Industries in Focus

DORA: What banks and financial institutions must implement now

DORA: What banks and financial institutions must implement now

DORA: What banks and financial institutions must implement now

Last updated:

8 min.

Dr. Dr. Fabian Teichmann is a lawyer, researcher, and one of the leading experts on cybersecurity compliance in the German-speaking region. He advises companies on NIS2 and KRITIS and has published over 200 academic papers.

Dr. Dr. Fabian Teichmann is a lawyer, researcher, and one of the leading experts on cybersecurity compliance in the German-speaking region. He advises companies on NIS2 and KRITIS and has published over 200 academic papers.

Share

Based on the research work of Dr. iur. Dr. rer. pol. Fabian M. A. Teichmann

Since January 17, 2025, it has been binding in all EU member states: the Digital Operational Resilience Act, or DORA for short. For banks, insurance companies, investment firms, and dozens of other financial actors, this means: a fundamentally new legal framework for IT security and digital operational resilience – directly applicable, without any national implementation act, and with severe sanctions for non-compliance.

What was previously considered an administrative circular in Germany – BAIT for banks, VAIT for insurers – has been replaced by an EU regulation that is significantly more specific, binding, and stringent. Teichmann has systematically analyzed DORA in several scientific publications. The message for practice is clear: anyone who views DORA as a mere continuation of previous IT requirements underestimates the scale of the change.

What DORA is – and why it was created

The Digital Operational Resilience Act (Regulation EU 2022/2554) is the result of a long-standing realization: the financial sector is system-critical – and, at the same time, technologically more dependent than any other. A severe IT failure at a major bank or a central payment service provider can jeopardize the stability of the entire financial system. Previous regulation was fragmented: differing national requirements, sectoral guidelines, and inconsistent standards. DORA establishes, for the first time, a harmonized, binding EU framework for the digital operational resilience of the entire financial sector (Teichmann, Digital Operational Resilience Act – EU-weit einheitliche IT-Sicherheitsregeln für Finanzinstitute, BB 2025, pp. 2760–2770).

The political urgency was real: the European Central Bank warned in its Financial Stability Review 2022 of increased cyber risks and a growing need for investment in IT security. State-sponsored hacker attacks in the context of geopolitical conflicts, ransomware attacks on systemically important infrastructures, and the increasing reliance on cloud computing made it clear that isolated national regulations were insufficient.

DORA pursues a dual objective: preventively, financial institutions must implement robust ICT risk management frameworks to avoid incidents or limit their impact. Reactively, standardized processes for incident response and crisis management are intended to ensure rapid and coordinated action in an emergency (Teichmann, BB 2025, pp. 2760–2770).

Who is affected: Almost the entire financial sector

The scope of DORA is remarkably broad. It covers over 20 types of financial entities, including credit institutions, payment and electronic money institutions, investment firms, insurance and reinsurance undertakings, investment fund management companies, central securities depositories, central counterparties, crypto-asset service providers under MiCA, credit rating agencies, as well as trading venues and other financial market infrastructures (Teichmann, BB 2025, pp. 2760–2770).

Particularly important: DORA does not just cover financial entities themselves; it also addresses their IT service providers – cloud providers, data center operators, software vendors – through third-party risk management. Critical ICT third-party service providers can even be subjected to direct European supervision. This is one of the most far-reaching innovations of DORA: for the first time, the entire IT supply chain is systematically regulated.

In Germany, VAIT, KAIT, and ZAIT were repealed with effect from January 17, 2025. The BAIT remain in force on a transitional basis for certain smaller institutions until the end of 2026. For the vast majority of financial institutions, DORA is already the primary set of rules today (Teichmann, DORA – Teil 1: Ein einheitlicher Rechtsrahmen für die IT- und Cybersicherheit, ZRFC 2025, pp. 172–175).

The Five Pillars of DORA

First Pillar: ICT Risk Management. At the heart of DORA is the mandate for a comprehensive ICT risk management framework. All financial entities must continuously identify, analyze, assess, treat, and monitor ICT risks. This includes an ICT strategy as an integral part of the overall corporate strategy, clear responsibilities at the board level, systematic vulnerability management, data encryption, network segregation, and firewall management. Particularly new: DORA explicitly requires that legacy systems and new technologies undergo special assessment – the regulation recognizes that many financial institutions operate with outdated IT infrastructure and makes the risk management of these legacy systems an explicit obligation.

Second Pillar: ICT-related Incident Reporting. DORA introduces a harmonized, three-step reporting procedure for major ICT-related incidents. An initial notification must be submitted to BaFin within four hours of classification. An intermediate report must follow within 72 hours, and a final report within one month. What constitutes a major incident is defined by DORA based on concrete criteria: the number of affected clients, the duration of the operational disruption, reputational damage, and financial impacts. DORA acts as a lex specialis – the notification to BaFin generally replaces the NIS 2 notification to the BSI (Teichmann, BB 2025, pp. 2760–2770).

Third Pillar: Digital Operational Resilience Testing. DORA introduces mandatory, regular testing of digital operational resilience. All financial entities must conduct basic resilience tests at least annually: vulnerability assessments, network-based tests, physical security reviews, and scenario-based tests. For significant institutions, a crucial requirement is added: threat-led penetration testing (TLPT), which must be carried out at least every three years by accredited external testers based on current threat scenarios (Teichmann, DORA – Teil 2: IKT-Risikomanagement, Resilienztests und Drittparteienkontrolle, ZRFC 2025, pp. 273–278).

Fourth Pillar: Managing ICT Third-Party Risk. This is perhaps the most impactful innovation for practical application. DORA requires financial entities to systematically manage their overall reliance on external IT service providers – with minimum requirements for contracts, continuous monitoring, exit strategies, and risk concentration analyses. In the future, contracts with ICT service providers must include mandatory minimum clauses: a complete description of services, key performance indicators, security requirements, audit rights for the financial entity and the supervisory authority, as well as provisions on business continuity and termination. Existing contracts must be adjusted accordingly. For ICT providers classified as critical, DORA introduces a completely new instrument: direct European supervision by the EBA, EIOPA, or ESMA (Teichmann, ZRFC 2025, pp. 273–278).

Fifth Pillar: Information Sharing. DORA explicitly encourages financial entities to share information about cyber threats among themselves – within clearly defined legal boundaries. Threat intelligence, attack patterns, and insights from incidents are to be shared in order to strengthen the resilience of the entire sector.

Governance: IT Resilience Becomes a Boardroom Issue

A central principle of DORA is the explicit responsibility of senior management. The management body bears the ultimate responsibility for managing ICT risks. It must define and approve the ICT strategy, possess sufficient expertise in IT risks, and receive regular training. A board member who claims not to understand anything about IT security does not meet the requirements of DORA (Teichmann, DORA – Teil 3: Governance-Verantwortung und Compliance-Risiken, ZRFC 2025, pp. 279–283).

Teichmann analyzes that the governance requirements of DORA, in combination with general corporate law, can lead to personal internal liability for senior management if ICT obligations have been systematically neglected and damage occurs as a result (Teichmann, ZRFC 2025, pp. 279–283).

What Practice Must Do Now

DORA is not a complete novelty for many financial institutions – its contents overlap significantly with BAIT, MaRisk, and EBA guidelines. The decisive difference lies in the level of binding force and detail. What was previously formulated as a supervisory expectation is now regulatory law with direct sanctioning effect.

Specifically, financial institutions must address three main gaps. The first concerns third-party management: existing contracts with IT service providers must be reviewed and adjusted for DORA compliance – particularly cloud contracts, which often do not contain sufficient audit rights and exit clauses. The second gap is in the testing regime: penetration testing according to the TLPT standard is new for many firms and requires organizational preparation. The third gap relates to emergency planning: DORA explicitly requires that scenarios such as climate events, insider attacks, and large-scale power outages be taken into account in business continuity plans – requirements that many previous BCM concepts do not cover (Teichmann, ZRFC 2025, pp. 273–278).

Conclusion: DORA is Not a Box-Ticking Exercise – It is a Cultural Shift

DORA is more than just another set of rules to be ticked off. It is a mandate to the entire European financial sector to understand IT security and digital operational resilience as a core strategic task – not as a peripheral technical issue.

Teichmann's research shows: financial institutions that take DORA seriously and implement it consistently will become more resilient to cyberattacks, legally more secure in their dealings with supervisors, and ultimately more trustworthy in the eyes of customers and business partners. DORA is not an endpoint, but rather the beginning of a new era of regulated digital resilience in the financial sector.

All citations refer to published scientific contributions by Dr. iur. Dr. rer. pol. Fabian M. A. Teichmann. The complete bibliography is documented in the publication index (as of May 2026).



Dr. Dr. Fabian Teichmann is a lawyer, researcher, and one of the leading experts on cybersecurity compliance in the German-speaking region. He advises companies on NIS2 and KRITIS and has published over 200 academic papers.

Share

We use cookies to improve your experience. By continuing, you agree to our cookie policy.