
Insights · IT security
Digital Operational Resilience Act (DORA): new IT security requirements for companies in the financial sector
- Published
- 8 July 2025
- Author
- Dr. Markus Hülper
- Reading time
- 4 min read
Digitalisation has fundamentally changed the financial sector in recent years. While digital processes enable efficiency gains and innovative services, the risk of IT outages and cyber attacks is rising at the same time. To address these challenges, Regulation (EU) 2022/2554 – better known as the Digital Operational Resilience Act (DORA) – has applied since 17 January 2025. This new regulation lays down uniform requirements across Europe for the digital operational resilience of financial undertakings and ensures uniform rules on IT security requirements in the European Union.
Digital resilience must gain in importance in numerous companies
DORA covers a wide range of companies in the financial sector, including credit institutions, payment and e-money institutions, insurance undertakings and intermediaries, rating agencies and investment firms. In addition, financial holding companies, central securities depositories, trading venues, fund management companies, crypto-asset service providers and companies that provide critical financial market services are affected by the new requirements. External IT service providers that work for financial undertakings must also comply with the regulatory requirements, particularly if they provide essential or critical services. The regulation serves as a specialised supplement to existing national rules and ensures that financial undertakings implement the necessary protective measures against IT risks and cyber attacks. Especially at a time when the threat from cybercrime is steadily increasing, a common regulatory framework is of decisive importance.
Important requirements and implementation measures
DORA pursues a comprehensive approach to strengthening the resilience of financial undertakings against digital threats. This includes in particular requirements on ICT risk management, control of IT third parties and stricter notification and reporting duties. A central aspect of the regulation is the introduction of structured risk management for information and communication technology (ICT). Companies must ensure that they have robust IT governance structures and continuously review their networks and systems for vulnerabilities and threats.
In the area of ICT risk management, companies must take targeted measures to identify, assess and prevent IT risks. This includes, among other things, the implementation of mechanisms to detect and defend against cyber attacks as well as plans for the rapid restoration of operational capability after IT disruptions. DORA also requires regular tests of digital resilience to ensure that companies are prepared for possible threat scenarios.
A further important component of the regulation is the management of risks arising from the use of external IT service providers. Many financial undertakings rely on external providers for cloud services, data processing or cybersecurity solutions, which leads to a stronger dependence on third parties. DORA requires financial undertakings to control their third-party providers more strictly and to ensure that they meet the regulatory requirements. Particular attention is paid to the outsourcing of critical functions, for which strict contractual requirements and monitoring mechanisms are necessary.
In addition, the regulation places high demands on the notification duties for IT security incidents. Companies are obliged to report serious cyber attacks and IT outages to the competent supervisory authorities in a timely manner. The reports are intended to enable better monitoring of threats and to help companies prepare more specifically for security incidents. Regular audits and stress tests are also prescribed in order to review the resilience of the IT infrastructure.
Preparing for DORA: what companies should do now
To implement the new DORA requirements successfully, financial undertakings should take measures to adapt their IT and compliance strategies. A comprehensive inventory of the current IT security architecture helps to identify existing vulnerabilities and remedy them in a targeted way. It is also advisable to develop emergency and recovery plans in order to be prepared for unexpected IT incidents.
Close cooperation between the IT and compliance departments is essential in order to implement DORA-compliant security strategies. Companies should invest in training and awareness measures for their staff in order to create a basic understanding of the new regulatory requirements. Existing IT outsourcing contracts should also be reviewed and, where necessary, adapted to ensure that third-party providers comply with the necessary security standards.
In addition, early audits and tests can help to identify gaps in the IT security architecture and take protective measures in good time. Companies that act proactively can not only avoid regulatory sanctions, but also strengthen their resilience against cyber threats on a lasting basis.
DORA as a milestone for the digital security of the financial sector
With DORA taking effect, the digital resilience of financial undertakings is being raised to a new level. Companies that prepare for the new requirements at an early stage benefit not only from regulatory compliance, but also from increased IT security and improved protection against cyber threats. In view of the growing digital risks, implementing the DORA requirements is an indispensable measure for the long-term safeguarding of the financial sector.
We will be glad to support you in implementing the Digital Operational Resilience Act (DORA) and making the necessary contractual adjustments.
Do you have questions about this topic?
We can assess what the development means for your organisation and advise you directly.


