SHORT ANSWER
DORA (Regulation (EU) 2022/2554) has applied since 17 January 2025 to banks, payment and e-money providers, investment firms, insurers, crypto-asset service providers and other financial entities. It rests on five pillars: ICT risk management, incident reporting, resilience testing, ICT third-party risk and information sharing. Major incidents need an initial report within 4 hours of classification, and software vendors must accept contract terms set by Article 30.
If your software runs inside a bank, insurer or payment provider, DORA now shapes your contracts, your testing and how fast you report problems. The Digital Operational Resilience Act (DORA, Regulation (EU) 2022/2554) sets one EU rulebook for how financial entities manage ICT risk. It has applied since 17 January 2025 to around 20 types of financial entity, from banks and payment providers to insurers, investment firms and crypto-asset service providers. For engineering teams, DORA turns resilience from good practice into auditable evidence: documented architectures, tested recovery, traceable incidents and contracts that let the client audit and exit. This guide is general information, not legal advice.
What are the five pillars of DORA?
Pillar | Articles | What it requires | What it means for engineering |
|---|---|---|---|
ICT risk management | 5 to 16 | Governance by the management body, an ICT risk framework, asset identification, protection, detection, response, backup and recovery | Asset and dependency inventories, secure SDLC, monitoring, documented backup and restore with tested recovery times |
ICT incident management and reporting | 17 to 23 | Incident process, classification by set criteria, reporting of major incidents | Logging, alerting and runbooks that give facts within hours |
Digital operational resilience testing | 24 to 27 | Annual testing programme, plus threat-led penetration testing (TLPT) every three years for significant entities | Vulnerability scans, performance and failover tests, penetration tests, taking part in TLPT |
ICT third-party risk | 28 to 44 | Risk strategy, register of information, contract terms, exit plans, oversight of critical providers | Contract clauses, audit access, subcontractor transparency, exit support |
Information sharing | 45 | Voluntary sharing of cyber threat intelligence | Taking part in client threat-sharing arrangements |
The detail sits in regulatory and implementing technical standards. These include the RTS on the ICT risk management framework, incident classification (Delegated Regulation (EU) 2024/1772), incident report content and timelines (Delegated Regulation (EU) 2025/301), TLPT and subcontracting of critical functions. Microenterprises and some smaller entities can use a simplified ICT risk framework.
How do ICT third-party risk and the register of information work?
Financial entities stay fully responsible for compliance when they outsource. They must assess providers before signing, keep a register of information on all ICT arrangements and report it every year. The first registers were collected in 2025, and the 2026 round was due at the European Supervisory Authorities by 31 March 2026. The register reaches down the supply chain: for services that support critical or important functions, it lists subcontractors too.
Article 30 sets the minimum contract content. Every ICT contract needs a clear service description, data locations, data protection and security provisions, access to and return of data on exit, service levels, cooperation with authorities and termination rights. Contracts that support critical or important functions also need precise quantitative SLAs, notice and reporting duties, business continuity plans, participation in the client’s security training and TLPT, unrestricted audit and inspection rights and a mandatory exit strategy with a transition period.
What are the DORA incident reporting timelines?
Report | Deadline | Vendor contribution |
|---|---|---|
Initial notification | Within 4 hours of classifying the incident as major, and no later than 24 hours after becoming aware of it | Notify the client immediately with scope, time of detection and affected services |
Intermediate report | Within 72 hours of the initial notification, updated when services recover | Root cause hypotheses, impact data, mitigation status |
Final report | Within one month of the latest intermediate report | Confirmed root cause, permanent fixes, lessons learned |
Classification uses criteria such as clients affected, duration, data losses, critical services affected, geographical spread and economic impact. Your client can’t meet a 4-hour clock if your monitoring takes a day to notice a problem. Put vendor notification times in hours into the contract and rehearse them.
The EU is also negotiating a single incident reporting entry point across GDPR, NIS2 and DORA as part of the wider digital omnibus. It had not been adopted as of September 2026, so current national reporting channels still apply.
What does DORA resilience testing involve?
Every financial entity except microenterprises needs a risk-based testing programme. It covers vulnerability assessments, open source analysis, network security assessments, scenario tests, performance and end-to-end tests and penetration tests, with critical systems tested at least once a year. Significant entities selected by their authority must run threat-led penetration testing at least every three years on live production systems, following the TIBER-EU framework. If your software supports a critical function, expect to be in scope and to take part.
What does DORA mean for software vendors serving financial entities?
Expect contract renegotiation: Article 30 clauses, audit rights, subcontracting notice and exit assistance are now standard in bank procurement.
Document your subcontracting chain: hosting, SaaS components and freelancers that support the service must be visible.
Show secure development evidence: code review, dependency scanning, SBOMs, change management and separated environments.
Build observability in: structured logs, audit trails, alerting and dashboards that support incident classification.
Test recovery, not just backups: agreed RTO and RPO values, failover drills and documented restore tests.
Plan for exit: data export in usable formats, documentation and handover support so the client can switch providers.
Map your certifications: ISO 27001 doesn’t equal DORA compliance, but it covers much of the evidence clients request.
Here’s what that evidence looks like in delivery. On a native Android app we built for a U.S. digital banking platform, we ran the full secure software development lifecycle, including documentation and release notes for the final release. We tracked security issues in frameworks and libraries against OWASP guidance, obfuscated the code and encrypted the local database with AES-256. The client’s team reported very few issues in the finished product, and we resolved those before the release date. A paper trail like that is what a bank’s DORA audit will ask its vendors to show.
Many vendors serving banks also fall under NIS2 or its national laws through other clients. See our guide to NIS2 requirements for software suppliers. Older core systems are often the hardest part to bring into line, which our legacy application modernisation guide covers.
How RUBICON helps fintech teams with DORA
We’ve built software for financial services clients, including a digital banking mobile platform and performance testing for a fintech product. We’re about 55 people, 40+ engineers, ISO 27001:2022 and ISO 9001:2015 certified, and we work in the CET time zone with documented, testable delivery processes. See our banking and fintech work and QA and testing services.
If a bank client has just sent you an Article 30 contract, our architects can go through the engineering side with you.
Frequently asked questions
Does DORA apply to software vendors?
Not directly, unless the vendor is itself a financial entity or has been designated a critical ICT third-party provider. But DORA requires financial entities to put specific terms in their ICT contracts, keep a register of every ICT provider and test their resilience. Software vendors, cloud providers and development partners inherit many obligations through those contracts, audits and incident reporting duties.
What are the DORA incident reporting deadlines?
For a major ICT-related incident, the financial entity must send an initial notification within 4 hours of classifying it as major and no later than 24 hours after becoming aware of it. An intermediate report follows within 72 hours of the initial notification, and a final report within one month of the latest intermediate report. Vendors must support these timelines with fast detection and notification.
What is the DORA register of information?
It's a structured register, in the format set by Implementing Regulation (EU) 2024/2956, of all contractual arrangements with ICT third-party service providers, including subcontractors that support critical or important functions. Financial entities keep it at entity, sub-consolidated and consolidated level and submit it to their competent authority each year. Authorities pass it to the European Supervisory Authorities, in 2026 by 31 March.
What is a critical ICT third-party provider under DORA?
It's a provider the European Supervisory Authorities designate because financial entities depend heavily on it. The first list, published on 18 November 2025, named 19 providers, including major cloud and technology companies. A Lead Overseer supervises them directly and can inspect them, issue recommendations and impose periodic penalty payments of up to 1% of average daily worldwide turnover.
Related case study

Digital Banking Mobile Platform | Case Study
The FinTech app brings you curated brands and experiences while helping manage your spending
More resources
