Structured, sourced documentary assistance. This service does not constitute legal advice: the legally binding aspects require a qualified professional (lawyer, DPO or certified auditor).
REGULATION (EU) 2022/2554 - APPLICABLE SINCE 17 JANUARY 2025

Your DORA compliance,
documented and defensible

The European regulation on the digital operational resilience of the financial sector (DORA) requires financial entities - and, by extension, their ICT providers - to maintain an exhaustive register of contracts, precise contractual clauses and dated audit evidence. SYAGA DORA-Express helps you meet these requirements without improvising, whether you are a financial entity or a provider.

17/01
Applicable since 2025
21
Categories of entities in scope (art. 2)
4h
Notification deadline for a major incident
19
Critical ICT providers already designated

The regulatory context

DORA is a regulation, not a directive: it applies directly in all member states, with no national transposition law to wait for.

DORA has applied directly since 17 January 2025

Regulation (EU) 2022/2554 of 14 December 2022, published in the Official Journal of the EU on 27 December 2022, entered into force on 16 January 2023 and applicable since 17 January 2025. No national transposition required: it is directly enforceable.

📋

An exhaustive ICT register is required (art. 28 §3)

Every financial entity must maintain and transmit annually to the authorities a complete register of its ICT contracts: provider, nature of the service, criticality of the function, country where the data is hosted.

📄

Your contracts must contain precise clauses (art. 30)

Audit and inspection rights, guarantees of data availability and integrity, tested exit plans, incident notification without delay. These clauses cascade down from your financial client to you if you are its ICT provider.

📧

The due diligence questionnaire is already in your inbox

Before signing or renewing a contract, a bank, insurer or investor sends a cyber questionnaire (governance, MFA, EDR, encryption, awareness training). Answering without documented evidence costs you the contract.

The 18 November 2025 trigger

Your cloud providers have just been officially designated "critical"

On 18-19 November 2025, the European Supervisory Authorities (EBA, ESMA, EIOPA) published the first official list of critical ICT third-party providers under Article 32 of DORA. Among the names confirmed by the official announcements: AWS EMEA Sarl, Microsoft Ireland Operations Limited, Google Cloud, Orange SA, Capgemini SE (and 14 other providers not confirmed by name in our sources).

Concrete consequence: if your critical services rely on one of these providers, your financial client must now document this in its ICT register - and may question you about your own subcontracting chain.

Source: official EIOPA and ESMA announcements of 18-19 November 2025 (eiopa.europa.eu, esma.europa.eu).

Our response: DORA-Express

A structured 5-step engagement to document your compliance - without promising what neither a tool nor a firm can certify on your behalf.

1
Step 1 - Qualification

Let's identify your actual exposure

Are you a financial entity directly subject to DORA (one of the 21 categories in article 2), or an ICT provider indirectly targeted through the contractual clauses of your financial clients (article 30)? The exact scope determines everything else.

2
Step 2 - Due diligence

Response to your cyber questionnaire

We answer your bank, investor or insurer due diligence questionnaire (governance, MFA, EDR, encryption, awareness training...), relying on a technical audit of your Microsoft 365 tenant as dated, verifiable evidence.

3
Step 3 - Register and contracts

ICT register and article 30 clauses

We help you structure your ICT contracts register (art. 28 §3) and check or integrate the minimum and enhanced contractual clauses of article 30 into your provider contracts.

4
Step 4 - Continuity and resilience

BCP/DRP Finance sector profile

Our BCP/DRP Suite offers a Finance sector profile (DORA, PSD2, ACPR) that covers the operational resilience testing requirements of Chapter IV of DORA, aligned with ISO 22301.

5
Step 5 - Handover

A documented compliance file

Delivery to your management, CISO or CFO of a consolidated file, with the precise points to be decided by your legal counsel before any communication to the authorities.

What you receive

Concrete, sourced deliverables, with no certification promise that no one can guarantee

📝

Cyber due diligence answers

10 typical bank / M&A due diligence questions, documented and sourced (ILPA DDQ, CSA CAIQ, cyber insurer questionnaires).

  • Security policy / recognized framework
  • MFA, least privilege, privileged accounts
  • M365 license, EDR / threat hunting
  • Legacy protocols, disk encryption
  • Awareness program
📄

DORA reference sheet

Sourced summary of Regulation (EU) 2022/2554.

  • Scope: 21 categories of entities (art. 2)
  • 5 areas of obligations
  • Notification deadlines (4h / 72h / 1 month)
  • Interplay with NIS2 (lex specialis)
📋

ICT register (art. 28 §3 template)

Structure of the exhaustive register required by the authorities.

  • Provider and nature of the service
  • Criticality of the supported function
  • Country where the data is hosted
  • Format ready for annual submission
🔐

Contractual clauses (art. 30 template)

To be integrated or checked in your ICT provider contracts.

  • Minimum clauses (all contracts)
  • Enhanced clauses (critical functions)
  • Audit and inspection rights
  • Exit plans and data extractability
🏗

BCP/DRP Finance profile

Business continuity and disaster recovery plan, dedicated sector profile.

  • Covers Chapter IV DORA (resilience testing)
  • Aligned with ISO 22301
  • DORA / PSD2 / ACPR sector profile
  • Built on our existing BCP/DRP Suite
💾

Documented compliance file

PDF and DOCX formats, consolidating the full set of deliverables.

  • Ready for your management / CISO / CFO
  • Points to be validated by your lawyer flagged
  • Basis for your exchanges with ACPR / AMF (the French authorities)
  • Editable for annual updates

An example: the bank due diligence questionnaire

Excerpt of the 10 questions we document for you, with the source for each question

Topic Question Source
Governance Is your security policy based on a recognized framework (NIST, ISO 27001)? ILPA DDQ 2.0
Third-party audit Do you carry out an annual independent audit and penetration tests? CSA CAIQ v4
Incident plan Is there a formal, documented and maintained incident response plan? CSA CAIQ v4 / ILPA DDQ 2.0
MFA For which services do you enforce multi-factor authentication? Travelers - MFA Supplement
Privileged accounts Do access rights follow the least-privilege principle, reviewed periodically? CSA CAIQ v4 IAM
Messaging Which M365 license do you use? Is Defender / advanced threat hunting active? vCSO.ai Cyber DD Checklist
Encryption Are endpoint disks fully encrypted? Google VSAQ
Training Is a security awareness program established for all staff? CSA CAIQ v4 HRS

Texts and frameworks covered

Each deliverable explicitly states what it covers - and what it does not

DO

DORA (Regulation (EU) 2022/2554)

ICT register (art. 28), contractual clauses (art. 30), notification deadlines (art. 19), reference to designated critical ICT providers (art. 32).

N2

NIS2 - interplay with DORA

DORA is a lex specialis relative to NIS2 for the financial sector: the entities concerned apply DORA instead of the equivalent NIS2 measures.

ISO

ISO 22301 - business continuity

The BCP/DRP Finance profile is aligned with ISO 22301, the business continuity management framework used to complement DORA.

RG

GDPR - separate notification

The DORA incident notification (ACPR/AMF, the French authorities) is separate from the GDPR notification (to the competent data protection authority, the CNIL in France) in the event of a personal data breach: both may be required simultaneously.

An engagement tailored to your situation

Every DORA file is different depending on your status - a personalized quote in every case

ICT provider

You supply services to one or more financial entities

Quote
depending on scope
  • Cyber due diligence response
  • ICT register, provider-side
  • Review of article 30 clauses
  • Documented file ready to submit
Request a quote

Annual follow-up

Regular update of the file (obligations, contracts, register)

Quote
recurring
  • ICT register update
  • Annual review of contractual clauses
  • Monitoring of designated critical providers
  • Support for your client due diligences
Request a quote

Frequently asked questions

Is my company a financial entity in scope of DORA?
Article 2 of DORA lists 21 categories of financial entities: credit and payment institutions, investment firms, MiCA-authorized crypto-asset providers, insurance and reinsurance, fund management, credit rating agencies, and others. Microenterprises (fewer than 10 employees, turnover or balance sheet below 2 million euros) benefit from proportionality on certain obligations, but are not fully excluded. To be checked case by case with legal counsel.
I'm not a bank, why does DORA concern me anyway?
If you provide ICT services (IT, cloud, software, hosting) to a financial entity, article 30 requires your client to list you in its register and to impose precise contractual clauses on you: audit rights, incident notification without delay, exit plans. These obligations flow through your client's contract, not through direct supervision by the authority - unless you are yourself designated a critical ICT provider (article 31).
What are the notification deadlines for a major ICT incident?
Article 19: initial notification within 4 hours of classification as a major incident (at most 24 hours after detection), intermediate report within 72 hours, final report within 1 month. These notifications are separate from any GDPR notification to the competent data protection authority (the CNIL in France) in the event of a personal data breach.
What is a "critical ICT provider"?
These are providers explicitly designated by the European Supervisory Authorities (EBA, ESMA, EIOPA) based on criteria of systemic impact, substitutability and dependency (article 31). The first official list, published on 18-19 November 2025, includes 19 providers. They are subject to direct supervision (inspections, extended reporting); other ICT providers remain governed solely by the contractual clauses of their financial clients.
Does DORA replace NIS2 for my sector?
Yes, for financial entities within the meaning of article 2: DORA constitutes a lex specialis relative to NIS2 for the financial sector. The 21 categories concerned apply DORA instead of the equivalent NIS2 measures on risk management and incident notification.
Does this service constitute legal advice?
No. DORA-Express is a documentation support tool, not legal advice. The exact applicability of DORA to your organization and the legal compliance of your contracts must be validated by a specialized lawyer before any binding decision.

Regulatory watch - official sources

DORA explained simply, without legal jargon. Each point below links to the official text that confirms it.

Who is affected?

DORA applies to European financial players: banks, insurers, investment firms, trading venues, fund managers, payment providers... as well as their IT providers. Very small structures benefit from lighter rules.

official source (EUR-Lex) ↗

What DORA concretely requires of you

The regulation covers 6 major topics: ICT risk management, oversight of your external providers, regular resilience testing, reporting of major incidents, threat information sharing, and oversight of the largest ICT providers.

official source (EIOPA) ↗

The dates to remember

Text adopted on 14 December 2022, published in the EU Official Journal on 27 December 2022 (OJ L 333). Entered into force on 16 January 2023. The obligations have genuinely been due since 17 January 2025.

EUR-Lex source ↗ · ESMA source ↗

Your IT providers are also monitored

The largest IT providers (cloud, hosting...) deemed "critical" for the financial sector are now directly overseen at European level, with a lead overseer that can impose measures on them.

official source (EIOPA) ↗

Incident reporting, finally harmonized

Before DORA, each EU country had its own rules for reporting a serious IT incident. Now a single European procedure applies: major incidents are reported directly to the competent authorities.

EUR-Lex source ↗

And the penalties?

The text provides that authorities publish the administrative penalties they impose. The precise fine amounts are not stabilized in the sources consulted to date - to be confirmed as official clarifications emerge.

EUR-Lex source (recital 97) ↗

DORA: who is really affected?

You keep hearing about DORA without knowing whether it applies to you? Here, explained simply, is the official scope of the regulation, understood in 2 minutes, with the texts that prove it.

European Regulation 2022/2554 (Article 2) targets 21 different categories of financial companies, 12 of which are supervised by ESMA. This isn't a matter reserved for large banks: since 17 January 2025, nearly the entire European financial sector is affected, with different levels of requirement depending on the size of the structure. official source (ESMA) ↗

🏦

Banking and payments

Credit institutions (banks), payment institutions, electronic money institutions, account information service providers.

  • Any commercial or cooperative bank
  • Licensed payment fintechs
  • Neobanks and electronic wallets
📈

Financial markets and investment

Investment firms, trading venues, central securities depositories, central counterparties, trade repositories, credit rating agencies, alternative fund managers, management companies.

  • Brokerage firms, brokers
  • Asset and fund managers
  • Credit rating agencies
🛡

Insurance and pensions

Insurance and reinsurance undertakings, insurance intermediaries (excluding micro-enterprises), institutions for occupational retirement provision with more than 15 members.

  • Insurers and mutual insurance companies
  • Insurance brokers (depending on size)
  • Occupational pension funds
🪙

New digital players

Crypto-asset service providers, crowdfunding platforms, securitisation repositories: digital finance also falls within scope.

  • Licensed crypto exchange platforms
  • Financial crowdfunding platforms
💻

Your IT providers

The ICT providers (cloud, hosting, critical software) that run these companies are also on the radar. The most "critical" ones for the whole sector are directly overseen at European level.

  • Cloud hosts used by a bank
  • Publishers of critical banking software

Not everyone has the same obligations

DORA applies a proportionality principle: the smaller a structure, the lighter its obligations. Some structures are even explicitly out of scope.

Micro-enterprises have lighter rules

A micro-enterprise is officially defined as a structure with fewer than 10 employees whose annual turnover or balance sheet does not exceed 2 million euros. These very small financial structures are exempt from the regulation's heaviest governance obligations.

official source (EUR-Lex, EU definition) ↗ · EUR-Lex source (DORA regulation) ↗

Small investment or pension structures

Small "non-interconnected" investment firms and small institutions for occupational retirement provision benefit from a simplified ICT risk management framework, detailed by a delegated regulation of the European Commission.

EUR-Lex source (recital 42) ↗

Very small pension schemes: out of scope

An institution for occupational retirement provision whose scheme(s) have 15 members or fewer in total does not fall within the scope of the regulation.

EUR-Lex source (Article 2) ↗

A few specific excluded cases

Also out of scope: postal giro institutions covered by the credit institutions directive, certain fund managers or insurers benefiting from sectoral exemptions, as well as insurance intermediaries that are themselves micro-enterprises or SMEs.

EUR-Lex source (Article 2) ↗

In plain terms: if your company is a European financial entity, or if you are one of its IT providers, the question is no longer "am I affected" but "at what level of requirement". The text specifies that each structure must adapt its IT resources to its size, risk profile and the complexity of its activities. EUR-Lex source (recital 36) ↗

The DORA calendar, made clear

DORA isn't "a" date - it's several stages that have followed one another since late 2022. Here, in order, is what has already happened and what is still in progress, with, for each stage, the official text that proves it.

Already mandatory today

  • The DORA regulation has fully applied since 17 January 2025.
  • The ICT risk management rules (1st batch of technical standards) are in force.
  • The "register of information" (the inventory of your ICT providers) is an active obligation.
  • Reporting of major ICT incidents already follows the DORA procedure.

Still being finalized

  • The official list of IT providers deemed "critical" for the whole of Europe (process launched late 2024, still being refined by the authorities).
  • Certain technical standards (including subcontracting) were sent back by the European authorities for correction and are not yet stabilized.
  • The European authorities' regular reviews (progress reports, lessons learned) continue at least until 2026.
1
14 December 2022

The text is adopted

The European Parliament and the Council adopt Regulation (EU) 2022/2554. EUR-Lex source ↗

2
27 December 2022

Official publication

The text is published in the Official Journal of the European Union (OJ L 333). EUR-Lex source ↗

3
16 January 2023

Entry into force

The regulation legally exists, but its effective application to companies is still deferred by two years - the time needed to prepare the technical standards and registers. ESMA source ↗

4
July 2023 - January 2024

Public consultations

The three European financial supervisory authorities (banking, insurance, markets) hold two public hearings to finalize the practical implementation rules. ESMA source ↗

5
25 June 2024

1st batch of technical standards published

First set of precise rules on ICT risk management (how to map, protect, detect, respond), adopted by the Commission on 13 March 2024. EUR-Lex source (2024/1774) ↗

6
17 July 2024

2nd batch of technical standards

Second set of implementing rules (notably on ICT subcontracting and oversight of providers). ESMA source ↗

7
2 December 2024

Official template for the "register of information"

The Commission publishes the technical template (forms) that every affected company must use to keep its inventory of IT providers up to date. Entered into force on 22 December 2024. EUR-Lex source (2024/2956) ↗

17 January 2025 - KEY DATE

DORA fully applies

From this date, all affected financial entities (and their strategic IT providers) must be in genuine compliance, not just "on paper". ESMA source ↗ · EIOPA source ↗

8
30 April 2025

First collection of registers

National supervisory authorities were to report to the European authorities the first registers of information received from covered companies. ESMA source ↗

November 2024 - May 2025 (ongoing)

Designation of "critical" providers

The European authorities are building, step by step, the list of IT providers (cloud, hosting...) deemed so important for the whole financial sector that they will be directly overseen at European level. The process (information gathering, decisions, progress report) ran from November 2024 to May 2025; the exact date of the first official designation is not stabilized in the sources consulted to date - to be confirmed as publications emerge. ESMA source ↗

December 2025 - June 2026 and beyond

Regular reviews ongoing

The European authorities continue to publish progress reports (lessons learned on major incidents, adjustments to subcontracting rules). DORA is a living project, not a fixed text. ESMA source ↗

Calendar compiled from official sources (EUR-Lex, ESMA, EIOPA) consulted on 17 July 2026. Some dates (final designation of critical providers, penalty amounts) are still being stabilized by the authorities - we will update them as soon as they are published.

A few more executive questions

7 more technical questions, digested simply: each sourced from the official text that confirms it.

Do I need to organize a "real conditions" penetration test (TLPT)?
Not necessarily. DORA provides for an advanced testing level called TLPT (threat-led penetration testing): a real attack simulation carried out by specialized testers. The regulation reserves this obligation for the most significant financial entities and explicitly exempts micro-enterprises (fewer than 10 employees). A European technical standard published in 2025 specifies who is affected and requires that an external tester be involved at least once every three testing cycles.

EUR-Lex source (recitals 43, 56, 61) ↗ · ESMA source (Delegated Regulation (EU) 2025/1190) ↗

Who actually checks that my company applies DORA?
Not a new digital police force: DORA relies on the supervisory authorities that already exist for each financial sector (banking, insurance, markets, payments...). Each Member State designates one or more "competent authorities" among its usual sectoral regulators, which apply DORA in addition to their historical missions.

EUR-Lex source (recital 37) ↗

What exactly is the "register" I must keep on my IT providers?
It's an identity card for all your IT contracts: who the provider is (cloud, software, hosting...), what service they provide, whether that service is "critical or important" for your business, and where the data is hosted. It isn't a simple in-house IT inventory: the exact format is imposed by a European text that sets precise templates to follow.

EUR-Lex source (recital 65) ↗ · ESMA source (Implementing Regulation (EU) 2024/2956) ↗

Do I have to send this register to an authority, and by what deadline?
Yes: supervisory authorities collect these registers to forward them to the European authorities. The first major collection took place in spring 2025 (30 April 2025). Check each year the calendar set by your supervisory authority, as the exact update frequency depends on your sector.

ESMA source ↗

My company is small - do I really have the same obligations as a large bank?
No, DORA provides for a proportionality principle. If you are a micro-enterprise (fewer than 10 employees, turnover or balance sheet under 2 million euros), you are not required to appoint a dedicated officer to oversee your providers, you can adapt your tests to your actual resources, you are exempt from the advanced TLPT test, and you can rely on pooled independent audits rather than auditing each provider yourself.

EUR-Lex source (recital 43) ↗

Are there already detailed implementing texts my IT provider should know about?
Yes, DORA is not just a text of principles: several detailed technical standards have already been published to specify how to apply it concretely, for example on resilience testing (Delegated Regulation (EU) 2025/1190) or on the format of the provider register (Implementing Regulation (EU) 2024/2956). These are the texts a serious IT provider needs to know to support you properly.

ESMA source ↗

If one of my "critical" IT providers doesn't respect the rules, who can sanction them?
For the largest IT providers designated "critical" at European level, a European "lead overseer" can directly impose daily periodic penalty payments on them if they fail to comply with its recommendations: a sanctioning power that goes beyond national borders. For standard financial entities (you, if you are one), penalties remain defined and imposed by your usual national competent authorities.

EUR-Lex source (recital 80) ↗

These answers digest the official DORA text in plain language: they do not replace legal advice. Always check your specific situation with specialized counsel.

DORA penalties, made clear

"DORA provides for fines" comes up often in sales pitches. What the official text actually says, in black and white: two distinct regimes, with a single harmonized European figure - and no single scale for everyone.

You are a financial entity (bank, insurer, management company...)

DORA sets no amount or percentage of turnover. The text explicitly leaves it to each Member State to set its own penalty rules (Article 50, §3: "Member States shall lay down rules establishing appropriate administrative penalties..."). In France, it is your usual authorities - ACPR for banking/insurance, AMF for markets - that apply their own national scale, not a single harmonized European DORA scale.

What the regulation does impose, however: types of measures that each country must provide for at a minimum (list below) - it is up to national law to set the exact amounts.

You are an IT provider designated "critical" (cloud, hosting provider...)

Here, DORA sets a precise figure, harmonized across all of Europe: a periodic penalty payment of up to 1% of average daily worldwide turnover, per day of delay, for a maximum of 6 months (Article 35, §7-8). This is not an immediate sanction: it can only be triggered after at least 30 calendar days of non-compliance found by the authority.

This penalty payment concerns only the large providers officially designated "critical" by the EU - not the client companies that use them.

The only official figure in the entire DORA regulation

1% of average daily worldwide turnover, per day, for a maximum of 6 months

This is the periodic penalty payment that the "Lead Overseer" - one of the three European financial supervisory authorities (EBA, ESMA or EIOPA, designated per provider) - can impose on a critical IT provider that refuses to come into compliance after a period of at least 30 days. The money is paid into the general budget of the European Union, and each penalty payment imposed must in principle be made public by the Lead Overseer.

Source: Regulation (EU) 2022/2554, Article 35, paragraphs 6 to 10 - official EUR-Lex text ↗

What your authority can decide (financial entities)

Five types of measures that each Member State must provide for at a minimum in its national law - Article 50, §4 of DORA.

1

Order to cease

Require the company to immediately stop the non-compliant practice and not resume it.

2

Temporary or permanent cessation

Prohibit a practice or conduct deemed contrary to the regulation, temporarily or permanently.

3

Pecuniary measure

Any measure, including financial, to bring the company back into compliance - amount set by the national law of each country.

4

Requisition of traffic data

Require existing records from a telecom operator, in the event of reasonable suspicion of a breach.

5

Publication of the name

Make public a notice indicating the identity of the company and the nature of the breach ("name and shame").

To calibrate the exact level of the penalty, Article 51§2 of DORA requires the authority to take into account, among other things: the gravity and duration of the breach, the degree of responsibility, the financial soundness of the company, profits gained or losses avoided, damage caused to third parties, the level of cooperation, and prior record.

Analysis based on the full reading of Articles 35 and 50 to 53 of Regulation (EU) 2022/2554, official text published in the EU Official Journal (L 333, 27/12/2022), consulted on EUR-Lex on 17 July 2026. No specific penalty amount exists in the text for financial entities (reference to the national law of each Member State) - we therefore do not invent one. No periodic penalty payment under Article 35 is publicly recorded to date in our sources; DORA has only been fully applicable since 17 January 2025.

Ready to document your DORA compliance?

Contact us to receive a personalized quote based on your status (financial entity or ICT provider).

Start my free diagnostic

Free: your score + your gaps. The detailed report and the attestation: 499 EUR excl. VAT, only if you decide to.

contact@syaga.eu
DORA-Express is a documentation support tool and does not constitute legal advice. The applicability of DORA to your organization and the legal validity of your contracts and registers must be confirmed by a specialized lawyer.