What is DORA? The EU rules on digital resilience explained

DORA is the EU's Digital Operational Resilience Act, and it changes how regulated financial firms manage IT risk and vendor contracts. Here's what it actually requires, and who needs to act on it.

A gray folder with two metal clasps, a signed document with a pen, and a round wall clock arranged on a white surface.

In short

DORA, the Digital Operational Resilience Act (Regulation (EU) 2022/2554), is an EU law that sets binding ICT risk management rules for banks, insurers, investment firms and other regulated financial entities. It has applied across the EU since 17 January 2025. It covers risk management, incident reporting, resilience testing, and oversight of critical technology vendors. Most Irish SMBs are not directly in scope, but firms supplying services to financial clients often meet its requirements through contracts.

If you work in accountancy, financial services or a regulated trade, you've probably started seeing DORA mentioned in client contracts, vendor questionnaires or bank correspondence. It's an EU law with a hard compliance date already behind it, not a buzzword. Most Irish SMBs won't be directly in scope, but if your clients are financial firms, DORA can still land on your desk.

Who DORA applies to, and who it doesn't

DORA is the Digital Operational Resilience Act, EU Regulation (EU) 2022/2554. It became enforceable across the EU on 17 January 2025, after a two-year transition period (EIOPA).

Article 2 of the regulation lists the financial entities in scope: credit institutions, payment and e-money institutions, investment firms, insurance and reinsurance undertakings, crypto-asset service providers, and several other categories of regulated financial business, around 20 in total. If you run a dental practice, a hotel, a wholesale distributor or a general professional services firm, you are not one of these entities and DORA does not apply to you directly.

Where DORA reaches further is through contracts. An in-scope financial entity has to manage its technology vendors as part of its own compliance. If your firm, or your client, supplies IT, software, payment processing or cloud services to a bank, insurer or investment firm, that relationship now falls under DORA's third-party risk rules, even though your business sits outside the regulation's direct scope. This is where accountancy and financial-services-adjacent firms usually meet DORA for the first time.

The six areas DORA covers

DORA sets out six main areas of requirement for the entities it covers:

  1. ICT risk management. A formal, board-owned framework for managing technology risk, not a document that sits in a drawer.
  2. ICT third-party risk management. Ongoing oversight of vendors, plus mandatory contract terms covering audit rights, service levels and exit plans.
  3. Digital operational resilience testing. Regular testing of systems, from basic vulnerability scans up to advanced threat-led penetration testing for the largest entities.
  4. Incident management and reporting. Detecting, classifying and reporting major ICT incidents to regulators within tight timeframes.
  5. Information sharing. Voluntary arrangements to share cyber threat intelligence between financial entities.
  6. Oversight of critical third-party providers. A new EU-level oversight regime for the handful of technology vendors, mostly large cloud and infrastructure providers, that the whole sector depends on.

For most readers of this blog, points two and three are the ones that matter. If a client asks how you manage IT risk or whether you can be audited, DORA is very likely the reason behind the question.

What changes in your contracts with technology providers

DORA's rules on ICT third-party risk, set out in Chapter V of the regulation, require in-scope financial entities to hold a full register of their technology suppliers and to build specific clauses into every relevant contract. Expect to see requests for:

  • audit and access rights, so the financial entity or its regulator can review how you handle their systems and data
  • defined service levels and reporting on incidents that affect them
  • a documented exit plan, so they are not locked in if they need to move provider
  • clarity on subcontracting, since DORA expects financial entities to know who is actually running the infrastructure underneath their supplier

None of this is unusual for a well-run managed IT provider. It is, however, a shift from a general service agreement to something closer to a compliance-grade contract, and it is worth reviewing your own supplier agreements if you serve financial clients directly.

DORA and NIS2: how the two compare

DORA is often confused with NIS2, the EU's broader cybersecurity directive, because both arrived around the same time and both talk about ICT risk and incident reporting.

The difference is scope and depth. NIS2 applies across a wide range of sectors, energy, transport, health, digital infrastructure and more, and Irish legislation transposing it is still being finalised. DORA applies only to the financial sector, but where it applies, it is more prescriptive: specific contract clauses, specific testing obligations, and a dedicated oversight regime for critical vendors that NIS2 does not have.

Where the sectors overlap, for example a fintech or a payment firm, DORA takes precedence as the sector-specific law. Everyone else in a regulated trade is more likely to meet NIS2 than DORA.

Where to start

If DORA doesn't apply to you directly, the practical question is whether it applies to your clients, and whether that shows up in the contracts and questionnaires landing on your desk. A few starting points:

  • If you serve financial services or accountancy clients, ask them directly whether they consider you in scope of their DORA third-party register.
  • Review your own contracts with critical IT and cloud suppliers for the same gaps DORA asks financial entities to close: audit rights, incident reporting, and an exit plan.
  • Treat any request for evidence of ICT risk management as routine, not exceptional. It is the same evidence a good managed IT relationship should already produce.

We work through exactly this kind of question with clients as part of our Technology Success Program, where a named advisor reviews your compliance posture on a rolling basis rather than once a year. If a client or bank has asked you about DORA and you are not sure how to answer, that is a good place to start the conversation.

What does DORA stand for?

DORA stands for the Digital Operational Resilience Act, EU Regulation (EU) 2022/2554. It sets binding ICT risk management, testing and incident-reporting rules for banks, insurers, investment firms and other regulated financial entities across the EU. It has applied in full since 17 January 2025, following a two-year transition period.

Does DORA apply to Irish businesses outside financial services?

Not directly. DORA's scope, set out in Article 2 of the regulation, covers around 20 categories of financial entity. Most Irish SMBs, including dental practices, accountancy firms and hospitality businesses, sit outside that list. Firms that supply technology or services to an in-scope financial entity can still be drawn in through that client's contracts.

Is DORA the same as NIS2?

No. NIS2 is a broader EU cybersecurity directive covering many sectors, while DORA applies only to financial entities and their critical technology vendors. Where a business sits in both, for example a fintech, DORA takes precedence as the more specific, sector-focused law.

What happens if an in-scope firm doesn't comply with DORA?

Enforcement in Ireland sits with the Central Bank of Ireland, which is the state's competent authority for DORA, except for occupational pension schemes, which the Pensions Authority supervises. Under Ireland's implementing regulations, S.I. 20/2025, penalties can reach 10 million euro or 10% of annual turnover, whichever is higher, for a financial entity, and up to 1 million euro for an individual in a controlled function role.

Do I need to change my IT contracts because of DORA?

Only if you supply services to a financial entity that is in DORA's scope. If so, expect requests for audit rights, incident reporting terms and a documented exit plan in your contract, since DORA requires the financial entity to hold these terms with its technology suppliers.

All field notes

Start with a free IT review.

You'll get a clear picture of where you're exposed today, and what it looks like to have your whole IT covered as one managed system. No obligation.