Frameworks / EU
DORA
DORA is the EU regulation that makes digital operational resilience a supervised obligation for the financial sector. It reaches directly into the technology vendors that financial entities depend on, including those outside the EU.
What it requires
DORA has applied since 17 January 2025 and rests on five pillars. First, ICT risk management: a documented framework owned and approved by the management body, which is explicitly accountable. Second, ICT-related incident management: classification of incidents against defined criteria and reporting of major incidents to the competent authority on a staged timetable (an initial notification, an intermediate report and a final report). Third, digital operational resilience testing: a programme of testing proportionate to the entity, with advanced threat-led penetration testing (TLPT, modelled on the TIBER-EU framework) required for entities identified as significant. Fourth, ICT third-party risk management: contractual requirements for ICT service contracts, a maintained register of information on all contractual arrangements with ICT third-party providers, and an EU-level oversight regime for those designated as critical ICT third-party providers. Fifth, information and intelligence sharing on cyber threats, which is voluntary. DORA is supplemented by Regulatory and Implementing Technical Standards developed by the European Supervisory Authorities, which carry much of the operational detail.
DORA applies to a broad list of EU financial entities (banks, payment and e-money institutions, investment firms, insurers and intermediaries, crypto-asset service providers, trading venues, fund managers and more) and to ICT third-party service providers serving them. For Israeli companies the exposure is nearly always as a vendor: if you provide software, cloud, data or managed services to an EU financial entity, DORA obligations arrive through your contract, which must now contain specific terms on access, audit rights, subcontracting, exit strategies and incident cooperation. The trigger is a European bank or insurer sending a DORA contractual addendum and a supplier questionnaire your sales team cannot answer.
The controls people actually fail
- The register of information on ICT third-party arrangements is incomplete or built as a one-off spreadsheet: missing subcontractors, missing which contracts support critical or important functions, and immediately stale.
- Contracts with ICT providers lack the mandatory DORA terms: no audit and access rights, no defined exit and transition plan, no clarity on subcontracting of critical functions.
- No mapping of which ICT services actually support critical or important functions, which makes every downstream requirement (testing, reporting, exit planning) impossible to scope.
- Incident classification criteria are not implemented operationally, so nobody can decide within hours whether an incident is "major" and the reporting clock is missed.
- The resilience testing programme is an annual penetration test with no relationship to the entity's critical functions, and no scenario-based or threat-led testing where required.
- The management body has formally approved the ICT risk framework but receives no ongoing reporting, and cannot demonstrate the active oversight DORA requires of it.
- Exit strategies exist as a paragraph in a policy, with no tested plan for actually moving off a critical provider.
When did DORA come into force?
Regulation (EU) 2022/2554 entered into force in January 2023 and has applied since 17 January 2025. Because it is a regulation rather than a directive, it applies directly across all EU member states without needing national transposition, and its detailed operational requirements are set out in accompanying Regulatory and Implementing Technical Standards from the European Supervisory Authorities.
Does DORA apply to us if we are just a software vendor to a European bank?
Effectively, yes: through the contract. DORA imposes obligations on financial entities regarding their ICT third-party providers, which means your customer must now include specific contractual terms (audit and access rights, subcontracting conditions, exit and termination provisions, incident cooperation, service level requirements for critical or important functions) and must list you in its register of information. Separately, providers designated as critical ICT third-party providers fall under direct EU-level oversight by the European Supervisory Authorities: that designation applies to a small number of large providers, but the contractual pass-through reaches every vendor.
What are DORA's incident reporting requirements?
Financial entities must classify ICT-related incidents against criteria set out in the regulation and its technical standards, and must report major incidents to their competent authority in stages: an initial notification, an intermediate report as the situation develops, and a final report once root cause and remediation are established. The specific deadlines for each stage are fixed in the technical standards. The practical consequence is that classification must be an operational capability: a decision you can make quickly, with evidence, not a judgement made after the fact.
What is threat-led penetration testing (TLPT) under DORA?
TLPT is advanced, intelligence-led red teaming against an entity's live production systems, modelled on the TIBER-EU framework: threat intelligence is used to build realistic adversary scenarios, which a testing team then executes against the entity's critical or important functions. DORA requires it only of financial entities identified by their competent authorities as significant, on a defined cycle, and it is materially different from a standard annual penetration test: it targets the business functions that matter, uses real threat intelligence, and is conducted under supervisory oversight.