EU Regulation 2022/2554 · Financial Services

DORA compliance, without the guesswork

Advisory and monitoring tools built for DORA — meet financial-sector ICT resilience obligations without building a compliance department from scratch.

21entity categories
4 hrsincident classification
22,000+entities covered EU-wide
DORA, at a glance
100% directly applicable
EU-wide, no transposition
DORA is a Regulation, not a Directive — it took full legal effect across all 27 member states on 17 Jan 2025, with no national transposition step (unlike NIS2).
Critical ICT third-party providers — max penalty1% / day
Incident classification deadline4 hrs
See your DORA obligations
The basics

What DORA actually requires

A single EU rulebook for ICT risk, incident reporting, resilience testing and third-party oversight in finance.

You're likely in scope if you're a...

  • Bank, payment / e-money institution, or investment firm
  • Insurer, pension fund, or asset manager
  • Trading venue, CCP, CSD, or crypto-asset provider
  • An ICT provider a financial entity depends on

Two layers of oversight

  • Financial entities — direct obligations, all five pillars
  • Critical ICT providers (CTPPs) — 19 under direct EU oversight
  • Other vendors: bound by contract, not direct penalties
Articles 5–45

DORA's five pillars

Every obligation falls under one of five headings — testing usually stings the most.

01

ICT risk management

A board-accountable framework covering identification, protection, detection and recovery (Art. 5–16).

02

Incident reporting

Classification and reporting to hit the 4-hour / 72-hour / 1-month clock for major incidents.

03

Resilience testing

Annual baseline testing, plus Threat-Led Penetration Testing every three years for significant institutions.

04

Third-party risk

A Register of Information for every ICT arrangement, plus Article 30 contract clauses for critical providers.

05

Information sharing

Voluntary cyber threat-intelligence exchange between financial entities, with regulatory safe harbour.

Where things stand in 2026

DORA's rollout, at a glance

Past go-live — supervisors now test whether the paperwork actually holds up.

16 Jan 2023

Regulation in force

Starts a two-year run-in period.

17 Jan 2025

Full application begins

No further grace period.

30 Apr 2025

Register of Information due

Quarterly updates now ongoing.

2025 – 2026

Active enforcement

19 CTPPs designated; first TLPT cycles underway.

Why this reaches the board

ICT risk is now a governance duty, not an IT ticket

Article 50(5) extends penalties to management body members — supervisors are already querying incident classifications, not just asking whether a document exists.

Board-level exposure
LowModerateSevere
No EU cap
Fines set per Member State
1% / day
Max fine, critical ICT providers
4 hrs
To classify a major incident
Personal
Liability, Article 50(5)
Software + advisory, one team

How Channel IT gets you there

Prove resilience, don't just describe it — tooling and paperwork stay in sync.

Platform & tooling

Technology that keeps you audit-ready

  • ICT risk monitoring & asset mapping
  • Incident classification & reporting workflows
  • Register of Information management
  • Access, resilience & recovery tooling
Advisory & managed services

Expertise for the parts software can't cover

  • Scope & Register of Information review
  • Contract remediation (Article 30)
  • TLPT & resilience-testing support
  • Board briefings & governance advisory
Engagement model

From "are we covered?" to audit-ready

Assess

Scope check across all five pillars

Remediate

Register, contracts & risk framework fixed

Implement

Monitoring & testing tooling deployed

Monitor & report

Ongoing oversight, always audit-ready

Why work with us

One partner, not a stack of disconnected vendors

Tooling and advisory, one team

The fix a consultant recommends is the one that gets deployed.

Vendor-neutral recommendations

Not locked to one platform — the solution fits your environment.

Built around the five pillars

Maps to what supervisors check first.

Support that continues after go-live

Quarterly updates don't stop once the project is filed.

Questions

DORA, in plain language

Does DORA apply to our organisation?
DORA applies to more than 22,000 financial entities across 21 categories — banks, payment and e-money institutions, investment firms, insurers, crypto-asset service providers, pension funds, trading venues, CCPs, CSDs, asset managers and crowdfunding platforms — plus their critical ICT third-party providers. Some smaller, non-interconnected investment firms and payment institutions qualify for simplified requirements.
What are DORA's five pillars?
ICT risk management, incident reporting, digital operational resilience testing, ICT third-party risk management, and information sharing.
What are the DORA incident reporting deadlines?
For a major ICT-related incident: initial notification within 4 hours of classification, an intermediate report within 72 hours, and a final report within one month.
What does DORA require for our ICT vendors?
You need a Register of Information covering every ICT arrangement, and contracts with critical providers must include Article 30 clauses such as audit rights and exit plans. Some providers can also be designated as "critical" for direct oversight by EU supervisors.
What are the penalties for DORA non-compliance?
There's no single EU-wide fine cap for financial entities — each Member State sets its own maximum. Designated critical ICT third-party providers face fines of up to 1% of average daily worldwide turnover, accruable for up to six months. Management body members can also be held personally liable under Article 50(5).
Is DORA still being actively enforced in 2026?
Yes. DORA has applied in full since 17 January 2025. Supervisors are now auditing Register of Information quality, running the first TLPT cycles, folding DORA into the ECB's SREP process, and querying incident-classification errors — enforcement has moved from paperwork to active scrutiny.

Get a clear answer on where you stand

A free DORA scope and readiness assessment — no obligation, no jargon.

Get in touch

Book your free DORA assessment

A compliance specialist will follow up to schedule a call.

  • General NIS2 & DORA enquiries
  • 1 business day
    Typical response time
  • No-obligation scope check
    We'll tell you plainly if DORA doesn't apply to you

By submitting, you agree to be contacted by Channel IT about DORA compliance services. We don't share your details with third parties.

Book a free DORA assessment