. 2023 | 5 min read | author: Karolína Kubínová

Imagine a future where the financial sector is safe from cyber threats and breaches. Customer data is carefully protected, and the entire industry operates with unshakeable resilience. DORA, with its comprehensive framework of standards and processes, strives to turn this vision into a reality. It aims to ensure a consistent approach to digital resilience and to give the financial sector the best possible protection.

In this article, we bring you more information about DORA. You will learn what exactly DORA entails, what its objectives are, the possible consequences of non-compliance, the key requirements it involves, and, last but not least, which sectors are affected by the regulation.

Karolína Kubínová works at axelum as a Security Analyst specializing in preparing companies for security certifications, conducting internal audits and improving security processes (mainly based on ISO 27K, KB Act and best practices). She also works on social engineering, especially phishing and vishing campaigns, and security awareness.

What does DORA actually mean?

DORA, or the Digital Operational Resilience Act, is a new piece of legislation from the European Commission. Its purpose is to increase cyber security and operational resilience in financial services in the European Union. The regulation responds to the growing threat of cyber-attacks, data leaks, and other digital security risks facing the industry.

The DORA initiative seeks to create a unified approach to digital resilience in the financial sector through a comprehensive framework of standards and processes. At the same time, it strengthens the resilience of digital operations in the industry through increased supervisory powers and direct control capabilities.

Why is DORA important?

And what happens if you do not comply with DORA? In the event of non-compliance, the authority can impose daily fines for up to 6 months. The daily rate is 1 % of the average daily worldwide turnover of the provider.

When will DORA become effective?

DORA entered into force on January 16, 2023. However, please note in your calendar that it will not become effective until January 17, 2025. We encourage you to act as soon as possible and start preparing to meet this deadline. At axelum, we can help you with this!

What are the main requirements of DORA?

Governance: DORA highlights the importance of the direct involvement of the governing body in the ICT risk management process, as well as in regular training. In addition, a security awareness programme should be fully implemented for all employees.

Risk Management: The Regulation requires an ICT risk management framework, including a digital operational resilience plan, to be establishing and maintaining.

Intelligence Sharing: DORA promotes the sharing of threat intelligence in the financial industry, recognising that many cyber threat actors target multiple organisations simultaneously. By facilitating intelligence sharing, DORA enhances the industry's awareness of ongoing cyber threats and helps improve its preparedness to address them.

Incident Reporting: DORA requires the establishment of a process for tracking, recording, and classifying incidents to enable firms to monitor and respond to potential cyber threats and other operational disruptions effectively. To promote transparency and accountability, DORA mandates the reporting of serious incidents to supervisory authorities and, in certain cases, to clients to ensure that all relevant parties are aware of potential risks and can take appropriate measures to address them.

Resilience Testing: DORA requires firms to test assets and functions regularly to identify potential weaknesses and gaps to ensure they can respond effectively to potential cyber threats and other disruptions. To enhance the resilience of larger and more significant entities, DORA mandates regular advanced testing (not applicable to micro-businesses).

Audit Access: DORA enables regulators (and financial institutions in the case of suppliers) to conduct audits throughout the financial industry's supply chain, promoting compliance with regulatory requirements. As a result, organisations must be able to generate reports on demand to facilitate audit access and ensure compliance with the regulation.

Third Parties: DORA requires firms to establish principles for selecting third-party ICT service providers to ensure they meet appropriate standards for digital operational resilience and minimise potential risks to their operations. To promote effective oversight of third-party ICT service providers, DORA mandates the establishment of minimum requirements for relevant contractual arrangements.

What sectors are affected by DORA?

getData?accessKey=66e3fa38c06ce05d38980e94e36f18d6.29435661.276b26f8c2f74cc3a9beb3dbb56589c42de3ed6d&clientAwid=815aa54079914c30ac2c132ae7c1e23f&dataKey=prod2-small_Creditinstitutions
Credit institutions
getData?accessKey=66e3fa38c06ce05d38980e94e36f18d6.29435661.276b26f8c2f74cc3a9beb3dbb56589c42de3ed6d&clientAwid=815aa54079914c30ac2c132ae7c1e23f&dataKey=prod2-small_Paymentinstitutions
Payment institutions
getData?accessKey=66e3fa38c06ce05d38980e94e36f18d6.29435661.276b26f8c2f74cc3a9beb3dbb56589c42de3ed6d&clientAwid=815aa54079914c30ac2c132ae7c1e23f&dataKey=prod2-small_Accountinformationserviceproviders
Account information service providers
getData?accessKey=66e3fa38c06ce05d38980e94e36f18d6.29435661.276b26f8c2f74cc3a9beb3dbb56589c42de3ed6d&clientAwid=815aa54079914c30ac2c132ae7c1e23f&dataKey=prod2-small_Electronicmoneyinstitutions
Electronic money institutions
getData?accessKey=66e3fa38c06ce05d38980e94e36f18d6.29435661.276b26f8c2f74cc3a9beb3dbb56589c42de3ed6d&clientAwid=815aa54079914c30ac2c132ae7c1e23f&dataKey=prod2-small_Investmentfirms
Investment firms
getData?accessKey=66e3fa38c06ce05d38980e94e36f18d6.29435661.276b26f8c2f74cc3a9beb3dbb56589c42de3ed6d&clientAwid=815aa54079914c30ac2c132ae7c1e23f&dataKey=prod2-small_Serviceprovidersrelatedtocryptoassets
Service providers related to crypto-assets
getData?accessKey=66e3fa38c06ce05d38980e94e36f18d6.29435661.276b26f8c2f74cc3a9beb3dbb56589c42de3ed6d&clientAwid=815aa54079914c30ac2c132ae7c1e23f&dataKey=prod2-small_Centralsecuritiesdepositories
Central securities depositories
getData?accessKey=66e3fa38c06ce05d38980e94e36f18d6.29435661.276b26f8c2f74cc3a9beb3dbb56589c42de3ed6d&clientAwid=815aa54079914c30ac2c132ae7c1e23f&dataKey=prod2-small_Centralcounterparties
Central counterparties
getData?accessKey=66e3fa38c06ce05d38980e94e36f18d6.29435661.276b26f8c2f74cc3a9beb3dbb56589c42de3ed6d&clientAwid=815aa54079914c30ac2c132ae7c1e23f&dataKey=prod2-small_Tradingvenues
Trading venues
getData?accessKey=66e3fa38c06ce05d38980e94e36f18d6.29435661.276b26f8c2f74cc3a9beb3dbb56589c42de3ed6d&clientAwid=815aa54079914c30ac2c132ae7c1e23f&dataKey=prod2-small_Traderepositories
Trade repositories
getData?accessKey=66e3fa38c06ce05d38980e94e36f18d6.29435661.276b26f8c2f74cc3a9beb3dbb56589c42de3ed6d&clientAwid=815aa54079914c30ac2c132ae7c1e23f&dataKey=prod2-small_Managersofalternativeinvestmentfunds
Managers of alternative investment funds
getData?accessKey=66e3fa38c06ce05d38980e94e36f18d6.29435661.276b26f8c2f74cc3a9beb3dbb56589c42de3ed6d&clientAwid=815aa54079914c30ac2c132ae7c1e23f&dataKey=prod2-small_Managementcompanies
Management companies
getData?accessKey=66e3fa38c06ce05d38980e94e36f18d6.29435661.276b26f8c2f74cc3a9beb3dbb56589c42de3ed6d&clientAwid=815aa54079914c30ac2c132ae7c1e23f&dataKey=prod2-small_Datareportingserviceproviders
Data reporting service providers
getData?accessKey=66e3fa38c06ce05d38980e94e36f18d6.29435661.276b26f8c2f74cc3a9beb3dbb56589c42de3ed6d&clientAwid=815aa54079914c30ac2c132ae7c1e23f&dataKey=prod2-small_Insuranceandreinsuranceundertakings
Insurance and reinsurance undertakings
getData?accessKey=66e3fa38c06ce05d38980e94e36f18d6.29435661.276b26f8c2f74cc3a9beb3dbb56589c42de3ed6d&clientAwid=815aa54079914c30ac2c132ae7c1e23f&dataKey=prod2-small_Insuranceintermediaries
Insurance intermediaries, reinsurance intermediaries and ancillary insurance intermediaries
getData?accessKey=66e3fa38c06ce05d38980e94e36f18d6.29435661.276b26f8c2f74cc3a9beb3dbb56589c42de3ed6d&clientAwid=815aa54079914c30ac2c132ae7c1e23f&dataKey=prod2-small_Institutionsforoccupationalretirementprovision
Institutions for occupational retirement provision
getData?accessKey=66e3fa38c06ce05d38980e94e36f18d6.29435661.276b26f8c2f74cc3a9beb3dbb56589c42de3ed6d&clientAwid=815aa54079914c30ac2c132ae7c1e23f&dataKey=prod2-small_Creditratingagencies
Credit rating agencies
getData?accessKey=66e3fa38c06ce05d38980e94e36f18d6.29435661.276b26f8c2f74cc3a9beb3dbb56589c42de3ed6d&clientAwid=815aa54079914c30ac2c132ae7c1e23f&dataKey=prod2-small_Administratorsofcriticalbenchmarks
Administrators of critical benchmarks
getData?accessKey=66e3fa38c06ce05d38980e94e36f18d6.29435661.276b26f8c2f74cc3a9beb3dbb56589c42de3ed6d&clientAwid=815aa54079914c30ac2c132ae7c1e23f&dataKey=prod2-small_Crowdfundingserviceproviders
Crowdfunding service providers
getData?accessKey=66e3fa38c06ce05d38980e94e36f18d6.29435661.276b26f8c2f74cc3a9beb3dbb56589c42de3ed6d&clientAwid=815aa54079914c30ac2c132ae7c1e23f&dataKey=prod2-small_Securitisationrepositories
Securitisation repositories

What sectors are excluded from DORA?

  • Managers of alternative investment funds as referred to in Article 3(2) of Directive 2011/61/EU
  • Insurance and reinsurance undertakings as referred to in Article 4 of Directive 2009/138/EC
  • Institutions for occupational retirement provision which operate pension schemes which together do not have more than 15 members in total
  • Natural or legal persons exempted pursuant to Articles 2 and 3 of Directive 2014/65/EU
  • Insurance intermediaries, reinsurance intermediaries, and ancillary insurance intermediaries, which are microenterprises or small or medium-sized enterprises
  • Post office giro institutions as referred to in Article 2(5), point (3), of Directive 2013/36/EU


Adapt to DORA Easily with Our Experts

Count on us as your trusted guide in navigating the changes that the DORA regulations bring. We empower your financial business with deep expertise and knowledge of the new regulation, ensuring you can overcome challenges and seize opportunities.

Right in Your Inbox

Stay up to date and get the newsletter. Every month, you can look forward to exclusive educational content and news from the infosec world.

Info
Zabýváme se informační bezpečností. Naším cílem je zabezpečit nejcennější informace klientů, a tím chránit jejich podnikání.

© 2026 Axelum s.r.o.

Kontakt

Axelum s.r.o.

IČO: 25639056

DIČ: CZ699004029

V Kapslovně 2767/2

130 00 Prague CZ

info@axelum.eu

+420 221 400 111


Vytvořeno pomocí uuWebKit
document_check.svg
Na těchto webových stránkách používáme soubory cookies k zajištění jejich funkčnosti a dále k personalizaci reklam, a to výhradně s vaším souhlasem a v souladu s našimi Pravidly pro užívání cookies.

Kliknutím na tlačítko „Přijmout soubory cookies“ udělujete souhlas s využívaním vybraných souborů cookies a souhlasíte s předáním údajů o chování na našich webových stránkách pro zobrazení cílené reklamy na sociálních a reklamních sítích. Můžete si zvolit, které informace s námi chcete sdílet kliknutím na tlačítko Nastavení cookies.