Digital Operational Resilience Act

DORA Regulation

DORA is Regulation (EU) 2022/2554 on digital operational resilience for the financial sector. It lays down uniform rules enabling financial institutions to prevent, detect, respond to, and recover from ICT-related incidents, such as cyberattacks and system failures. The Regulation entered into force on 16 January 2023 and has applied since 17 January 2025.

DORA applies, among others, to banks, insurers, investment firms, payment institutions, funds, financial market infrastructures, crypto-asset service providers, and ICT third-party service providers, including cloud service providers, that supply services to financial entities.

The central principle of DORA is a shift from merely “ensuring IT security” to achieving “digital operational resilience”. Institutions must be prepared for security measures to fail and have procedures in place to safeguard client funds and maintain continuity of service when they do.

Why is it worth it?

DORA's core operational resilience pillars

ICT risk management

ICT incident management 

Operational resilience testing 

ICT service providers risk management

Information sharing

DORA – comprehensive support from Cybernite

How is DORA implemented in Poland?

Unlike directives, DORA is an EU regulation. It therefore applies directly in every EU Member State without the need for national implementing legislation.

Poland has nevertheless adopted the Act Amending Certain Acts in Connection with Ensuring the Digital Operational Resilience of the Financial Sector. The Act serves as a “technical bridge”: it designates the Polish Financial Supervision Authority (KNF) as the authority responsible for supervising compliance with DORA in Poland and aligns Polish legislation, including banking legislation, with EU requirements.

What is the purpose of DORA?

The main objectives of DORA are to:

  1. ensure the continuity of financial services in the EU;
  2. strengthen the resilience of financial institutions to ICT-related incidents;
  3. harmonise ICT risk-management requirements;
  4. improve oversight of ICT third-party service providers; and
  5. reduce the impact of system failures, cyberattacks and technological errors.

DORA is based on the premise that digital disruption in the financial sector can have serious systemic consequences - not only for an individual firm but for the economy as a whole.

Who does DORA apply to?

DORA applies to a broad range of financial-sector entities, including:

  • banks and branches of foreign banks;
  • payment institutions and electronic money institutions;
  • investment firms;
  • investment fund and pension fund management companies;
  • insurance and reinsurance undertakings;
  • stock exchanges, clearing houses and central securities depositories;
  • crypto-asset service providers; and
  • certain ICT third-party service providers serving the financial sector.

The Regulation has a very broad scope, covering both large institutions and smaller entities. The requirements are proportionate to each entity’s size and risk profile.

Key requirements for businesses

DORA is built around five pillars that every institution must address.

  1. ICT risk management

Institutions must maintain a robust ICT risk-management framework. The company’s management body bears ultimate responsibility for cybersecurity. It must regularly approve strategies and security budgets and undertake relevant training.

  1. ICT-related incident reporting

DORA establishes a harmonised framework for reporting major ICT-related incidents. Firms must classify system failures and cyberattacks against defined criteria and report them to the supervisory authorities within tight deadlines.

  1. Digital operational resilience testing

This is one of the most demanding requirements. Entities must test their systems regularly, for example by conducting penetration tests. The largest institutions must carry out advanced threat-led penetration testing (TLPT) – controlled attacks performed by ethical hackers – once every three years.

  1. ICT third-party risk management

Financial firms must carry out thorough due diligence on their IT service providers, including cloud service providers. Contracts with those providers must contain specific provisions on service levels, security, and audit rights.

  1. Information sharing

DORA encourages institutions to share information voluntarily about cyber threats and malware, enabling the sector as a whole to respond more quickly to new attack methods.

The Polish Financial Supervision Authority publishes relevant delegated and implementing EU acts on an ongoing basis, including criteria for designating critical providers and classifying incidents.

The European Supervisory Authorities (EBA, ESMA and EIOPA) have issued Level 2 measures (RTS/ITS) setting out detailed rules on incident classification, reporting, testing requirements, and ICT third-party risk management.

What are the penalties for non-compliance with DORA?

DORA requires Member States to introduce effective and dissuasive penalties. In Poland, these may include:

  • substantial financial penalties;
  • administrative orders requiring infringements to be remedied;
  • restrictions on or withdrawal of authorisations;
  • liability of members of the management body; and
  • increased supervision and inspections by the Polish Financial Supervision Authority.

The precise level of a penalty depends on the type of entity and the nature of the infringement.

Supervisory authorities may conduct inspections, order remedial action, impose restrictions and levy financial penalties. In practice, financial entities may face penalties of up to 2% of total worldwide turnover, while critical ICT third-party service providers may face penalties of up to EUR 5 million. Agreements with providers may also be suspended or terminated if they threaten operational resilience. Specific thresholds may arise from EU legislation, national law, and supervisory decisions.

What does this mean for businesses?

  • a structured ICT risk-management framework and continuous resilience testing;
  • rapid, standardised reporting of major ICT-related incidents;
  • stringent contractual requirements for ICT providers, including concentration-risk controls and oversight of critical providers; and
  • readiness for KNF inspections and potential sanctions for non-compliance.

Summary

In summary, DORA:

  • applies to most of the EU financial sector;
  • focuses on digital operational resilience;
  • introduces obligations relating to ICT risk and third-party service providers; and
  • has applied directly in Poland since 17 January 2025.

For businesses, the message is clear: stable IT systems and continuity of financial services are now key legal and strategic obligations.

Prepared by Professor Grzegorz Strupczewski

Through Cybernite Status we help organisations assess their current cybersecurity posture and regulatory readiness.

Through Cybernite Safe, we provide ongoing support with cybersecurity management, regulatory obligations, and compliance with industry standards under a Cybersecurity as a Service (CSaaS) model.

Do you need support with NIS2, the CRA, DORA or the AI Act – from determining whether the requirements apply and conducting a gap analysis to reviewing the measures already taken and addressing any remaining gaps?
Cybernite can help you organise your documentation, implement the missing measures and maintain compliance in practice.

Book a free consultation