Digital Operational Resilience Act

DORA Regulation

DORA is Regulation (EU) 2022/2554 on digital operational resilience for the financial sector. It lays down uniform rules, so that financial institutions can prevent, detect, react to, and recover after ICT incidents (e.g. a cyberattack or a system failure). The Regulation came into effect on 16/01/2023 and has applied since 17/01/2025.

DORA covers e.g. banks, insurance companies, brokerage houses, payment institutions, funds, financial market infrastructure, providers of crypto services, and external ICT suppliers (e.g. clouds) that provide services to financial entities.

The key idea of DORA is to move from simple “ensuring of IT security” to “operational resilience”. This means that an institution has to be ready for a situation where security measures fail and has to have procedures in place that will still make it possible to protect the clients’ funds and ensure business continuity.

Why is it worth it?

DORA's core operational resilience pillars

ICT risk management

ICT incident management 

Operational resilience testing 

ICT service providers risk management

Information sharing

DORA – comprehensive support from Cybernite

Which law implements DORA in Poland?

DORA is a EU regulation and not a directive. This means that is applies directly in every EU Member State without the need for an implementing law to be passed.

However, in Poland, the Law on Amendments to Certain Laws in Connection With Ensuring Digital Operational Resilience of the Financial Sector was adopted. It serves as a “technical connection”, designating the Polish Financial Supervision Authority (KNF) as the body responsible for supervision over DORA in Poland and aligning Polish legal regulations (e.g. banking law) with EU requirements.

What is the purpose of DORA?

The main goals of DORA are to:

  1. Ensure the continuity of financial services in the EU
  2. Increase the resilience of financial institutions to ICT incidents
  3. Consolidate requirements in terms of IT risk management
  4. Ensure better control over external providers of ICT services
  5. Limit the consequences of failures, cyberattacks, and technological errors

The idea behind DORA is that digital interferences in the financial sector may have serious systemic consequences - not only for a single company, but for the entire economy.

Who does DORA apply to?

DORA applies to a large number of entities in the financial sector, including:

  • Banks and branches of foreign banks,
  • Payment and electronic money institutions,
  • Investment companies,
  • Investment and pension fund societies,
  • Insurance and reinsurance companies,
  • Stock exchanges, clearing houses, and securities depositories,
  • Providers of cryptocurrency services,
  • Selcted providers of ICT services to financial sector

The scope of regulation is extensive and covers both large institutions and smaller entities; however, requirements are proportional to scale and risk profile.

Key requirements for business

DORA is based on five pillars each institution has to implement:

  1. ICT risk management

Institutions have to have a solid risk management framework. The management board of the company is responsible for cybersecurity. It needs to regularly approve strategies and security budgets and participate in training seminars.

  1. Reporting of incidents

A uniform system of reporting major technology-related incidents has been implemented. Companies have to classify failures and attacks according to specific criteria and report them to supervisory authorities in a very short time.

  1. Testing resilience

This is one of the most difficult requirements. Entities have to regularly test their systems (e.g. through penetration tests). Once every 3 years, the largest institutions are required to carry out advanced TLPTs (Threat Led Penetration Tests), i.e., controlled attacks performed by ethical hackers.

  1. Risk management by external providers

Financial companies have to very carefully verify their IT providers (e.g. cloud providers). The agreements signed with them have to contain specific provisions in terms of service levels, security, and the right to audit.

  1. Exchange of information

DORA encourages institutions to voluntarily share among themselves information regarding threats and viruses, so that the entire sector can respond more quickly to new methods used by hackers.

The Polish Financial Supervision Authority publishes, on an ongoing basis, the relevant EU delegated and implementing acts (e.g. criteria for designating critical providers or classification of incidents).

European supervision authorities (EBA, ESMA, EIOPA) have published level 2 acts (RTS/ITS) specifying in detail e.g. the classification of incidents, the reporting process, and the requirements in terms of tests and the process of managing third parties.

What are the penalties for non-compliance with DORA?

DORA requires Member States to introduce effective and dissuasive penalties. In Poland, these include:

  • High financial penalties,
  • Administrative decisions ordering the removal of violations,
  • Restriction or revocation of a permission,
  • Responsibility of the members of the management board,
  • Increased supervision and inspections by the Polish Financial Supervision Authority,

The exact amount of a financial penalty depends on the type of entity and the nature of the violation.

Supervisory authorities may carry out inspections, order the implementation of remedial measures, introduce restrictions, and impose financial penalties. In practice, a penalty of up to 2% of global turnover for financial entities and up to EUR 5 million for critical providers of ICT services is possible, with an option to suspend or terminate agreements with providers if these pose a threat to operational resilience. (Specific thresholds may be specified in EU regulations, domestic law, and supervisory decisions.)

What does that mean for business?

  • Organized ICT frameworks and continuous resilience testing.
  • Quick, standardized reporting of major ICT incidents.
  • Tough rules for agreements with ICT providers, including in terms of controlling the risk of concentration and supervision over critical providers.
  • Having to be ready for Polish Financial Supervision Authority inspections and potential penalties in the event of non-compliance.

Summary

DORA:

  • Applies to most of the financial sector in the EU,
  • Focuses on operational and digital resilience,
  • Introduces obligations in terms of managing ICT risks and providers,
  • In Poland, it has been in force directly since 17 January 2025.

For business, this means one thing: the stability of IT systems and the continuity of financial services are a key legal and strategic obligation.

Text by professor Grzegorz Strupczewski

Within the framework of Cybernite Status we help assess the organization’s current level of security and regulatory preparedness.

Through Cybernite Safe, we provide regular support in terms of cybersecurity management, performance of regulatory obligations, and compliance with industry standards, using the Cybersecurity as a Service (CSaaS) model.

Do you need support with respect to NIS2/KSC, CRA, DORA, or the AI Act, from confirming that you are subject to them, through gap analysis, to verification and supplementation of existing actions?
Cybernite helps organize documentation, implement the missing elements, and maintain compliance in practice.

Schedule a free meeting