Quick answer
DORA (the Digital Operational Resilience Act) is the EU regulation requiring financial entities to withstand, respond to, and recover from ICT disruptions. It's been in force since January 2025 and covers banks, insurers, investment firms, payment institutions, and crypto providers, plus, decisively, their ICT third-party providers. If you sell technology services to European financial companies, DORA reaches you through their contracts even though you're not a financial entity yourself.
The five pillars
- ICT risk management: a documented framework, board-owned, covering identification, protection, detection, response, and recovery.
- Incident management and reporting: classifying ICT incidents and reporting major ones to supervisors on strict timelines.
- Digital operational resilience testing: regular testing of critical systems, up to threat-led penetration testing for significant entities.
- ICT third-party risk: the pillar with supply chain teeth. Financial entities must maintain a register of information on all ICT contracts, impose contractual provisions on providers, and manage concentration risk. Critical providers face direct EU oversight.
- Information sharing on threats, voluntary but encouraged.
What it means for tech vendors
Your financial-sector customers are now obligated to demand things from you: specific contract clauses (audit rights, exit strategies, incident notification duties), entries in their ICT register, evidence of your resilience, and participation in their testing. Expect due-diligence questionnaires that reference DORA articles, renegotiated contracts, and recurring evidence requests. Vendors that answer with a maintained compliance posture keep the deals; see the SaaS-to-enterprise pattern.
How DORA relates to NIS 2
The two arrived together and overlap in spirit: NIS 2 covers critical sectors broadly, DORA is the financial sector's stricter, more specific regime (and takes precedence there). For a tech provider serving both worlds, the efficient answer is one control set cross-mapped to both, with the DORA-specific artifacts (contract register support, resilience testing evidence) layered on top; see how OptiTech does it.

Get a personalized walkthrough of automated compliance for your team. No commitment required.