EU Regulation 2022/2554 · DORA Compliance · STORM GRC

What is DORA and Why It Matters 

The Digital Operational Resilience Act (DORA) (EU Regulation 2022/2554) is a key EU regulation focused on strengthening cybersecurity and operational resilience in the financial sector.

DORA aims to ensure that financial institutions can maintain secure and resilient operations, both within their own systems and across third-party ICT providers. This includes strengthening ICT capabilities to protect networks and systems, while ensuring financial services remain available during disruptions.

DORA is not just another compliance requirement—it changes how organisations approach ICT risk and operational resilience. It represents a shift toward continuous risk management and accountability across systems, processes, and third-party relationships.

Who Needs to Comply with DORA?

DORA applies to a range of financial entities, covering 21 different types of organisations, as defined in Article 2 of the Regulation.

Category Entities
Credit & Payment Institutions Credit institutions, payment institutions, e-money institutions, account information service providers, electronic money institutions
Investment & Market Entities Investment firms, trading venues, central counterparties, trade repositories
Post-Trade & Infrastructure Central securities depositories (CSDs), securitisation repositories
Funds & Management Entities Managers of alternative investment funds (AIFMs), management companies
Insurance Sector Insurance and reinsurance undertakings, insurance, reinsurance and ancillary insurance intermediaries
Pensions Institutions for occupational retirement provision
Market Support & Data Services Credit rating agencies, benchmark administrators, data reporting service providers
Digital Financial Services Crypto-asset service providers, crowdfunding platforms
ICT Providers ICT third-party service providers

Key DORA Requirements

ICT Risk Management and Governance

DORA requires financial institutions to adopt a proactive, risk-based approach to ICT risk management, ensuring resilience across systems and operations.

Organisations must go beyond prevention and establish capabilities for detection, containment, and effective recovery.

In practice, this means:

  • Maintain full visibility of ICT assets and critical functions
  • Understand dependencies across systems, processes, and third-party providers
  • Continuously assess and mitigate cyber risks
  • Align risk tolerance with Business Impact Analysis (BIA)

DORA requires organisations to move from static risk assessments to continuously managed ICT risk environments.

Incident Response and Reporting

DORA requires organisations to establish effective processes for detecting, managing, and reporting ICT-related incidents in a timely manner.

  • Detect, classify, and report ICT incidents to relevant competent authorities in line with defined timelines.
  • Assess impact on services and customers
  • Monitor service downtime
  • Evaluate geographic impact
  • Identify significant data loss

Digital Operational Resilience Testing

Organisations must regularly test their ability to withstand and recover from ICT disruptions.

  • Identify critical systems and high-risk areas
  • Perform testing activities such as penetration testing
  • Define testing frequency based on risk
  • Include relevant third-party providers
  • Address identified vulnerabilities

For critical entities, this may include advanced testing such as Threat-Led Penetration Testing (TLPT).

Third-Party Risk Management

DORA extends beyond internal systems and requires structured management of ICT third-party risk.

  • Identify and assess third-party risks
  • Maintain an inventory of ICT providers
  • Define contractual security requirements
  • Continuously monitor third-party performance
  • Establish formal TPRM policies and procedures

Information Sharing

DORA encourages organisations to participate in threat intelligence sharing to strengthen resilience.

  • Receive and analyse cyber threat intelligence
  • Share relevant insights with trusted parties
  • Act on intelligence to strengthen security posture and resilience capabilities
DORA Regulation

How STORM Supports DORA Compliance

STORM supports DORA compliance by bringing ICT risk, resilience, and third-party management into a single, structured platform.

In practice, this enables organisations to:

  • Assess current security posture and identify compliance gaps, supporting DORA readiness from the outset
  • Map and manage ICT assets, systems, and dependencies, ensuring full visibility across services and infrastructure
  • Perform Business Impact Analysis (BIA) and define recovery objectives (RTO, RPO), aligning risk tolerance with business priorities
  • Conduct risk assessments and implement mitigation measures, based on threats, vulnerabilities, and business impact
  • Manage ICT incidents, including classification, tracking, and reporting in line with regulatory requirements
  • Assess and monitor third-party risks, ensuring compliance across the supply chain
  • Integrate threat intelligence feeds (e.g. BitSight, FortiRecon) to enhance visibility into external risks and emerging cyber threats
  • Develop and maintain security policies, procedures, and audit evidence, supporting governance and regulatory audits

Conclusion

DORA pushes financial institutions toward continuous resilience and accountability.

Compliance can no longer be treated as a periodic exercise. It requires structured processes, real-time visibility, and continuous control.

STORM helps financial institutions move from fragmented compliance processes to continuous control, with real-time visibility across ICT risk, resilience, and third-party dependencies.

To see how this works in practice, request a demo or get in touch with our team to learn more.