DORA — Digital Operational Resilience Act

DORA, handled by The Agency.

Operational resilience for the EU's most regulated sectors. Five pillars, twenty-four-hour notification windows, regulator-formatted Article 28 reports — all on a continuous loop.

What is DORA?

The Digital Operational Resilience Act is an EU regulation on the operational resilience of the financial sector, in force since 17 January 2025. It applies directly across member states — as a regulation rather than a directive, it is not transposed into national law and does not vary between them — and it covers a wide population of financial entities: banks, insurers, investment firms, payment and e-money institutions, crypto-asset service providers, trading venues and more.

Its premise is that a financial firm's resilience is inseparable from the resilience of its technology suppliers. So alongside obligations on firms, DORA creates an oversight regime for critical ICT third-party service providers, in which designated providers are supervised directly by a Lead Overseer at European level. That is a genuine novelty: the regulator reaches past the regulated firm to the vendor behind it.

The obligations sit across five pillars — ICT risk management, incident reporting, resilience testing, third-party risk, and information sharing. For third-party risk specifically, Article 28 is the load-bearing one: a register of information covering every ICT contractual arrangement, specified contract terms, pre-contractual due diligence, concentration risk assessment and documented exit strategies for anything supporting a critical or important function.

The numbers your team already knows.

DORA isn't an annual audit. It's a continuous obligation across five pillars, with statutory windows the regulator measures in hours. Spreadsheets won't make the deadline.

5 pillars
Risk management, incident reporting, resilience testing, third-party risk, threat-intel sharing
DORA scope
24 hrs
Initial-notification window for major ICT-related incidents
DORA Article 19
Article 28
Third-party register and oversight obligations
Continuous, not annual

TARA, VANCE, REX — your DORA backbone.

Three of The Agency's leads cover the full DORA loop: gap analysis against the five pillars, regulator-formatted reporting, and the continuous monitoring that keeps the 24-hour incident window from being a fire drill.

TARA avatar
TARA
Compliance & Remediation

DORA five-pillar gap analysis on a rolling basis. TARA continuously assesses every vendor's posture against the DORA pillars — and assigns SLA-bound remediation when material gaps surface.

What you get
  • DORA five-pillar continuous gap analysis
  • Critical / High / Medium / Low vendor tiering
  • SLA-driven remediation, escalations on miss
VANCE avatar
VANCE
Regulatory Reporting

Article 28 packs composed from live data. VANCE generates DORA-aligned third-party registers, material-incident reports and board-pack summaries — formatted for the regulator, evidence linked.

What you get
  • Article 28 third-party register, kept current
  • Major ICT-incident reports composed in minutes
  • Tamper-evident audit trail per output
REX avatar
REX
Outside-In & Incident Intelligence

Material incident detection in hours, not at the next audit. REX continuously monitors every vendor's posture and surfaces material change in time for the 24-hour notification window to be met.

What you get
  • Continuous monitoring across 5M+ companies
  • Material-change detection in hours
  • Concentration risk visible across the third-party portfolio

Four shifts you'll feel at the next reporting cycle.

DORA stops being a quarterly assembly project and becomes a continuous evidence layer the regulator can drop in on at any time.

Article 28 register stays current

The third-party register reflects today's contracts, today's critical operations and today's concentration risk — not last quarter's.

Five-pillar gap analysis runs continuously

TARA assesses every material vendor against all five DORA pillars on a rolling basis. Drift surfaces the week it happens.

24-hour incident window is achievable

REX detects material change continuously, VANCE drafts the Article 19 notification — your team reviews and submits, not assembles from scratch.

Concentration risk visible across the portfolio

See exposure to systemically important third parties at a glance. The DORA-driven question your board will ask, already answered.

DORA reporting that used to take a quarter now takes a morning. VANCE produced our first board pack in under an hour.

DK
Operational Risk Director
European Asset Manager

What risk teams ask about DORA.

The questions that come up most often in DORA conversations — what the regulation requires, who it reaches, and what changes operationally.

What is DORA and when did it start to apply?
The Digital Operational Resilience Act is an EU regulation that has applied since 17 January 2025. It covers financial entities — banks, insurers, investment firms, payment institutions and others — and, through a separate oversight regime, the ICT providers those entities depend on. Its purpose is to make firms able to withstand, respond to and recover from ICT disruption, rather than merely to document that they have thought about it.
What are the five pillars of DORA?
ICT risk management (a governed framework for identifying and controlling ICT risk); ICT-related incident reporting (classifying and notifying major incidents within statutory windows); digital operational resilience testing (regular testing, including threat-led penetration testing for larger entities); ICT third-party risk management (Article 28 — the register of information, contractual requirements and exit strategies); and information sharing (voluntary exchange of cyber threat intelligence between entities.)
What counts as a major ICT-related incident?
One with a high adverse impact on the network and information systems supportingcritical or important functions. Classification runs on criteria set out in DORA and its technical standards — clients and financial counterparts affected, duration, geographic spread, data losses, economic impact and the criticality of the services hit. The judgement that matters in practice is whether a function is critical or important, because that is what pulls an incident into the reporting regime and its Article 19 windows.
What does DORA require for third-party ICT risk?
Article 28 requires a register of information covering all contractual arrangements for ICT services, maintained at entity, sub-consolidated and consolidated level, and supplied to the regulator on request. Contracts have to carry specified provisions — access, audit and inspection rights, service levels, incident cooperation, and exit. Entities must run pre-contractual due diligence, keep arrangements under review, and hold documented exit strategies for arrangements supporting critical or important functions. Concentration risk has to be assessed, not just recorded.
What are the penalties for DORA non-compliance?
They work differently for the two populations DORA reaches, and the distinction is routinely misreported. For financial entities, DORA leaves administrative penalties to member states under Article 50, so the amounts are set nationally rather than by a single EU-wide figure; competent authorities can also order conduct to cease and require remedial action. For critical ICT third-party service providers, the Lead Overseer may impose periodic penalty payments of 1% of average daily worldwide turnover from the preceding business year, charged for each day of non-compliance for up to six months. The widely quoted "1% of annual turnover" merges the two regimes: the 1% is a daily measure applied to designated providers, not an annual fine on financial entities.
How does RiskXchange help with DORA?
Across the three pillars where third-party risk actually sits. TARA runs continuous gap analysis against the five pillars and assigns SLA-bound remediation when material gaps appear. VANCE composes the Article 28 register and regulator-formatted incident and board reporting from live data rather than from a quarterly assembly exercise. REX monitors vendor posture continuously, so material change surfaces while the Article 19 notification window is still open. What it does not do is make the resilience-testing or information-sharing pillars someone else's problem — those stay with your own programme.

See it on your vendors.

Book a 30-minute call and we'll have NOVA, ARIA and REX produce a complete posture report on one of your live vendors inside 24 hours.