> ## Documentation Index
> Fetch the complete documentation index at: https://help.dsalta.com/llms.txt
> Use this file to discover all available pages before exploring further.

# DORA

> Achieve Digital Operational Resilience for financial entities under the EU's DORA regulation.

The Digital Operational Resilience Act (DORA) is an EU regulation that requires financial entities to ensure they can withstand, respond to, and recover from ICT-related disruptions and threats. It has been fully enforceable since **January 17, 2025**.

<Warning>
  DORA is mandatory for all EU financial entities and their critical ICT third-party service providers, including non-EU SaaS vendors serving EU financial clients. Non-compliance can result in fines up to **2% of global turnover or €5 million**.
</Warning>

## Who needs DORA compliance?

<CardGroup cols={2}>
  <Card title="Financial entities" icon="building-columns">
    Banks, insurance companies, investment firms, payment institutions, and crypto-asset service providers operating in the EU.
  </Card>

  <Card title="ICT providers" icon="server">
    Technology vendors and cloud service providers designated as critical third-party providers to the financial sector — including non-EU companies.
  </Card>
</CardGroup>

## Five pillars of DORA

<CardGroup cols={3}>
  <Card title="ICT Risk Management" icon="shield-check">
    Comprehensive framework for identifying, protecting, detecting, responding to, and recovering from ICT risks.
  </Card>

  <Card title="Incident Reporting" icon="bell">
    Major ICT incidents must be reported to authorities. Initial notification within 4 hours, interim report within 72 hours, final report within 1 month.
  </Card>

  <Card title="Resilience Testing" icon="flask-vial">
    Regular testing of ICT systems including threat-led penetration testing (TLPT) for significant entities.
  </Card>

  <Card title="Third-Party Risk" icon="building">
    Manage risks from ICT third-party providers, including contractual requirements, exit strategies, and concentration risk monitoring.
  </Card>

  <Card title="Information Sharing" icon="share-nodes">
    Voluntary sharing of cyber threat intelligence between financial entities to improve sector-wide resilience.
  </Card>
</CardGroup>

## How DSALTA helps

* **DORA-specific controls** mapped to all five pillars
* **ICT risk management framework** through the risk register
* **Incident response documentation** and reporting templates
* **Third-party risk management** with vendor scoring and monitoring
* **Cross-framework mapping** — significant overlap with NIS 2, ISO 27001, and SOC 2

## Frequently asked questions

<AccordionGroup>
  <Accordion title="Does DORA apply to non-EU companies?" icon="globe">
    Yes, if you are an ICT third-party service provider designated as critical to EU financial entities. EU financial clients will require DORA compliance evidence as part of their vendor management.
  </Accordion>

  <Accordion title="How does DORA relate to NIS 2?" icon="diagram-project">
    DORA is lex specialis (sector-specific) for financial entities, while NIS 2 is the broader EU cybersecurity directive. DORA takes precedence for in-scope financial entities, but NIS 2 requirements may still apply for broader governance.
  </Accordion>

  <Accordion title="What are the incident reporting timelines?" icon="clock">
    Initial notification within 4 hours of classification, interim report within 72 hours, and final report within 1 month of the incident.
  </Accordion>
</AccordionGroup>

## How DSALTA automates this

**3** of DSALTA's automated checks contribute evidence to this framework, drawn from **3** integrations. Browse them in the [Compliance Tests](/tests/overview) catalog.

## Related pages

* [NIS 2](/frameworks/nis2/overview)
* [Active Frameworks](/guides/compliance/frameworks-active)
