The Digital Operational Resilience Act, known as DORA, is a European Union regulation that makes the ability to withstand and recover from ICT disruption a regulated requirement for financial entities and the technology providers they depend on.

Although DORA targets the financial sector, its principles, managing ICT risk, reporting incidents, testing resilience and controlling third parties, apply to any operation that depends on resilient technology. For organizations that combine financial obligations with physical or operational infrastructure, those principles reach into OT as well.

01Key takeaways

  1. 01

    DORA is an EU regulation establishing digital operational resilience requirements for the financial sector and its ICT providers.

  2. 02

    It is built on pillars covering ICT risk management, incident reporting, resilience testing, third-party risk and information sharing.

  3. 03

    Its focus on resilience and recovery aligns closely with protecting critical operations and infrastructure.

  4. 04

    Technical controls that reduce exposure, protect recovery and limit third-party reach support DORA's expectations.

  5. 05

    DORA complements NIS2 and existing frameworks rather than replacing them, with a sharper resilience focus.

02What DORA is and who is in scope

DORA is an EU regulation focused on the digital operational resilience of the financial sector. It applies to a wide range of financial entities, from banks and insurers to investment firms, and importantly extends to critical ICT third-party providers that serve them.

Because it is a regulation rather than a directive, its requirements apply more directly across member states. Its central idea is that financial entities must be able to keep operating through ICT disruptions, not merely try to prevent them.

DORA's premise: assume ICT disruption will happen, and require the ability to withstand and recover from it.

03The pillars of DORA

ICT risk management
A framework to identify, protect, detect, respond and recover, with governance and accountability at the leadership level.
Incident reporting
Classifying and reporting major ICT-related incidents to authorities within defined timeframes.
Resilience testing
Regular testing of digital operational resilience, including advanced testing for significant entities.
Third-party risk
Managing the risk from ICT providers, including oversight of critical providers and contractual safeguards.
Information sharing
Encouraging the exchange of cyber threat information among entities to improve collective resilience.

04How DORA intersects with OT and infrastructure

DORA is written for financial services, but resilience does not stop at the data center. Financial operations increasingly depend on physical infrastructure, data centers, facilities and connected systems, where availability and recovery are as physical as they are digital.

The mindset DORA enforces, assume disruption and engineer to withstand it, is the same mindset that OT security has long applied to operational continuity. Organizations that span both worlds can apply consistent resilience thinking across their digital and operational estates.

05Technical controls that help

No single control delivers DORA compliance, but several technical measures support its resilience and risk-management expectations, especially around protecting recovery and limiting how far a disruption can spread.

Protected recovery
Isolated, recoverable backups support the ability to restore operations after an ICT incident.
Exposure reduction
Keeping systems reachable only when needed limits the attack window and the spread of disruption.
Controlled third-party access
Time-bound, governed provider access reduces the third-party risk DORA emphasizes.
Segmentation and boundaries
Containing incidents within zones supports resilience by preventing a single failure from cascading.

For the recovery and third-party dimensions in particular, an AIRGAPNET controlled connectivity approach can protect a recovery copy behind a path that is offline by default and confine provider access to approved windows, producing the records that make resilience demonstrable.

06Evidence and auditability

DORA expects resilience to be demonstrable, through documented frameworks, tested recovery, reported incidents and oversight of providers. Evidence is part of the obligation, not an afterthought.

  • Document the ICT risk-management framework and the controls protecting critical operations.
  • Test and record recovery so continuity claims are backed by evidence.
  • Maintain incident classification and reporting capable of meeting required timeframes.
  • Log third-party access and connectivity so provider risk can be shown to be controlled.

07How DORA relates to NIS2

DORA and NIS2 are part of the same broad push to strengthen resilience in the EU, and they overlap in themes such as risk management, incident reporting and third-party risk. For the financial sector, DORA acts as the more specific, sector-focused regime.

Rather than meeting each in isolation, organizations can build one coherent resilience program and map it to both. The underlying security measures, reducing exposure, protecting recovery, controlling access and keeping evidence, serve both regimes at once.

08Closing thought

DORA codifies a simple truth: in a world that depends on technology, the ability to keep operating through disruption is not optional. It turns operational resilience from an aspiration into a regulated outcome with evidence behind it.

Treat it as a prompt to make resilience real. Protect recovery, reduce exposure, control third-party access and keep the records that prove it. The compliance follows from operations that can genuinely withstand and recover from disruption.

FAQFrequently asked questions

What is DORA?

DORA, the Digital Operational Resilience Act, is an EU regulation that establishes digital operational resilience requirements for the financial sector and its critical ICT third-party providers. Its premise is that entities must be able to withstand and recover from ICT disruption, not just prevent it.

Who does DORA apply to?

It applies to a wide range of financial entities such as banks, insurers and investment firms, and extends to critical ICT third-party providers that serve them. As a regulation, its requirements apply directly across EU member states.

What are the pillars of DORA?

DORA is built on ICT risk management, incident reporting, digital operational resilience testing, management of ICT third-party risk, and information sharing of cyber threat intelligence among entities.

How does DORA relate to OT and infrastructure?

Although written for financial services, DORA's assume-disruption mindset matches how OT security approaches operational continuity. Financial operations depend on physical infrastructure where availability and recovery are physical as well as digital, so the principles reach into OT.

How does DORA relate to NIS2?

Both are part of the EU's resilience push and overlap on risk management, incident reporting and third-party risk, with DORA acting as the more specific, sector-focused regime for finance. One coherent resilience program can be mapped to both.

SRCSources of record

Resilience you can prove

Make recovery and third-party access demonstrably controlled.

Protect a recovery copy behind a path that is offline by default and confine provider access to approved windows, producing the records that make resilience auditable.

Related article

Continue the thread NIS2 and OT Security: What the Directive Means for Industrial Operators