What is DORA and who does it really affect?
EU regulation on financial-sector digital resilience, applicable since 17 January 2025: it covers ICT suppliers too, not only banks.
DORA (Digital Operational Resilience Act, EU Regulation 2022/2554) is the rule requiring banks, insurers and other financial entities to ensure their digital operational resilience: ICT risk management, resilience testing, incident handling and oversight of third-party providers. It has been applicable since 17 January 2025 and, unlike many EU rules, it does not only concern entities supervised by a national or European regulator. The regulation was written to replace the fragmented way the financial sector used to handle cybersecurity, often leaving it up to each institution to decide whether and how to include suppliers in risk assessment: DORA makes this mandatory across the European Union, setting common testing standards, including advanced penetration testing (TLPT) for the most critical entities, and requiring banks and insurers to map the chain of ICT providers they depend on. For anyone working with financial clients, this translates into concrete contractual obligations on audits, incident notification and service continuity, not just an administrative box for the regulated client to tick.
The side people forget: suppliers
DORA classifies ICT providers serving the financial sector as part of the resilience chain to be governed: system integrators, software houses, MSPs, and anyone building data or AI platforms for banks and insurers falls within the contractual perimeter, with mandatory clauses on audit rights, subcontracting, exit strategy and incident notification. If you work with financial clients, DORA is not "their problem": it lands on you through the contract, often without the supplier noticing until they sign an annex with obligations that were not there before.
The penalties and what changes in practice
Legislative Decree 23/2025, which transposes it in Italy, sets penalties of up to 10% of turnover for some categories of entity in the most serious violations, plus sanctions for the responsible individuals. In practice, anyone providing digital services to the financial sector must be able to demonstrate: ICT risk mapping, tested continuity plans, incident traceability and the ability to respond to a regulated client's audit requests. It is not abstract paperwork: it is the same data governance and observability discipline you need anyway to run your systems well, made contractually binding.
This entry is informational and does not constitute legal advice: for contractual and regulatory compliance, involve your legal counsel or the client's compliance officer.
Related terms
- NIS2 · The EU cybersecurity directive, in Italy D.Lgs. 138/2024: staged obligations run by ACN for companies from 50 employees upwards.
- BCBS 239 · Basel Committee standard on risk data aggregation, now an ECB supervisory expectation via the RDARR guide.
- Data governance · The rules, roles and processes that make company data reliable, secure and usable: who can do what, on which data, at what quality.
- CLOUD Act · US law compelling American providers to hand over data under US legal orders, even when it is stored in Europe.
A term that hits close to home? Let's talk.
CONTACT ME