Editorial explainer · official sourcesmedium
DORA, one year on: what it really requires of finance, and why it reaches IT suppliers too
Not an attack, but the resilience framework the European financial sector must hold up under when incidents hit. Regulation (EU) 2022/2554 — DORA, the Digital Operational Resilience Act — has been fully applicable since 17 January 2025. It harmonizes ICT risk management for banks, insurers, crypto-asset providers and many others, mandates incident reporting, resilience testing and third-party risk management — and, through oversight of critical providers, reaches those who serve finance too.
An explainer, not the attack of the day
This piece doesn't cover a breach: it covers the framework within which, in European finance, IT incidents must be prevented, managed and reported. It's worth doing because DORA has been fully in force for over a year, yet its most misunderstood part — the one about technology suppliers, often not directly regulated — keeps catching off guard companies that assumed it didn't apply to them.
What DORA is, and since when
Regulation (EU) 2022/2554, known as DORA (Digital Operational Resilience Act), has been fully applicable since 17 January 2025. Unlike a directive, an EU regulation applies directly without national transposition: its rules take effect uniformly across the Union. The goal is to harmonize, under a single framework, information and communication technology (ICT) risk management in the financial sector, where fragmented, country-by-country practices and obligations used to coexist.
The scope is broad: credit institutions, payment and e-money institutions, investment firms, crypto-asset service providers, fund managers, insurance and reinsurance undertakings and their intermediaries, rating agencies, crowdfunding providers, pension institutions. In practice, almost everything in the financial perimeter that depends on IT systems — which is everything.
The four pillars, briefly
DORA rests on a few blocks worth keeping distinct. The first is ICT risk management: clear governance, accountability rising to management bodies, documented measures. The second is incident management and reporting of significant incidents, with classification and notification to authorities on harmonized timelines and formats. The third is digital operational resilience testing, up to advanced threat-led tests for the most significant entities. The fourth — the most underrated — is ICT third-party risk management.
The point that gets missed: suppliers
This is where DORA surprises those who didn't read it to the end. Financial entities remain responsible even when they hand functions to outside providers: cloud, software, managed services. They must map dependencies, insert precise contractual clauses, assess risk concentration on a few suppliers. And above them, the regulation introduces an EU oversight regime over Critical Third-Party Providers — ICT suppliers deemed critical to the financial system — designated and supervised directly by European authorities.
The practical effect is a contractual cascade: a technology company that is not a financial entity, and thus not directly in scope, still faces stringent demands — on security, continuity, audit, notification — because it sits in the supply chain of someone who is. Anyone serving banks or insurers without having adapted discovers the obligations at the first contract renewal, not before.
Why we cover it here
Because almost every incident we cover in finance runs into the same operational questions: who is accountable, by when it must be reported, how you demonstrate you tested your defenses. DORA is the European answer to those questions, and it is already applicable law. In Italy the relevant supervisors — Banca d'Italia, IVASS, CONSOB in their respective domains — oversee its implementation. For those who work in finance or supply it, the message is simple: compliance is not a future project, it is a state you must be able to demonstrate now. The official sources (EUR-Lex for the text, Banca d'Italia and IVASS for national implementation) remain the reference for operational detail.