Skip to content

What DORA is and who must comply in the financial sector

The Digital Operational Resilience Act (EU Regulation 2022/2554), applicable from 17 January 2025, imposes a harmonised ICT risk-management framework on EU financial entities: banks, insurers, asset managers, financial market infrastructures and critical third-party ICT service providers.

Unlike NIS2, which covers critical sectors in general, DORA is specific to the digital operational resilience of the financial sector: it requires an ICT risk-management framework, digital operational resilience testing (including Threat-Led Penetration Testing for the most significant entities), incident management and monitoring of critical third-party providers.

Reporting obligations are strict: major ICT incidents must be reported with an initial notification, intermediate updates and a final report within defined timeframes to the competent authorities (e.g. Banca d'Italia, Consob in Italy), in a way similar to, but not identical to, the NIS2 mechanism.

Although designed for finance, DORA touches mixed IT/OT technology infrastructure wherever critical ICT systems interact with operational environments - data centres, physical payment systems, connected physical-security infrastructure - where the continuous monitoring and asset visibility required by the regulation extend to components not traditionally considered IT.

07FINANCE · EU · INFRASTRUCTURE

DORA

Digital Operational Resilience Act (EU Reg. 2022/2554)

EU regulation applicable from 17/01/2025 to financial entities (banks, insurance, payment, crypto, fund management) and their critical ICT suppliers. Also affects OT operators providing services to these entities or running data centres / technology infrastructure supporting them.

Key requirements
  • 01Integrated and documented ICT risk management framework
  • 02Incident reporting to competent authorities
  • 03Digital operational resilience testing (including threat-led penetration testing)
  • 04Third-party ICT risk management (TPRM)
  • 05Information sharing on cyber threat intelligence
How MON5 helps

For financial entities with technology infrastructure and data centres, and for ICT suppliers operating across mixed IT/OT environments, MON5 provides continuous network monitoring, asset inventory and anomaly detection - feeding the ICT risk management framework and the incident reporting required by DORA.

  • Continuous monitoring for ICT risk management
  • Asset inventory for TPRM on supplied systems
  • Event detection supporting incident reporting
  • Technical evidence for resilience testing
  • Audit trail reusable for supervisory authorities
Key terms
Financial entity
DORA's subjective scope: banks, insurance and reinsurance undertakings, fund managers, investment firms, market infrastructures and other regulated categories listed in the regulation.
Critical third-party ICT service provider
External provider (e.g. a cloud provider) whose disruption would have a significant impact on financial stability; DORA introduces direct EU oversight of these providers when designated "critical".
TLPT (Threat-Led Penetration Testing)
Advanced penetration test based on realistic threat scenarios, required of the most significant financial entities at least every three years to validate operational resilience.
Register of Information
Document that financial entities must maintain and report to authorities, detailing all ICT contractual arrangements with third-party providers.
ICT risk-management framework
The set of policies, procedures and tools required by DORA to identify, protect, detect, respond to and recover from ICT incidents, partly mirroring the structure of the NIST CSF.
Major ICT incident
Event that exceeds predefined impact thresholds (users affected, duration, geographic spread, economic loss) and triggers the obligation to notify competent authorities within DORA's timeframes.
Frequently asked questions
Does DORA apply only to banks or also to IT/OT infrastructure?+

DORA applies to all EU-regulated financial entities: banks, insurers, asset managers, financial market infrastructures and critical ICT providers, including those with mixed IT/OT environments.

What are DORA's technical requirements for continuous monitoring?+

DORA requires continuous monitoring of ICT networks and systems, anomaly detection, digital operational resilience testing (TLPT), incident management and mandatory reporting to competent authorities.

Does MON5 support the ICT risk management framework required by DORA?+

Yes. MON5 provides asset inventory, anomaly detection and network logs for IT/OT environments, producing the technical evidence needed for DORA's ICT risk management framework and resilience testing.

When does DORA apply from?+

From 17 January 2025, the date from which financial entities must be fully compliant with the regulation's obligations.

What happens if a financial entity fails to comply with DORA?+

Penalties are defined by member states and can include administrative fines, corrective measures imposed by supervisory authorities and, in the most serious cases, operational restrictions.

Do DORA and NIS2 overlap?+

Partially. Financial entities regulated by DORA are generally excluded from NIS2's scope to avoid double regulation, since DORA acts as lex specialis for the financial sector on ICT resilience.

What are the digital operational resilience tests required by DORA?+

A testing programme ranging from vulnerability assessments and security scans up to Threat-Led Penetration Testing for the most significant entities, aimed at concretely validating the ability to withstand and recover from an attack.

Does MON5 support the third-party ICT provider oversight required by DORA?+

MON5 provides visibility into assets and network traffic involving systems and components supplied by third parties, contributing technical evidence to concentration-risk monitoring and the due diligence required by the regulation, alongside contractual and governance processes.

READY FOR THE AUDIT?

Let's figure out what you really need.

Show us the OT perimeter and the regulations you need to cover: we will tell you what MON5 documents directly, where complementary work is needed, and which tier to start from - no hard selling.

MON5.EU

OT (Operational Technology) cybersecurity for manufacturing plants. Map, identify, monitor and protect your industrial network.

🇮🇹MON5 S.R.L. · Italy
Bologna · Via Paolo Nanni Costa 20
Faenza · Corso Aurelio Saffi 21
VAT IT02725300392
🇱🇺AARG S.à.r.l. · Luxembourg
49, Boulevard Royal
L-2449 Luxembourg
VAT LU35998569
© 2026 MON5 · All rights reserved
Get certifications
Coesione Italia 21-27 Emilia-Romagna · Co-funded by the European Union · Ministero delle Imprese · Regione Emilia-Romagna