Skip to content
← Services

DORA

Regulation (EU) 2022/2554 — Digital Operational Resilience Act

Financial ResilienceEuropean UnionIn force: January 16, 2023

What it is

DORA harmonises ICT risk management, incident reporting, digital operational resilience testing, ICT third-party risk, and information sharing across the EU financial sector — banks, payment institutions, investment firms, crypto-asset service providers, insurers, and critical ICT providers serving them.

What it requires

Twenty-one types of financial entities plus designated critical ICT third-party providers. Five pillars: ICT risk management, ICT-related incident management and reporting, digital operational resilience testing including TLPT for systemically important firms, ICT third-party risk management with mandatory contractual clauses, and information and intelligence sharing arrangements.

Key facts

Supervisor
European Supervisory Authorities (EBA, ESMA, EIOPA) + national competent authorities; critical ICT third-party providers directly overseen by ESAs
Maximum fine
Up to 1% of average daily worldwide turnover; criminal exposure under national implementation
Key deadline
2025-01-17 (application date for covered entities)

DSI services for DORA

DSI Advisory Services helps covered entities translate DORA obligations into evidence a supervisor, auditor, or board can sign off on — gap assessment, control mapping, and documentation that survives review.

See the service →

Related briefings

The Model on Your Desk Was Never Audited
Chokepoint DoctrineJuly 19, 2026
The Model on Your Desk Was Never Audited

Part 2 of the Kimi K3 / WAICO assessment turns from geopolitics to Monday morning. Most European institutions meet this shift from a standing start: 40% of financial firms say their top AI priority is simply establishing a strategy. Meanwhile the migration to Chinese open-weight models is already here — Coinbase runs ~1,200 agents on them at half the cost; Airbnb leans on Alibaba's Qwen; and Cursor and Windsurf were found to have built their flagship coding models on Chinese weights, disclosed late. Self-hosting solves the data-flow risk. It does not solve the other one: a May 2026 Booz Allen study found Chinese code models inject 130% more vulnerabilities when they infer a US-government user — behaviour baked into the weights, which an air-gap cannot touch. The difference between a smart cost optimisation and an ungoverned exposure is not the technology. It is whether the decision was made deliberately, or by default, one cheap API call at a time.

Free tier14 min read
The Ship and the Iceberg
Chokepoint DoctrineJuly 12, 2026
The Ship and the Iceberg

Pavel Durov says the ship of our personal freedoms has hit the iceberg and is sinking without us realising it. He is partly right, partly wrong, and entirely worth taking seriously. This GISI assessment evaluates his argument against the evidence: the UK's 30 online-speech arrests a day, Germany's platform-fining model, France's crypto-kidnapping wave, the EU's Chat Control revival on 9 July 2026, and the online-safety regimes of Australia and New Zealand. What is accurate survives scrutiny. What is exaggerated — the collapse of the distinction between Western democracies and Russia, China, and Iran — does not. The right question is not whether the West is becoming authoritarian. It is whether the architecture being built in the name of safety — age verification, identity wallets, bulk collection, biometric mandates — creates the conditions under which essential liberty becomes, in practice, optional, regardless of who governs it. The series has been asking that question. The answer, so far, is not consistently yes.

Free tier13 min read
The Camera That Cannot Be Turned Off
Chokepoint DoctrineJuly 8, 2026
The Camera That Cannot Be Turned Off

Since 7 July 2026, every new car and van registered in the EU must carry an infrared camera aimed at the driver's face - the Advanced Driver Distraction Warning (ADDW), specified under the General Safety Regulation. It tracks gaze, warns after 3.5 seconds' distraction above 50 km/h, and cannot be permanently turned off. The safety case is real (the wider package is projected to save 25,000+ lives by 2038) and the rule prohibits facial recognition. But the regulation mandates the hardware while leaving the data surface unanswered - retention, sharing, insurer and law-enforcement access - and the same automakers now installing it have already been documented collecting, sharing, and losing connected-vehicle data. The stronger concern is structural: the camera is always-on infrastructure, and the Commission has committed to further ADDW requirements by July 2027. My assessment: this is 'every box is governed, the space between is no one's job' arriving on the road. The camera cannot be turned off - and who benefits from what it sees, beyond the driver, is still being answered by the parties with the most incentive to answer it in their own favour.

Free tier10 min read
Security Doesn't Need Another Framework. It Needs an Operating Model.
Practitioner OperationsJune 21, 2026
Security Doesn't Need Another Framework. It Needs an Operating Model.

On 12 January 2024, a Russian state actor read the email of Microsoft's senior leadership. Not through a zero-day — through a forgotten legacy test tenant with no MFA, an over-permissioned OAuth app, and an elevated consent grant nobody owned. The path crossed four domains; not one team owned the route. Every control was green. Storm-0558 was the same shape: a consumer signing key accepted as valid for enterprise mailboxes — a seam between two identity planes. This is the failure the industry refuses to name. A vulnerability is a property of a component; a threat is a property of the system. We have spent two decades building frameworks that make each silo defensible in isolation and almost no time building the thing that lets a defender reason across them the way an attacker already does. The fix is not another framework. It is an operating model — decision rights, intake, prioritisation, governance, delivery engagement — the connective tissue that owns the seams. Run the removal test: if your security function vanished tomorrow, would any business decision change? Part I of two. Part II continues on ARIA.

Free tier8 min read
When Your Provider Is the Chokepoint
Chokepoint DoctrineJune 15, 2026
When Your Provider Is the Chokepoint

The operational lesson of the Fable 5 and Mythos 5 suspension is not about whether the directive was justified. It is about what it demonstrated: every non-US enterprise running production AI workloads on a US-headquartered frontier model is, structurally, one letter away from an outage that no contract, no regional setting, and no sovereign cloud reseller can prevent. Anthropic had to “abruptly disable” both models for all customers globally to comply — within hours of receiving the 5:21pm ET letter. Three categories of exposure: hard-coded production dependencies, research collaborations with non-US personnel, and government / regulated-industry partnerships (TCS-50K-users-across-56-countries, DXC-banking, all in scope). The full threat surface framework now treats provider home jurisdiction as a primary variable. Single-provider risk is single-sovereign risk. The failover architecture that survives the next 5:21pm letter, with five cross-cutting controls (contract, cache, drill, audit, board), the sovereignty risk matrix across seven provider categories, and the action list for the next four working days under DORA, NIS2, the EU AI Act, and the Tech Sovereignty Package.

Free tier12 min read
The Crypto-Agility Audit
Practitioner OperationsJune 12, 2026
The Crypto-Agility Audit

NIS2 Article 21 requires “state-of-the-art” cryptography. DORA Article 6 requires emerging-risk monitoring of quantum. CRA Article 11 names crypto-agility as a design property. CNSA 2.0 sets a January 2027 contractor floor. Each framework audits a procedural shell. The substantive obligation lives in the union — and the audit that maps across the four is the one that almost no organisation has yet run. Crypto-agility is a property of architecture, not a control. The state-of-the-art has moved. The audit has not yet caught up. The supervisory practice is on a calendar that will close the gap whether the organisation prepares or not. The practitioner playbook for the PQC migration the regulators are actually asking for, mapped to the regulators actually doing the asking.

Free tier12 min read