What is DORA and How to Comply with the Regulation?
DORA (Digital Operational Resilience Act) is the European regulation that establishes uniform digital resilience requirements for financial entities and their critical ICT service providers. It entered into application on January 17, 2025, and applies to banks, insurers, fund managers, investment firms, fintechs, payment service providers, and critical technology providers in the sector.
DORA is structured around five pillars: ICT risk management (identification, protection, detection, response, and recovery), incident reporting (classification and reporting to authorities), resilience testing (regular testing of critical systems), third-party ICT risk management (oversight of technology providers), and information-sharing arrangements (sharing threat intelligence).
Unlike previous directives such as NIS2, DORA is a directly applicable regulation: it does not require national transposition. Its requirements are the same across all EU member states, eliminating the regulatory fragmentation that previously existed in the area of financial digital resilience.
Why it matters
The financial sector critically depends on its information systems. According to the ECB, the number of significant cyber incidents in the European financial sector tripled between 2020 and 2024. A failure in a bank's systems can affect millions of customers and generate systemic risk. DORA responds to this reality by requiring entities to demonstrate the ability to withstand, respond to, and recover from disruptions.
Penalties for non-compliance can reach 1% of average daily global turnover for a maximum of 6 months. But beyond fines, non-compliance can result in operational restrictions imposed by supervisors. For critical technology providers, the European Commission may request changes to their practices or even prohibit their use by supervised entities.
How it works in practice
DORA requires financial entities to maintain a complete inventory of their information assets and ICT systems, with documentation of their interdependencies. They must identify the data and systems supporting critical or important functions, assess associated risks, and demonstrate the ability to recover from disruptions.
In practice, this requires: an up-to-date catalog of data assets and systems, data traceability across systems (lineage), criticality classification, documented retention and quality policies, and the ability to report to authorities in detail how data flows and what controls exist. Critical technology providers (cloud, data, core banking) must also meet specific requirements.
DORA and How to Comply with the Regulation in Linedat
Linedat covers several DORA requirements by providing a complete inventory of data assets and their interdependencies (lineage), sensitivity and criticality classification, documented quality and retention policies, and audit logs that demonstrate controls over data. These capabilities are directly auditable and exportable for regulatory reports.
Related terms
The GDPR (General Data Protection Regulation) is the European data protection regulation. Learn its key principles and how to implement compliance.
What is Data Governance?Data Governance is the framework of policies, processes, and roles that ensures data quality, security, and correct use across an organization.
What is Data Quality?Data Quality measures whether data is accurate, complete, consistent, and up to date. Learn how to implement effective quality rules.
What is Data Impact Analysis?Impact analysis evaluates what will break before making changes to data, tables, or columns. It prevents downstream incidents.
