“In New York, Chicago, and San Francisco, risk managers at US banks, broker-dealers, and insurance groups found themselves fielding urgent calls from European counterparts asking for evidence of operational resilience controls that most US firms had never been asked to produce before. The Digital Operational Resilience Act was no longer a European problem.”
— Risk Publishing, June 2026
The EU adopted the Digital Operational Resilience Act (DORA) in 2022, and it became enforceable on January 17, 2025. The law requires that financial institutions withstand, respond to, and recover from information and communication technology disruptions. It’s not just a cybersecurity law. In addition to cyberattacks, DORA includes IT system failures, power outages, or third-party provider incidents—anything that disrupts a financial entity’s digital operations.
DORA’s impact on US financial institutions
DORA was designed to remedy the gaps and uncertainty caused by patchwork EU regulations that shifted from state to state and sector to sector. These were often non-binding guidelines. To replace all that, DORA creates a single framework across all EU states and financial sectors, and its reach extends to US companies with the following profiles:
- US bank with EU subsidiary
- US cloud provider serving EU banks
- US fintech with EU clients
- US insurer with EU reinsurance
- US asset manager with EU fund
These organizations must comply with the 5 pillars of DORA1:
| ICT Risk Management | Establish and maintain a comprehensive ICT risk management framework with governance, identification, protection, detection, response, and recovery capabilities |
| Incident Reporting | Classify, report, and notify competent authorities of major ICT-related incidents within prescribed timelines |
| Resilience Testing | Conduct regular testing including TLPT at least every 3 years for significant entities |
| Third-Party Risk | Maintain a Register of Information on all ICT third-party arrangements; conduct due diligence and ongoing monitoring |
| Information Sharing | Participate in voluntary cyber threat intelligence sharing arrangements with other financial entities |
Institutional Readiness
Recent survey data finds US financial firms’ DORA readiness lacking, particularly in resilience testing and third-party risk management.1

Organizations operating under ISO 27001, NIST CSF, SOC 2, and other industry-specific controls benefit from overlap between the DORA compliance checklist and those of existing frameworks. For instance, “organizations certified to ISO 27001 or aligned to NIST CSF 2.0 will find that roughly 70-80% of Pillar 1 requirements are already addressed.”1

However, organizations like fintechs that tend to have less mature GRC frameworks or lack GRC capabilities altogether should consider the following steps:
- Determine which DORA provisions apply: Applicability can vary by organization size, type, and services. Smaller organization can benefit from a simplified ICT risk management framework under Article 16.
- Perform a gap assessment and detect areas for improvement: Identify any weaknesses in current resiliency practices—for cybersecurity and beyond.
- Develop an ICT risk management framework: Document policies, integrate with organizational risk management, and ensure board-level governance.
- Build a third-party register and review third-party contracts: Document all third-party arrangements per DORA requirements and ensure contracts include mandatory DORA provisions.
- Prepare to test regularly: Perform vulnerability assessments, resilience drills, and penetration tests in accordance with your risk profile.
- Reporting framework: Develop processes to classify and report ICT incidents.
- Train your staff: Ensure relevant individuals are aware of DORA requirements and their roles in ensuring compliance.
As always, penalty avoidance is the major impetus for rigorous compliance. The penalties for DORA non-compliance are significant1:
| Violation Category | Maximum Penalty | Additional Consequences |
| Financial entity: failure in ICT risk management | Up to 2% of total annual worldwide turnover | Public disclosure of breach; suspension of ICT service agreements |
| Financial entity: failure to report major incidents | Up to 2% of total annual worldwide turnover | Increased supervisory scrutiny; remediation orders |
| Critical third-party ICT provider: non-compliance | Up to EUR 5 million (entity) / EUR 500,000 (individual) | Daily periodic penalty payments for up to 6 months at 1% of average daily worldwide turnover |
| Individual accountability: senior management failures | Up to EUR 1 million per individual | Personal liability for board members and ICT risk officers |
DORA is not only an EU issue. It impacts a great many US financial institutions that serve the EU and provide services to EU customers. It should be considered an integral part of any organization’s compliance framework, right up there with FINRA or SEC regulations. Finance operates across borders, and with DORA in particular, the regulations function similarly.
To help guide you toward full DORA compliance, Risk Management has published the informative, “DORA Compliance Checklist: What US Financial Firms Need to Know.” It contains details on requirements for each of the five DORA pillars, information on mapping DORA to ISO 27001 and NIST CSF 2.0 and the anticipated gaps, and more.


