Articles
EU regulation

DORA

The EU regulation on digital operational resilience, the Digital Operational Resilience Act (DORA), aims to strengthen the financial sector through penetration testing and remediation plans. From 17 January 2025, all covered firms must comply with the legal requirements.

DORA applies to companies in the financial sector, with the aim of ensuring that these companies take a more consistent approach to risk and vulnerability management. Digitalisation over recent decades has made IT essential to the operation of banks and other institutions.

There is also strong interconnection between so-called financial entities, financial markets and infrastructure within the EU, which in itself can create a vulnerability for the entire EU financial system and, in the worst case, affect financial stability across the EU. DORA covers several areas of information and communication technology (ICT).

  • Risk management means having strategies and methods for regular risk assessments, monitoring of ICT systems, backup and recovery procedures, and ICT continuity policies. ICT risk management must be updated on a regular basis.
  • Incidents must be logged, managed, monitored and followed up in accordance with established processes. Major ICT-related incidents must be reported to the designated supervisory authority.
  • Testing of digital operational resilience must be carried out under an established testing programme that includes, for example, vulnerability assessments, network security assessments, physical security reviews and penetration testing. Based on the test results, the financial entity must draw up a remediation plan to ensure that identified weaknesses are addressed.
  • Financial entities of central importance to the financial system must, in most cases every three years, carry out advanced testing based on threat-led penetration testing under the European Central Bank's Threat Intelligence-Based Ethical Red teaming framework (TIBER-EU). Red teaming means commissioning someone to attempt to breach the organisation the way an attacker, an adversarial party, might, in order to detect and remediate vulnerabilities before an actual attack occurs.
  • Third-party risks must be managed as an integral part of ICT risk management. Before signing an agreement with a third-party ICT service provider, the provider must be reviewed through due diligence, among other things. Conflicts of interest and relevant risks that the agreement could give rise to must be identified and assessed. There are also requirements for exit strategies.

DORA is law in Sweden

In January 2024, the Ministry of Finance proposed a new law with supplementary national provisions to the DORA regulation, under the supervision of the Swedish Financial Supervisory Authority (Finansinspektionen).

  • Finansinspektionen becomes the competent authority and will determine which financial entities must carry out penetration tests and how often.
  • The Riksbank's expertise within the TIBER-EU framework is put to use. The Riksbank oversees and coordinates the penetration tests and issues certificates.
  • At the Riksbank's request, financial entities must provide information for the tests.
  • Finansinspektionen will exercise supervision and may order a natural or legal person to provide information, documents or other material.
  • If necessary, Finansinspektionen may inspect the business premises of a financial entity.
  • No new provisions on criminal liability for breaches of the DORA regulation will be introduced. Finansinspektionen's existing powers are considered sufficient. Entities within scope will pay fees that cover the costs incurred by Finansinspektionen and the Riksbank.

DORA covers NIS2 and CER

Companies covered by DORA do not also need to comply with the NIS2 and CER directives. DORA has stricter requirements for risk management and incident reporting than NIS2, and it includes protection of physical infrastructure equivalent to CER.

All entities must, however, register with the register that each member state is required to establish under NIS2 and CER. EBA, ESMA and EIOPA are supervisory authorities at EU level. Read more from the EU authority EIOPA.

Keep reading