DORA and the Future of Operational Resilience:

A Practical Checklist for Financial Entities

DORA has changed the rules of digital resilience

 

The Digital Operational Resilience Act (DORA) has introduced a harmonised European framework for managing information and communication technology risk across the financial sector.

DORA has applied since 17 January 2025. Financial entities within its scope must comply with Regulation (EU) 2022/2554 and the associated regulatory and implementing technical standards.

 

The Regulation applies to a broad range of organisations, including credit institutions, payment institutions, electronic-money institutions, investment firms, fund managers, insurance undertakings, crypto-asset service providers and certain financial-market infrastructures. Its requirements are subject to exclusions, exemptions, simplified frameworks and the principle of proportionality.

 

DORA brings together disciplines that were often managed separately, including ICT risk, cybersecurity, business continuity, incident reporting, resilience testing and third-party oversight. Its purpose is not simply to prevent incidents. Financial entities must be able to withstand, respond to and recover from ICT-related disruption while maintaining the continuity and integrity of their critical or important functions.

 

For Cyprus financial entities, the relevant competent authority depends on the entity and sector. Organisations should follow the requirements and reporting arrangements communicated by the Central Bank of Cyprus, the Cyprus Securities and Exchange Commission (CySEC), or another competent authority responsible for their supervision.

From regulatory compliance to organisational capability

DORA is first and foremost a regulatory requirement. However, the capabilities needed to comply with it can also produce wider organisational benefits.

 

Reliable digital services help protect customer relationships and business continuity. Clear accountability can improve decision-making during disruption. Effective testing can expose weaknesses before they cause significant harm, while stronger oversight of technology providers can reduce the risks associated with outsourcing and complex digital supply chains.

 

Operational resilience should therefore not be treated solely as an ICT project or a collection of policy documents. It is an organisation-wide capability involving the board, senior management, business operations, technology, risk, compliance, legal, internal audit and third-party management functions.

 

Financial entities that embed resilience into everyday decisions may be better positioned to protect their services, support responsible innovation and maintain stakeholder confidence during disruption.

A practical DORA compliance checklist

DORA compliance is an ongoing responsibility rather than a one-off implementation project. The precise measures required will depend on the entity’s size, risk profile, activities and applicable regulatory framework. Nevertheless, the following areas should form the foundation of a DORA compliance programme.

 

1. Establish governance and accountability

 

The management body has ultimate responsibility for the financial entity’s ICT risk. It should define, approve and oversee the ICT risk-management framework, establish clear responsibilities and receive timely information about major incidents, testing results, control weaknesses, third-party dependencies and remediation.

 

The management body should also approve and periodically review ICT business-continuity and response-and-recovery arrangements, oversee policies governing ICT third-party services and allocate appropriate budgets and resources.

 

Responsibility for managing and overseeing ICT risk should be assigned to an appropriate control function, with sufficient independence and segregation from internal audit. DORA permits the Three Lines Model or an equivalent internal risk-management and control framework.

 

Members of the management body must also maintain sufficient knowledge and skills to understand and assess ICT risk, including through regular training.

 

2. Maintain a comprehensive ICT risk-management framework

 

Financial entities should establish and maintain a sound, comprehensive and well-documented ICT risk-management framework as part of their overall risk-management arrangements.

 

This includes identifying and classifying ICT-supported business functions and maintaining accurate inventories of information and ICT assets. Entities should understand which systems, processes, people and third parties support their critical or important functions and how those dependencies could affect service continuity.

 

The framework should include proportionate protection, prevention and detection controls, secure and up-to-date ICT systems, continuous vulnerability and threat monitoring, and clear processes for assessing risk when systems, services or suppliers change.

 

Financial entities must also maintain ICT business-continuity and response-and-recovery arrangements. These should define recovery-time and recovery-point objectives, backup and restoration procedures, crisis-management responsibilities and communication plans.

 

For most entities, the ICT risk-management framework must be reviewed at least annually and after major incidents, material changes, testing results or audit findings. It should also be subject to regular independent internal audit. Certain microenterprises and qualifying entities are subject to different or simplified requirements.

 

 3. Classify, manage and report ICT-related incidents

 

Financial entities must have processes to detect, manage, record, classify and report ICT-related incidents.

 

Incident classification should consider factors such as affected clients and transactions, service downtime, geographical spread, data loss, the criticality of affected services, reputational consequences and economic impact. Potential major incidents should be escalated promptly, and reporting responsibilities should be understood before a disruption occurs.

 

Major ICT-related incidents must be reported to the relevant competent authority through initial, intermediate and final reports. Under the current EU framework, the initial notification is generally due within four hours of classification as a major incident and no later than 24 hours after the entity becomes aware of the incident. An intermediate report generally follows within 72 hours of the initial notification, while a final report is generally due within one month of the intermediate or latest updated intermediate report.

 

For CySEC-regulated entities, the applicable forms, submission process and deadlines are explained in CySEC Circular C700. CySEC has subsequently highlighted deficiencies in how some entities classify and report incidents and has reminded regulated entities to apply the relevant criteria and thresholds carefully in Circular C751.

 

Notification of a significant cyber threat is voluntary under DORA where the entity considers the threat relevant to the financial system, service users or clients.

 

Incident processes should also be coordinated with other potentially applicable requirements, including personal-data-breach reporting. Major incidents that disrupt core activities should lead to structured post-incident reviews, root-cause analysis and corrective action.

 

4. Test digital operational resilience

 

Policies and plans cannot, by themselves, demonstrate resilience. Financial entities other than microenterprises must maintain a proportionate digital operational resilience testing programme.

 

Testing may include vulnerability assessments, network-security assessments, gap analyses, scenario exercises, performance and end-to-end testing, penetration testing and crisis simulations involving management and relevant business functions.

 

Appropriate tests must be conducted at least annually on ICT systems and applications supporting critical or important functions. Weaknesses identified through testing should be prioritised, remediated and subject to follow-up validation.

 

Threat-led penetration testing is a separate advanced requirement. It does not apply automatically to every financial entity. Entities selected by the competent authority under DORA’s criteria must generally undertake TLPT at least every three years, although the competent authority may adjust the frequency according to the entity’s risk profile and operational circumstances.

 

Recovery arrangements should also be tested under realistic conditions. An organisation should be able to demonstrate not only that systems can be restored, but also that business services, decision-making and communication can continue effectively during disruption.

 

5. Manage ICT third-party risk

 

Using an external service provider does not transfer the financial entity’s regulatory responsibility. ICT third-party risk must be managed as an integral part of the entity’s ICT risk-management framework.

 

Before entering an arrangement, financial entities should assess the provider, the services involved and whether they support a critical or important function. They should consider concentration risk, substitutability, subcontracting and the consequences of provider failure.

 

Contracts must contain the provisions required by DORA. Depending on the service, these may include service descriptions, security and availability requirements, incident-assistance obligations, data-access and recovery provisions, audit and inspection rights, subcontracting conditions, termination rights and cooperation with competent authorities. Arrangements supporting critical or important functions are subject to additional requirements.

 

Entities should monitor provider performance and risk throughout the relationship and maintain credible exit strategies. The objective is not necessarily to use several providers for every service, but to demonstrate that concentration and continuity risks are understood and can be managed without unacceptable disruption.

 

DORA also requires financial entities to maintain a register of information covering contractual arrangements for ICT services at the relevant entity, sub-consolidated and consolidated levels.

 

CySEC-regulated entities must currently submit their register annually by 28 February, with a reference date of 31 December of the preceding year. CySEC requires the register to be submitted in XBRL-CSV format, as explained in Circular C751.

 

DORA also establishes EU-level oversight for ICT third-party providers formally designated as critical. Other technology providers may be affected through the contractual and oversight obligations imposed on their regulated financial-sector customers.

 

6. Maintain evidence and invest in people

 

Regulators need evidence that controls operate effectively, not simply confirmation that policies exist.

 

Financial entities should maintain appropriate governance records, asset and dependency inventories, risk assessments, incident reports, test results, remediation records, supplier assessments, contract reviews, training records and internal-audit reports. Management information should allow the board and senior management to understand the organisation’s risk exposure and progress in addressing weaknesses.

 

People are equally important. DORA requires ICT-security awareness and digital-operational-resilience training to form compulsory elements of staff training. These requirements apply to employees and senior management, with the depth of training reflecting each person’s responsibilities.

 

Training should help personnel understand how to recognise and escalate risks, what to do during an incident and how their decisions affect the continuity of critical or important functions. Cross-functional exercises can help directors, executives, operations teams, technology specialists, compliance professionals and risk managers practise working together during realistic disruptions.

 

One of the most significant implementation mistakes is treating DORA as an initiative owned solely by the ICT department. Technology teams have an essential role, but resilience failures can also arise from unclear accountability, poor communication, inadequate supplier oversight or delayed decision-making.

 

Operational resilience ultimately depends on informed leadership, capable professionals and a culture in which risk information is shared and acted upon.

Looking beyond minimum compliance

DORA establishes a regulatory baseline, but the operational environment will continue to evolve.

 

Financial entities face changing risks from cyberattacks, software supply-chain weaknesses, digital fraud, cloud concentration and increasingly complex third-party dependencies. Artificial intelligence can strengthen monitoring and threat detection, but it may also introduce new security, data-governance and model risks.

 

Continuous monitoring, resilience analytics and advanced scenario testing may offer benefits where they are proportionate, appropriately governed and supported by suitable expertise. The objective should not be to adopt every new technology, but to understand how technological change affects the entity’s risk profile and whether its governance, controls and skills are keeping pace.

Building the human side of resilience

Developing operational resilience requires sustained investment in professional knowledge across governance, risk, compliance, technology and financial regulation.

 

The European Institute of Management and Finance supports professionals and organisations through executive education, professional qualifications and academic programmes in these areas. Relevant learning opportunities include EIMF’s Master in Governance, Risk and Compliance, its governance, compliance and risk programmes and its catalogue of self-paced professional courses.

 

Professional development should complement not replace an entity’s legal, regulatory, technical and assurance arrangements.

Compliance today, resilience tomorrow

DORA moves the focus beyond cybersecurity controls and policy documentation towards the demonstrable ability to maintain critical or important functions during adverse events.

 

Successful implementation requires active governance, comprehensive ICT risk management, disciplined incident reporting, meaningful testing, effective third-party oversight and continued investment in people.

 

For boards and senior managers, the central question is no longer whether disruption will occur. It is whether the organisation has the governance, capabilities and evidence needed to respond effectively when it does.

 

DORA compliance is not the end of that process. It provides a framework through which financial entities can build stronger, more adaptable and more trustworthy organisations.

 

Questions for your organisation

• Does the management body receive sufficient information to understand and challenge ICT risk?

• Has the organisation identified the systems and third parties supporting its critical or important functions?

• Can major incidents be classified and reported within the required deadlines?

• Have recovery arrangements been tested under realistic conditions?

• Can the organisation demonstrate that incidents, tests and audits produce measurable improvement?

 

Notes

This article provides general educational information and does not constitute legal or regulatory advice. Financial entities should assess the requirements applicable to their activities and follow the instructions of their competent authority.

 

Resources and further reading

• Regulation (EU) 2022/2554 — Digital Operational Resilience Act

• CySEC: Digital Resilience and DORA

• CySEC Circular C700: Incident Reporting and Register of Information

• CySEC Circular C751: Reporting, Governance and Portal-Related Obligations

• Central Bank of Cyprus: Application of DORA

• ESMA: Digital Operational Resilience Act

• ENISA: Threat Landscape

 

Contact the EIMF Team

Phone: +357 2227 4470
Email: [email protected]

Days
Hours
Minutes
Seconds

Early bird discount

13 November 2025

Navigating Conflict for Collaborative Teams: Leading with Confidence

Join us to gain insights from Alana Hill, learn practical strategies for turning conflict into opportunity, and discover how challenges can drive growth and stronger team performance.

Days
Hours
Minutes
Seconds

Limited Time

30% Discount

On All Self-Paced eLearning CPD Courses in Financial Regulation

Days
Hours
Minutes
Seconds

Limited Availability

05 June 2025

Corporate Governance Today: Trends and Challenges

Hosted by the EIMF and the Chartered Governance Institute

Engage with 20+ leading experts and earn 6 CPD units in Financial Regulation.

Get Inspired by Our Head of Accounting

Think. Choose. Grow.

Not sure if it’s right for you? Let’s talk.

Days
Hours
Minutes
Seconds

limited time

PAIR UP AND SAVE

BUY ONE, GET ONE FREE

Short Self-Paced Online Courses

Days
Hours
Minutes
Seconds

Limited time

New Year, new you

10% discount on All Courses

Discount Coupon: NYNY10

Valid until 31 Jan 2025 23:59

EIMF's Christmas Advent Calendar

Unwrap the Gift of Knowledge this Festive Season!

Register now to receive a valuable educational resource each day and be automatically entered into our Grand Christmas Draw on 24th December – Don’t miss out!

Days
Hours
Minutes
Seconds

Limited time

black friday has arrived

up to 40% discount

On Self-Paced eLearning Courses

Days
Hours
Minutes
Seconds

Limited Availability

17 October 2024

Regulatory & AFC Compliance Conference

Hosted by the ACAMS Cyprus Chapter and the EIMF.

Engage with 17 leading experts, explore 12 critical areas, earn 6 CPD units in Financial Regulation, gain 4 ACAMS credits, and receive a Certificate of Participation.

Celebrate 9 Years with EIMF

EIMF Has Assisted 6,000+ Professionals Get Certified

 

Ready for your next professional certification? Choose from 9 self-paced eLearning courses and enjoy a 30% discount!

*complete your purchase before 21 April 2024

Starts 20 February 2024

Master in Governance,
Risk & Compliance

Accredited by the CyQAA, our GRC programme empowers you to navigate complex regulations, manage risks, and fortify governance structures. Dive into a dynamic learning experience that ensures ethical operations, regulatory compliance, and risk reduction.

✅ Explore Scholarships & Financial Aid ✅ Discover the Match Funding Scheme