Back to Field Notes
Compliance & Regulation/Field Note

DORA — The EU's Financial Sector Resilience Mandate

DORA replaces a patchwork of national rules with five hard pillars. The ICT third-party register is where most programs are still behind.

Author

Diana Petrov

Director, Governance Practice

Published

January 13, 2026

Read

10 min

Share
AI-generated illustration of a banking facility
AI-generated illustration of a banking facility
Key Takeaways
  • 01DORA's five pillars: ICT risk management with board accountability, classified incident reporting on tight timelines, threat-led penetration testing for significant entities, third-party risk with mandatory contractual clauses, and information sharing.
  • 02The Article 28 third-party register is where most programs are still behind. Procurement, vendor management, and IT inventory systems disagree on what 'one vendor' means — reconciling those before submission is the actual work.
  • 03Threat-led penetration testing (TLPT) is conducted on production by certified providers against business-specific threat models. It is not a quarterly pen test relabeled — plan budget and engineering capacity well in advance.
  • 04Senior management is personally accountable. Board-level sign-off on the ICT risk framework is mandatory and named individuals must own each pillar. Generic 'CIO owns ICT risk' will not survive a competent-authority review.

The Digital Operational Resilience Act (DORA), in force since January 2025, harmonizes ICT risk management for EU financial entities — banks, insurers, investment firms, crypto-asset service providers, and many of their critical ICT third parties.

The five DORA pillars

  • 01ICT risk management framework with board-level accountability
  • 02ICT incident classification and reporting on tight regulatory timelines
  • 03Threat-led penetration testing (TLPT) for significant entities
  • 04ICT third-party risk management with mandatory contractual clauses
  • 05Information sharing within trusted communities

The third-party register is harder than it looks

DORA Article 28 requires a register of all ICT third-party arrangements with detail on criticality, function supported, sub-contractor chain, and exit strategy. Most institutions discover that their procurement, vendor management, and IT inventory systems disagree on what 'one vendor' means. Reconciling those before submission is the work.

TLPT is real and expensive

Threat-led penetration testing is conducted on production systems, by certified providers, against threats specifically modeled on your business. It is not a quarterly pen test relabeled. Plan budget and engineering capacity well in advance.

#DORA#Financial Services#EU

/WRITTEN_BY

Diana Petrov

Director, Governance Practice · Alexa Cybersecurity