Skip to content
Compliance & Legal

DORA Digital Operational Resilience Act

The European regulation on digital operational resilience applicable to financial entities and their ICT suppliers.

Full definition

DORA (Digital Operational Resilience Act, EU Regulation 2022/2554) is the European regulation that establishes harmonised requirements for digital operational resilience for financial entities — banks, insurers, asset managers, fintechs — and, crucially, for their critical ICT suppliers (ICT third-party risk management). It came into force in January 2025.

The DORA pillars include: ICT risk management with executive-level governance, reporting of significant incidents within tight windows, operational resilience testing (including advanced penetration testing for larger entities), supplier risk management, and threat-information sharing between entities in the financial ecosystem.

For ICT suppliers serving financial entities (and INFOS fits several scenarios via banking customers), DORA means explicit contractual obligations, regular audits by customers, and potential direct supervision by European authorities in the case of suppliers classified as critical. INFOS has been reinforcing its DORA-ready compliance posture precisely to continue serving financial customers without friction.

Talk to a specialist

Let's talk.
We'll come back within 24h with next steps.

No complicated forms. One email or call, a team that knows your sector, and a concrete path forward — whether MULTI, MAXIRETAIL, KORA, PPLPORTAL or infrastructure.

Talk to a specialist

Book a demo

Leave your details and we'll get back to you within one business day with next steps.