Skip to content
Säkerhet

What is DORA?

The EU's digital resilience test for financial services. Not the explorer — the rules that stop banks and fintech from collapsing when IT fails.

DORA stands for the Digital Operational Resilience Act — an EU regulation (an EU law that applies directly in all member states without first being transposed into national law) for the financial sector. "Resilience" means the ability to stay standing when something breaks. Think of it as a stress test, but for IT systems instead of the economy.

The background is simple: banks, insurers and payment services are effectively IT companies now. If their systems go down, you cannot pay, withdraw cash or run your business. DORA says financial firms must be able to withstand, handle and recover from IT disruptions and cyber attacks — not just hope it never happens.

DORA sets requirements for risk management, testing, incident reporting and oversight of third-party suppliers (for example cloud services and IT consultants). That last part is interesting: even if you are not a bank, you may be covered if you deliver critical IT services to the financial sector.

Why does DORA matter for your business?

If you are in financial services, DORA is not optional — it is law. But even if you are a technology supplier selling to banks or fintech, your customers may require you to meet DORA's requirements, because you become part of their risk chain.

The upside of working resiliently is that your business becomes more reliable. Customers trust companies that do not suddenly stop working, and being able to say "we stay up even when it storms" is a competitive advantage.

DORA in practice

Imagine a fintech offering a payment app. Under DORA they must regularly test how the system handles an attack, have a clear plan for what happens if their cloud provider goes down, and quickly report serious IT incidents to the financial regulator.

If you are the IT agency that built the app, you may get asked: how do you make sure your part is not the weak link? Having proper routines, backups and an incident plan makes you a supplier financial firms are willing to bet on.

Common questions about DORA

What does DORA mean?

DORA (Digital Operational Resilience Act) is an EU regulation requiring financial firms to withstand, handle and recover from IT disruptions and cyber attacks. The goal is to stop the financial sector collapsing when technology fails.

Who is covered by DORA?

DORA applies to banks, insurers, payment services and other financial firms in the EU. Critical IT and cloud suppliers to the financial sector may also be covered by the requirements.

What is the difference between DORA and NIS2?

DORA is specialised rules for financial services, while NIS2 is broader and covers many sectors vital to society. For financial firms, DORA generally takes precedence as the more specific law.

Related terms

← Full glossary