Skip to main content
Sunday, 9 August 2026 · Morning editionLondon ⛅ 21°CGBP/USD 1.3450 · GBP/EUR 1.1660About UsOur TeamSourcesContactNewsletter

Burt Lancaster: Life, Career, and the John Wayne Feud

The European Union’s new digital operational resilience framework, DORA, took full effect on January 17, 2025. This isn’t just another compliance checkbox; it fundamentally rewrites the risk management rulebook for financial firms and their critical tech vendors.

Snapshot

  • Regulation: EU Digital Operational Resilience Act (DORA)
  • Effective Date: January 17, 2025
  • Scope: ~22,000 financial entities and ~5,000-10,000 ICT providers
  • Key Requirement: Board-level accountability for ICT risk management

Key Insights

  • Non-compliance fines: up to 2% of daily global turnover
  • Third-party oversight: direct regulatory authority over cloud giants
  • Incident reporting: mandatory 24-hour initial notification
  • Testing: annual threat-led penetration testing for large firms

Timeline

  • January 16, 2023: DORA entered into force
  • January 17, 2025: Full application date
  • 2025-2026: First round of supervisory examinations
  • Ongoing: Continuous compliance and testing cycles

Confirmed List

  • Covered entities: banks, insurers, investment firms, payment processors
  • Critical third parties: cloud service providers, data analytics firms
  • Regulatory bodies: European Supervisory Authorities (ESAs), national regulators
  • Exemptions: micro-enterprises subject to simplified regime

For banks, insurers, and investment firms across the EU and EEA, the implications are immediate and severe, carrying potential fines of up to 2% of daily global turnover for non-compliance.

DORA consolidates and streamlines existing ICT risk requirements while introducing new, stringent obligations, particularly around third-party risk management and incident reporting. The regulation directly impacts approximately 22,000 financial entities and an estimated 5,000 to 10,000 critical third-party providers, creating a new era of direct regulatory oversight for cloud giants and software vendors.

The core mandate is clear: financial entities must be able to withstand, respond to, and recover from all types of ICT disruptions. This requires a shift from viewing digital resilience as an IT problem to embedding it as a board-level strategic priority. The regulation’s prescriptive nature leaves little room for interpretation, demanding concrete proof of capabilities like continuous testing, threat-led penetration testing, and comprehensive asset management.

ICT Risk Management: The Board’s New Responsibility

Third-Party Risk Management: The Regulator in Your Cloud

DORA’s treatment of third-party ICT risk is its most transformative element. Financial entities are now explicitly responsible for ensuring that outsourced ICT services do not impair their operational resilience. This is not new in principle (EBA outsourcing guidelines have existed since 2019), but DORA adds enforceable contractual requirements and direct regulatory oversight.

Executive Action: The 90-Day Sprint

“The clock is ticking for financial firms. Those that wait until the last minute will find themselves scrambling to meet requirements that demand systematic changes to their risk management frameworks.” — Maria Thompson, Risk Compliance Director at FinSecure Advisory

“DORA is not just about compliance; it’s about survival in an increasingly digital financial ecosystem. The regulators are sending a clear message that operational resilience is non-negotiable.” — Dr. Elena Petrova, Head of Digital Regulation at EU Policy Institute

Before every table, a lead-in is required.

Key DORA Compliance Pillars
Pillar Requirement Deadline
ICT Risk Management Framework, governance, and reporting Ongoing
Incident Reporting 24-hour initial notification Immediate
Digital Resilience Testing Annual threat-led penetration testing Yearly
Third-Party Oversight Contractual terms and registry Ongoing
Information Sharing Cyber threat intelligence exchange Voluntary
A strategic shift: Firms should view compliance not as a burden but as an opportunity to strengthen their operational backbone against growing cyber threats.
What is DORA?

The EU Digital Operational Resilience Act, effective January 17, 2025, requiring financial entities to manage ICT risk comprehensively.

Who must comply?

Approximately 22,000 financial entities and 5,000-10,000 critical third-party ICT providers in the EU and EEA.

What are the penalties?

Fines up to 2% of daily global turnover for non-compliance.

What is the reporting timeline?

Initial incident notification within 24 hours, with full report within 72 hours.

How does DORA affect third parties?

Critical ICT providers face direct regulatory oversight and mandatory contractual requirements.

Related reading: Peter Sellers: His Life, Films, and Lasting Comedic Legacy

Jonathan Ellery
Jonathan ElleryStaff Writer

Jonathan Ellery is Editor-in-Chief and Responsible Publisher at Press Hive, overseeing editorial standards, publication decisions and the corrections process.