What is DORA?
The EU's digital resilience test for financial services. Not the explorer — the rules that stop banks and fintech from collapsing when IT fails.
DORA stands for the Digital Operational Resilience Act — an EU regulation (an EU law that applies directly in all member states without first being transposed into national law) for the financial sector. "Resilience" means the ability to stay standing when something breaks. Think of it as a stress test, but for IT systems instead of the economy.
The background is simple: banks, insurers and payment services are effectively IT companies now. If their systems go down, you cannot pay, withdraw cash or run your business. DORA says financial firms must be able to withstand, handle and recover from IT disruptions and cyber attacks — not just hope it never happens.
DORA sets requirements for risk management, testing, incident reporting and oversight of third-party suppliers (for example cloud services and IT consultants). That last part is interesting: even if you are not a bank, you may be covered if you deliver critical IT services to the financial sector.
Why does DORA matter for your business?
If you are in financial services, DORA is not optional — it is law. But even if you are a technology supplier selling to banks or fintech, your customers may require you to meet DORA's requirements, because you become part of their risk chain.
The upside of working resiliently is that your business becomes more reliable. Customers trust companies that do not suddenly stop working, and being able to say "we stay up even when it storms" is a competitive advantage.
DORA in practice
Imagine a fintech offering a payment app. Under DORA they must regularly test how the system handles an attack, have a clear plan for what happens if their cloud provider goes down, and quickly report serious IT incidents to the financial regulator.
If you are the IT agency that built the app, you may get asked: how do you make sure your part is not the weak link? Having proper routines, backups and an incident plan makes you a supplier financial firms are willing to bet on.
Common questions about DORA
What does DORA mean?
DORA (Digital Operational Resilience Act) is an EU regulation requiring financial firms to withstand, handle and recover from IT disruptions and cyber attacks. The goal is to stop the financial sector collapsing when technology fails.
Who is covered by DORA?
DORA applies to banks, insurers, payment services and other financial firms in the EU. Critical IT and cloud suppliers to the financial sector may also be covered by the requirements.
What is the difference between DORA and NIS2?
DORA is specialised rules for financial services, while NIS2 is broader and covers many sectors vital to society. For financial firms, DORA generally takes precedence as the more specific law.
Related terms
2FA / MFA
Two-factor or multi-factor authentication. Password plus SMS code or app. Stops most account takeovers. Turn it on. Now.
Data Breach
When the wrong person gets access to the right data. Like someone unauthorised walking into your archive — except you never hear the door.
End-to-End Encryption
Data is encrypted at the sender and only decrypted at the recipient. Middlemen only see unreadable text.
EU Hosting
Keeping your data in Europe. Like choosing a storage unit in the neighbourhood instead of one in a country whose rules you do not know.
NIS2
The EU's updated cyber security rules that say "raise your game — or else". Forces thousands of businesses to take security seriously, with fines as the wake-up call.
OWASP Top 10
The list of the 10 most dangerous security threats to web apps. We check every project against it.