DORA for US Financial Firms: Who’s Impacted and What’s at Stake

“In New York, Chicago, and San Francisco, risk managers at US banks, broker-dealers, and insurance groups found themselves fielding urgent calls from European counterparts asking for evidence of operational resilience controls that most US firms had never been asked to produce before. The Digital Operational Resilience Act was no longer a European problem.”

— Risk Publishing, June 2026

The EU adopted the Digital Operational Resilience Act (DORA) in 2022, and it became enforceable on January 17, 2025. The law requires that financial institutions withstand, respond to, and recover from information and communication technology disruptions. It’s not just a cybersecurity law. In addition to cyberattacks, DORA includes IT system failures, power outages, or third-party provider incidents—anything that disrupts a financial entity’s digital operations.

DORA’s impact on US financial institutions

DORA was designed to remedy the gaps and uncertainty caused by patchwork EU regulations that shifted from state to state and sector to sector. These were often non-binding guidelines. To replace all that, DORA creates a single framework across all EU states and financial sectors, and its reach extends to US companies with the following profiles:

  • US bank with EU subsidiary
  • US cloud provider serving EU banks
  • US fintech with EU clients
  • US insurer with EU reinsurance
  • US asset manager with EU fund

These organizations must comply with the 5 pillars of DORA1:

ICT Risk Management Establish and maintain a comprehensive ICT risk management framework with governance, identification, protection, detection, response, and recovery capabilities
Incident Reporting Classify, report, and notify competent authorities of major ICT-related incidents within prescribed timelines
Resilience Testing Conduct regular testing including TLPT at least every 3 years for significant entities
Third-Party Risk Maintain a Register of Information on all ICT third-party arrangements; conduct due diligence and ongoing monitoring
Information Sharing Participate in voluntary cyber threat intelligence sharing arrangements with other financial entities

Institutional Readiness

Recent survey data finds US financial firms’ DORA readiness lacking, particularly in resilience testing and third-party risk management.1

Organizations operating under ISO 27001, NIST CSF, SOC 2, and other industry-specific controls benefit from overlap between the DORA compliance checklist and those of existing frameworks. For instance, “organizations certified to ISO 27001 or aligned to NIST CSF 2.0 will find that roughly 70-80% of Pillar 1 requirements are already addressed.”1

However, organizations like fintechs that tend to have less mature GRC frameworks or lack GRC capabilities altogether should consider the following steps:

  • Determine which DORA provisions apply: Applicability can vary by organization size, type, and services. Smaller organization can benefit from a simplified ICT risk management framework under Article 16.
  • Perform a gap assessment and detect areas for improvement: Identify any weaknesses in current resiliency practices—for cybersecurity and beyond.
  • Develop an ICT risk management framework: Document policies, integrate with organizational risk management, and ensure board-level governance.
  • Build a third-party register and review third-party contracts: Document all third-party arrangements per DORA requirements and ensure contracts include mandatory DORA provisions.
  • Prepare to test regularly: Perform vulnerability assessments, resilience drills, and penetration tests in accordance with your risk profile.
  • Reporting framework: Develop processes to classify and report ICT incidents.
  • Train your staff: Ensure relevant individuals are aware of DORA requirements and their roles in ensuring compliance.

As always, penalty avoidance is the major impetus for rigorous compliance. The penalties for DORA non-compliance are significant1:

Violation Category Maximum Penalty Additional Consequences
Financial entity: failure in ICT risk management Up to 2% of total annual worldwide turnover Public disclosure of breach; suspension of ICT service agreements
Financial entity: failure to report major incidents Up to 2% of total annual worldwide turnover Increased supervisory scrutiny; remediation orders
Critical third-party ICT provider: non-compliance Up to EUR 5 million (entity) / EUR 500,000 (individual) Daily periodic penalty payments for up to 6 months at 1% of average daily worldwide turnover
Individual accountability: senior management failures Up to EUR 1 million per individual Personal liability for board members and ICT risk officers

DORA is not only an EU issue. It impacts a great many US financial institutions that serve the EU and provide services to EU customers. It should be considered an integral part of any organization’s compliance framework, right up there with FINRA or SEC regulations. Finance operates across borders, and with DORA in particular, the regulations function similarly.

To help guide you toward full DORA compliance, Risk Management has published the informative, “DORA Compliance Checklist: What US Financial Firms Need to Know.”  It contains details on requirements for each of the five DORA pillars, information on mapping DORA to ISO 27001 and NIST CSF 2.0 and the anticipated gaps, and more.

1 https://riskpublishing.com/dora-compliance-checklist-what-us-financial-2/#Financial_Sector_Compliance_Readiness_by_Pillar