Regulatory primer
DORA
Regulation (EU) 2022/2554 — Digital Operational Resilience Act · European Union · In force; applicable from 17 January 2025
DORA is the EU's horizontal regulation of digital operational resilience for the financial sector. It requires financial entities to manage ICT risk, classify + report ICT-related incidents, test their resilience, and govern third-party ICT providers. It applies from 17 January 2025.
What it is
DORA harmonises and tightens what was previously a patchwork of sectoral guidance (EBA + EIOPA + ESMA + national-supervisor expectations on outsourcing, cybersecurity, business continuity). It applies across banking, investment, insurance, payments, e-money, crypto-asset service providers, central securities depositories, trading venues, and selected other financial entities.
Five pillars: ICT risk management (Chapter II), ICT-related incident reporting (Chapter III), digital operational resilience testing (Chapter IV), management of third-party ICT risk (Chapter V), and information sharing (Chapter VI). Critical ICT third-party providers (CTPPs) — designated by the European Supervisory Authorities — face direct EU-level oversight.
Supervised at national level by the existing financial-sector supervisor (e.g. BaFin in Germany, ACPR in France, DNB in the Netherlands). The Joint Committee of the ESAs coordinates cross-border + CTPP supervision.
Who's in scope
- Banks (credit institutions), payment institutions, electronic money institutions, account information service providers, central securities depositories.
- Investment firms, fund managers, market makers, trading venues, central counterparties.
- Insurance + reinsurance undertakings, IORPs, insurance intermediaries (above thresholds).
- Crypto-asset service providers (under MiCA), credit-rating agencies, administrators of critical benchmarks.
- ICT third-party service providers serving the above financial entities (governed through their financial-entity customers; CTPPs face direct oversight).
- Some smaller entities benefit from proportionality (microenterprises, certain IORPs).
Key obligations
Art. 5 — ICT risk-management framework
Financial entity must adopt + maintain a documented ICT risk-management framework. The management body sets the framework, approves it, oversees ICT risk.
Art. 6-9 — ICT risk-management components
Identification + classification of ICT-supported business functions + information assets. Protection + prevention measures. Detection mechanisms. Response + recovery procedures.
Art. 17 — ICT-related incident management process
Documented process for ICT-related incident management. Early-warning indicators, monitoring + handling roles, post-incident reviews.
Art. 18 — incident classification
Classify ICT-related incidents by impact criteria — affected clients, data losses, duration, geographical spread, economic impact. The Joint Committee RTS (Reg. (EU) 2024/1772) standardises thresholds.
Art. 19 — major-incident notification
Major ICT incidents notified to competent authority: early warning within 24h, intermediate report within 72h, final report within 1 month of intermediate.
Art. 24-26 — digital operational resilience testing
Annual testing programme proportionate to size + risk profile. Includes vulnerability assessments, scenario-based testing, threat-led penetration testing (TLPT — Art. 26) every 3 years for designated entities.
Art. 28 — third-party ICT risk management
Strategy on ICT third-party risk including a register of contractual arrangements. Pre-contractual due diligence + ongoing monitoring of providers. Exit strategy + concentration-risk assessment.
Art. 30 — contractual provisions for ICT services
Mandatory contractual clauses for ICT services: clear service description, locations of processing, data-protection terms, business-continuity, access/inspection rights, exit clauses, sub-contracting controls.
Art. 31-44 — CTPP oversight
Critical ICT Third-Party Providers designated by the Joint Committee of ESAs face direct EU-level oversight (Lead Overseer). First CTPP designations expected through 2025-2026.
Timeline + applicability
- 16 Jan 2023DORA entered into force.
- 17 Jan 2025DORA became applicable. Financial entities must have full risk-management framework + register of ICT contractual arrangements.
- 2025-2026First CTPP designations + first major-incident reports under the new templated process.
What's still being worked out
Areas where the regulation's interpretation is genuinely unsettled. Vendor pages skip this; we don't. Your counsel is the right venue for definitive guidance on your deployment.
- Where 'ICT services' starts and 'pure SaaS / managed cloud' stops — the proportional regulatory treatment of standard cloud infrastructure vs critical financial-sector ICT.
- Threshold for CTPP designation — substantive criteria are in Art. 31 but the Joint Committee's application discretion is being established.
- How DORA's third-party-ICT register interacts with vendor concentration risk reporting under existing prudential regulation (CRR / Solvency II).
- Interaction with NIS2 — financial entities under DORA are excluded from most NIS2 obligations (NIS2 lex specialis / DORA lex specialis rules) but the boundary is operationally complex.
- How AI components within ICT services are governed — DORA doesn't distinguish AI, but AI Act + DORA concurrent obligations are emerging via practice + supervisor guidance.
Sectors most affected
Fintech & Payments
Banks, payment institutions, electronic money institutions all in scope. Art. 17-19 incident reporting + Art. 28 third-party risk operative.
InsurTech
Insurance + reinsurance undertakings in scope. AI claims-handling + pricing systems engage ICT-incident classification under Art. 18.
Cybersecurity
Cybersecurity vendors serving financial-entity customers are third-party ICT providers under Art. 28. Audit-trail demands cascade.
Primary sources
Where Promethean fits
Promethean's L12 chain feeds DORA Art. 17-19 incident classification + notification when an AI component fails. Per-decision evidence (when did the AI misbehave, what was the impact volume, what was active spec + model) collapses the postmortem from a multi-week reconstruction to a chain-export query. For third-party ICT providers (Art. 28), the chain is the per-customer audit-trail evidence the financial-entity customer references in their register of contractual arrangements.
What Promethean does NOT solve
- ICT risk-management framework design (Art. 5) — that's a board-level governance document.
- TLPT testing (Art. 26) — that's specialist offensive-security work.
- Business continuity + disaster recovery planning (Art. 11) — that's operations.
- Contractual due diligence with ICT vendors (Art. 30) — that's procurement + legal.
- ICT concentration-risk modelling — that's risk-function work.
FAQ
Does DORA apply to my fintech SMB?
If you hold a financial-sector authorisation (payment institution, e-money institution, investment firm, etc.) AND don't qualify for proportionality exemption, yes. Pre-licensed startups operating under a sponsor bank's umbrella inherit the bank's DORA obligations indirectly. Pure SaaS vendors serving financial entities are NOT directly regulated by DORA, but their financial-entity customers carry Art. 28 third-party-risk obligations that cascade.
What counts as a 'major incident' under Art. 19?
Defined by RTS (Reg. (EU) 2024/1772). Two-track classification: (1) significant impact criteria — affected clients, data loss, economic impact, duration, geographical spread, reputation — and (2) the entity's own thresholds. An incident is major when it meets either the significance criteria OR the entity's internal threshold AND has actually occurred. AI-component failures producing material customer-impact would generally cross.
How does DORA interact with NIS2?
Financial entities subject to DORA are largely excluded from NIS2 — DORA acts as lex specialis. But non-financial entities supplying ICT services to financial-sector customers may be NIS2-regulated separately (e.g. cloud providers, MSSPs). The DORA Art. 28 register-of-contractual-arrangements then sits alongside the NIS2 supplier-risk assessment for those vendors.
What's a CTPP and does my vendor need to worry?
Critical ICT Third-Party Provider — designated by the Joint Committee of ESAs under Art. 31. Criteria: systemic importance, substitutability, criticality of services, EU-wide scale. Designated CTPPs face direct EU-level oversight by a Lead Overseer (one of the ESAs). First designations are being made through 2025-2026. Most SaaS vendors won't be CTPPs; the large hyperscalers + major financial-infrastructure providers likely will be.
Can a chain-based audit trail satisfy DORA evidence requirements?
It can satisfy specific obligations within DORA — the per-decision evidence layer for AI components, the time-bounded incident reconstruction for Art. 19 notifications, the per-customer audit trail for Art. 28 third-party-risk register. It does NOT satisfy DORA in totality — DORA covers organisational governance, testing programmes, BCP/DR, and procurement processes that are operator-side. The chain is the AI-decisioning slice of the broader DORA compliance posture.