The European regulation on the digital operational resilience of the financial sector (DORA) requires financial entities - and, by extension, their ICT providers - to maintain an exhaustive register of contracts, precise contractual clauses and dated audit evidence. SYAGA DORA-Express helps you meet these requirements without improvising, whether you are a financial entity or a provider.
DORA is a regulation, not a directive: it applies directly in all member states, with no national transposition law to wait for.
Regulation (EU) 2022/2554 of 14 December 2022, published in the Official Journal of the EU on 27 December 2022, entered into force on 16 January 2023 and applicable since 17 January 2025. No national transposition required: it is directly enforceable.
Every financial entity must maintain and transmit annually to the authorities a complete register of its ICT contracts: provider, nature of the service, criticality of the function, country where the data is hosted.
Audit and inspection rights, guarantees of data availability and integrity, tested exit plans, incident notification without delay. These clauses cascade down from your financial client to you if you are its ICT provider.
Before signing or renewing a contract, a bank, insurer or investor sends a cyber questionnaire (governance, MFA, EDR, encryption, awareness training). Answering without documented evidence costs you the contract.
On 18-19 November 2025, the European Supervisory Authorities (EBA, ESMA, EIOPA) published the first official list of critical ICT third-party providers under Article 32 of DORA. Among the names confirmed by the official announcements: AWS EMEA Sarl, Microsoft Ireland Operations Limited, Google Cloud, Orange SA, Capgemini SE (and 14 other providers not confirmed by name in our sources).
Concrete consequence: if your critical services rely on one of these providers, your financial client must now document this in its ICT register - and may question you about your own subcontracting chain.
Source: official EIOPA and ESMA announcements of 18-19 November 2025 (eiopa.europa.eu, esma.europa.eu).
A structured 5-step engagement to document your compliance - without promising what neither a tool nor a firm can certify on your behalf.
Are you a financial entity directly subject to DORA (one of the 21 categories in article 2), or an ICT provider indirectly targeted through the contractual clauses of your financial clients (article 30)? The exact scope determines everything else.
We answer your bank, investor or insurer due diligence questionnaire (governance, MFA, EDR, encryption, awareness training...), relying on a technical audit of your Microsoft 365 tenant as dated, verifiable evidence.
We help you structure your ICT contracts register (art. 28 §3) and check or integrate the minimum and enhanced contractual clauses of article 30 into your provider contracts.
Our BCP/DRP Suite offers a Finance sector profile (DORA, PSD2, ACPR) that covers the operational resilience testing requirements of Chapter IV of DORA, aligned with ISO 22301.
Delivery to your management, CISO or CFO of a consolidated file, with the precise points to be decided by your legal counsel before any communication to the authorities.
Concrete, sourced deliverables, with no certification promise that no one can guarantee
10 typical bank / M&A due diligence questions, documented and sourced (ILPA DDQ, CSA CAIQ, cyber insurer questionnaires).
Sourced summary of Regulation (EU) 2022/2554.
Structure of the exhaustive register required by the authorities.
To be integrated or checked in your ICT provider contracts.
Business continuity and disaster recovery plan, dedicated sector profile.
PDF and DOCX formats, consolidating the full set of deliverables.
Excerpt of the 10 questions we document for you, with the source for each question
| Topic | Question | Source |
|---|---|---|
| Governance | Is your security policy based on a recognized framework (NIST, ISO 27001)? | ILPA DDQ 2.0 |
| Third-party audit | Do you carry out an annual independent audit and penetration tests? | CSA CAIQ v4 |
| Incident plan | Is there a formal, documented and maintained incident response plan? | CSA CAIQ v4 / ILPA DDQ 2.0 |
| MFA | For which services do you enforce multi-factor authentication? | Travelers - MFA Supplement |
| Privileged accounts | Do access rights follow the least-privilege principle, reviewed periodically? | CSA CAIQ v4 IAM |
| Messaging | Which M365 license do you use? Is Defender / advanced threat hunting active? | vCSO.ai Cyber DD Checklist |
| Encryption | Are endpoint disks fully encrypted? | Google VSAQ |
| Training | Is a security awareness program established for all staff? | CSA CAIQ v4 HRS |
Each deliverable explicitly states what it covers - and what it does not
ICT register (art. 28), contractual clauses (art. 30), notification deadlines (art. 19), reference to designated critical ICT providers (art. 32).
DORA is a lex specialis relative to NIS2 for the financial sector: the entities concerned apply DORA instead of the equivalent NIS2 measures.
The BCP/DRP Finance profile is aligned with ISO 22301, the business continuity management framework used to complement DORA.
The DORA incident notification (ACPR/AMF, the French authorities) is separate from the GDPR notification (to the competent data protection authority, the CNIL in France) in the event of a personal data breach: both may be required simultaneously.
Every DORA file is different depending on your status - a personalized quote in every case
You supply services to one or more financial entities
You are directly subject to DORA (one of the 21 categories, art. 2)
Regular update of the file (obligations, contracts, register)
DORA explained simply, without legal jargon. Each point below links to the official text that confirms it.
DORA applies to European financial players: banks, insurers, investment firms, trading venues, fund managers, payment providers... as well as their IT providers. Very small structures benefit from lighter rules.
The regulation covers 6 major topics: ICT risk management, oversight of your external providers, regular resilience testing, reporting of major incidents, threat information sharing, and oversight of the largest ICT providers.
Text adopted on 14 December 2022, published in the EU Official Journal on 27 December 2022 (OJ L 333). Entered into force on 16 January 2023. The obligations have genuinely been due since 17 January 2025.
The largest IT providers (cloud, hosting...) deemed "critical" for the financial sector are now directly overseen at European level, with a lead overseer that can impose measures on them.
Before DORA, each EU country had its own rules for reporting a serious IT incident. Now a single European procedure applies: major incidents are reported directly to the competent authorities.
The text provides that authorities publish the administrative penalties they impose. The precise fine amounts are not stabilized in the sources consulted to date - to be confirmed as official clarifications emerge.
You keep hearing about DORA without knowing whether it applies to you? Here, explained simply, is the official scope of the regulation, understood in 2 minutes, with the texts that prove it.
European Regulation 2022/2554 (Article 2) targets 21 different categories of financial companies, 12 of which are supervised by ESMA. This isn't a matter reserved for large banks: since 17 January 2025, nearly the entire European financial sector is affected, with different levels of requirement depending on the size of the structure. official source (ESMA) ↗
Credit institutions (banks), payment institutions, electronic money institutions, account information service providers.
Investment firms, trading venues, central securities depositories, central counterparties, trade repositories, credit rating agencies, alternative fund managers, management companies.
Insurance and reinsurance undertakings, insurance intermediaries (excluding micro-enterprises), institutions for occupational retirement provision with more than 15 members.
Crypto-asset service providers, crowdfunding platforms, securitisation repositories: digital finance also falls within scope.
The ICT providers (cloud, hosting, critical software) that run these companies are also on the radar. The most "critical" ones for the whole sector are directly overseen at European level.
DORA applies a proportionality principle: the smaller a structure, the lighter its obligations. Some structures are even explicitly out of scope.
A micro-enterprise is officially defined as a structure with fewer than 10 employees whose annual turnover or balance sheet does not exceed 2 million euros. These very small financial structures are exempt from the regulation's heaviest governance obligations.
official source (EUR-Lex, EU definition) ↗ · EUR-Lex source (DORA regulation) ↗
Small "non-interconnected" investment firms and small institutions for occupational retirement provision benefit from a simplified ICT risk management framework, detailed by a delegated regulation of the European Commission.
An institution for occupational retirement provision whose scheme(s) have 15 members or fewer in total does not fall within the scope of the regulation.
Also out of scope: postal giro institutions covered by the credit institutions directive, certain fund managers or insurers benefiting from sectoral exemptions, as well as insurance intermediaries that are themselves micro-enterprises or SMEs.
In plain terms: if your company is a European financial entity, or if you are one of its IT providers, the question is no longer "am I affected" but "at what level of requirement". The text specifies that each structure must adapt its IT resources to its size, risk profile and the complexity of its activities. EUR-Lex source (recital 36) ↗
DORA isn't "a" date - it's several stages that have followed one another since late 2022. Here, in order, is what has already happened and what is still in progress, with, for each stage, the official text that proves it.
The European Parliament and the Council adopt Regulation (EU) 2022/2554. EUR-Lex source ↗
The text is published in the Official Journal of the European Union (OJ L 333). EUR-Lex source ↗
The regulation legally exists, but its effective application to companies is still deferred by two years - the time needed to prepare the technical standards and registers. ESMA source ↗
The three European financial supervisory authorities (banking, insurance, markets) hold two public hearings to finalize the practical implementation rules. ESMA source ↗
First set of precise rules on ICT risk management (how to map, protect, detect, respond), adopted by the Commission on 13 March 2024. EUR-Lex source (2024/1774) ↗
Second set of implementing rules (notably on ICT subcontracting and oversight of providers). ESMA source ↗
The Commission publishes the technical template (forms) that every affected company must use to keep its inventory of IT providers up to date. Entered into force on 22 December 2024. EUR-Lex source (2024/2956) ↗
From this date, all affected financial entities (and their strategic IT providers) must be in genuine compliance, not just "on paper". ESMA source ↗ · EIOPA source ↗
National supervisory authorities were to report to the European authorities the first registers of information received from covered companies. ESMA source ↗
The European authorities are building, step by step, the list of IT providers (cloud, hosting...) deemed so important for the whole financial sector that they will be directly overseen at European level. The process (information gathering, decisions, progress report) ran from November 2024 to May 2025; the exact date of the first official designation is not stabilized in the sources consulted to date - to be confirmed as publications emerge. ESMA source ↗
The European authorities continue to publish progress reports (lessons learned on major incidents, adjustments to subcontracting rules). DORA is a living project, not a fixed text. ESMA source ↗
Calendar compiled from official sources (EUR-Lex, ESMA, EIOPA) consulted on 17 July 2026. Some dates (final designation of critical providers, penalty amounts) are still being stabilized by the authorities - we will update them as soon as they are published.
7 more technical questions, digested simply: each sourced from the official text that confirms it.
EUR-Lex source (recitals 43, 56, 61) ↗ · ESMA source (Delegated Regulation (EU) 2025/1190) ↗
EUR-Lex source (recital 65) ↗ · ESMA source (Implementing Regulation (EU) 2024/2956) ↗
"DORA provides for fines" comes up often in sales pitches. What the official text actually says, in black and white: two distinct regimes, with a single harmonized European figure - and no single scale for everyone.
DORA sets no amount or percentage of turnover. The text explicitly leaves it to each Member State to set its own penalty rules (Article 50, §3: "Member States shall lay down rules establishing appropriate administrative penalties..."). In France, it is your usual authorities - ACPR for banking/insurance, AMF for markets - that apply their own national scale, not a single harmonized European DORA scale.
What the regulation does impose, however: types of measures that each country must provide for at a minimum (list below) - it is up to national law to set the exact amounts.
Here, DORA sets a precise figure, harmonized across all of Europe: a periodic penalty payment of up to 1% of average daily worldwide turnover, per day of delay, for a maximum of 6 months (Article 35, §7-8). This is not an immediate sanction: it can only be triggered after at least 30 calendar days of non-compliance found by the authority.
This penalty payment concerns only the large providers officially designated "critical" by the EU - not the client companies that use them.
This is the periodic penalty payment that the "Lead Overseer" - one of the three European financial supervisory authorities (EBA, ESMA or EIOPA, designated per provider) - can impose on a critical IT provider that refuses to come into compliance after a period of at least 30 days. The money is paid into the general budget of the European Union, and each penalty payment imposed must in principle be made public by the Lead Overseer.
Source: Regulation (EU) 2022/2554, Article 35, paragraphs 6 to 10 - official EUR-Lex text ↗
Five types of measures that each Member State must provide for at a minimum in its national law - Article 50, §4 of DORA.
Require the company to immediately stop the non-compliant practice and not resume it.
Prohibit a practice or conduct deemed contrary to the regulation, temporarily or permanently.
Any measure, including financial, to bring the company back into compliance - amount set by the national law of each country.
Require existing records from a telecom operator, in the event of reasonable suspicion of a breach.
Make public a notice indicating the identity of the company and the nature of the breach ("name and shame").
To calibrate the exact level of the penalty, Article 51§2 of DORA requires the authority to take into account, among other things: the gravity and duration of the breach, the degree of responsibility, the financial soundness of the company, profits gained or losses avoided, damage caused to third parties, the level of cooperation, and prior record.
Analysis based on the full reading of Articles 35 and 50 to 53 of Regulation (EU) 2022/2554, official text published in the EU Official Journal (L 333, 27/12/2022), consulted on EUR-Lex on 17 July 2026. No specific penalty amount exists in the text for financial entities (reference to the national law of each Member State) - we therefore do not invent one. No periodic penalty payment under Article 35 is publicly recorded to date in our sources; DORA has only been fully applicable since 17 January 2025.
Contact us to receive a personalized quote based on your status (financial entity or ICT provider).
Free: your score + your gaps. The detailed report and the attestation: 499 EUR excl. VAT, only if you decide to.
contact@syaga.eu