
Insights · IT security
Strict requirements for “financial entities”
- Published
- 8 July 2025
- Author
- Dr. Markus Hülper
- Reading time
- 4 min read
Alongside the new NIS2 Directive, which we have already discussed elsewhere [How do companies implement the NIS2 cybersecurity requirements? (clarius.legal), or: NIS2 Directive: implementation and current status in Germany (clarius.legal)], the European legislator has established further cybersecurity compliance requirements for particular companies through the Digital Operational Resilience Act (DORA). The Regulation applies directly from 17 January 2025. While the personal scope of the NIS2 Directive is generally aimed in particular at infrastructure and important entities, DORA contains specific legislation for the financial sector and related service providers. “ICT” stands for “information and communication technology”.
Which companies does DORA apply to?
Despite its status as specific legislation in relation to the NIS2 Directive, DORA’s understanding of the financial sector is extremely broad. As a starting point, the Regulation applies comprehensively to “financial entities”. Under Article 2(1) and (2) of DORA, these include in particular:
- Credit institutions
- Investment firms
- Payment institutions
- Insurance and reinsurance undertakings
- Insurance and reinsurance intermediaries
- Institutions for occupational retirement provision
Alongside financial entities, Article 2(1)(k) of DORA also covers so-called ICT third-party service providers. These are companies that provide digital services relating to hardware or software on an ongoing basis (Article 3(21)). Restrictions apply to small and medium-sized enterprises within the meaning of Article 3(63) and (64).
What are the requirements for ICT risk management?
As a general rule, every financial entity must implement an internal governance and control framework (Article 5(1) DORA) that provides a “high level of digital operational resilience”. Under Article 5(2)(a) DORA, ultimate responsibility lies with the entity’s management body, meaning its management or executive board. Under Article 5 DORA, its tasks essentially include:
- Policies aimed at ensuring high standards of availability, authenticity, integrity and confidentiality
- Allocating clear roles and responsibilities for ICT-related functions to enable effective and timely communication, cooperation and coordination
- Approving, overseeing and reviewing ICT business continuity policies and ICT response and recovery plans (Article 11 DORA)
- Approving and reviewing ICT audit plans
- Allocating appropriate budgetary resources
- Reviewing and approving policies concerning arrangements for the use of ICT services provided by third parties.
On this basis, Article 6 DORA requires the development of a comprehensive and documented ICT risk-management framework. This encompasses all policies, procedures and similar measures required to ensure appropriate protection for all information and ICT assets (particularly hardware, servers, software and premises) against risks, including damage and unauthorised access or use (Article 6(2)). The systems and protocols created in this way must always be adapted to the latest state of the art and potential threats (Article 7). Mechanisms must also be implemented to detect anomalies, ICT incidents and potential vulnerabilities (Article 10). In addition, business continuity policies must be implemented and documented, providing appropriate and effective mechanisms for all ICT-related incidents, including safeguarding critical functions and assessing and limiting damage (Article 11). A procedure must also be maintained for subsequent review and communication with customers and the public.
- This is only a broad outline. The Regulation contains further and, in particular, much more detailed provisions that cannot be presented here in full.
To what extent must an entity test its own resilience?
As a further preventive approach, Chapter IV of DORA directly requires digital operational resilience testing by law:
- Tests must be carried out by an independent party (not necessarily external).
- The scope of testing depends on size, overall risk profile, criticality and technically specific ICT risks.
- Large financial entities (within the meaning of Article 26(1)) are also required to carry out penetration tests at regular intervals.
Risk management concerning third-party providers?
Outsourcing processes to ICT service providers does not remove responsibility. Chapter V of DORA sets out extensive provisions on managing third-party risk. ICT third-party risk must be included in the risk management described above as an “integral component” (Article 28(1)). A strategy for managing third-party risk must therefore be developed through reviews and policies on the use of third-party providers.
Responding to acute incidents and managing third-party service providers?
Alongside the preventive approaches described above, Articles 17 et seq. of DORA govern the management of specific incidents and the corresponding reporting obligations. How to proceed in this regard will be covered in a separate article.
Conclusion
Regulation (EU) 2022/2554 creates a close network of preventive measures within the entity, controls over third-party ICT service providers and obligations for a serious incident. In detail, these go far beyond what can be presented here. Your company can achieve compliance only through a comprehensive review and advice tailored to the individual case. We will be glad to support you in implementing DORA and with our other flexible products in the fields of compliance, data protection and IT security law.
Do you have questions about this topic?
We can assess what the development means for your organisation and advise you directly.


