FINANCIAL SERVICES
What Is DORA (EU Digital Operational Resilience Act)?
DEFINITION
DORA (the EU Digital Operational Resilience Act) is the European Union regulation that requires financial entities to manage ICT risk, report major incidents, test digital resilience, and govern third-party technology providers under mandatory contractual terms. It has applied since January 17, 2025, and reaches US and other non-EU vendors through contract requirements flowed down by their EU financial clients.
DORA harmonizes digital resilience requirements across the EU financial sector. It rests on five pillars: ICT risk management with clear board accountability, classification and reporting of major ICT incidents to regulators, digital operational resilience testing that scales up to threat-led penetration testing for significant entities, management of ICT third-party risk, and information sharing arrangements. Critical ICT providers to the sector can also fall under direct EU regulatory oversight.
The regulation applies to a broad set of EU financial entities, including banks, insurers, investment firms, payment and e-money institutions, and crypto-asset service providers. It does not directly regulate US companies, but it reaches them anyway. EU financial entities must impose specific contractual provisions on their ICT service providers, covering audit and access rights, incident notification, subcontracting transparency, and exit strategies, and those obligations flow down to vendors wherever they are located.
The practical implication for US software and services companies is that DORA shows up as contract redlines and due-diligence questionnaires from EU financial customers, and the requests have been live since the regulation began applying on January 17, 2025. Vendors that cannot evidence incident response, resilience testing, and subcontractor governance risk losing those deals. Z Cyber helps technology vendors and financial institutions build that evidence, as described on our financial services page.
Running a program that has to satisfy this?
A Z Cyber advisor can walk your current posture against the requirement and show you what a running program looks like on Glance.
Meet Your Security Team →