DORA Compliance Assessment for EU Financial Entities

The Digital Operational Resilience Act (DORA) has applied to EU financial entities since 17 January 2025. This free DORA compliance assessment checks whether your organisation falls within scope under Article 2 of Regulation (EU) 2022/2554, classifies your obligation level, and evaluates operational readiness across all five DORA pillars. Seven questions. Under two minutes. No registration required.

The tool covers all 20 entity categories from Article 2(1), the six exemption paths under Article 2(3), the simplified framework under Article 16 for eligible smaller entities, and the quantitative incident classification thresholds from Delegated Regulation (EU) 2024/1772. Your result includes a readiness score, penalty exposure based on your member state, and prioritised next steps. Every output cites the specific Article it relies on.

One practical note before you begin. DORA itself does not set a unified EU maximum for fines for financial entities. There is no “2% of annual turnover” or “€1 million for individuals” anywhere in the regulation. Article 50 requires each member state to establish its own effective, proportionate and dissuasive penalties, and the resulting amounts vary significantly between countries. When you assess your penalty exposure, start with your national implementation law and your competent supervisor. That is the number that actually applies to you.

How This DORA Compliance Assessment Works

The assessment follows the decision tree a regulator would apply. It determines scope under Article 2, checks exemptions under Article 2(3), classifies entity size using the thresholds in Article 3(60), 3(63), and 3(64), and evaluates whether the simplified ICT risk management framework of Article 16 applies. Readiness questions map to the five compliance pillars defined in Chapters II through VI of the regulation: ICT risk management (Articles 5 to 16), incident reporting (Articles 17 to 23), resilience testing (Articles 24 to 27), third-party risk management (Articles 28 to 44), and information sharing (Article 45). Penalty information draws on Article 50 (national penalties for financial entities) and Article 35 (oversight penalties for Critical ICT Third-Party Providers), cross-referenced with published national transposition data. The tool does not assess individual contractual arrangements with ICT providers, evaluate your internal policies, or replace a compliance gap analysis conducted by qualified legal counsel.

What Are the Five Pillars of DORA

DORA is structured around five compliance pillars, each covering a distinct area of digital operational resilience.

  • Pillar 1, ICT risk management (Articles 5 to 16), requires a documented framework covering risk identification, protection, detection, response, and recovery.
  • Pillar 2, incident reporting (Articles 17 to 23), mandates classification and notification of major ICT incidents to national regulators within strict timelines.
  • Pillar 3, digital operational resilience testing (Articles 24 to 27), requires vulnerability assessments, scenario-based testing, and threat-led penetration testing for qualifying entities.
  • Pillar 4, ICT third-party risk management (Articles 28 to 44), covers the information register of all ICT provider arrangements, mandatory contractual clauses, and concentration risk monitoring.
  • Pillar 5, information sharing (Article 45), enables financial entities to exchange cyber threat intelligence with industry peers and sector groups.

The first four pillars carry mandatory obligations for all in-scope financial entities. The fifth pillar is voluntary in its framing but increasingly viewed by supervisory authorities as an indicator of mature operational resilience.

Who Needs to Comply with DORA

DORA applies to 20 categories of financial entities listed in Article 2(1) of Regulation (EU) 2022/2554. These include credit institutions, payment institutions, investment firms, insurance and reinsurance undertakings, crypto-asset service providers, institutions for occupational retirement provision, central counterparties, trade repositories, and credit rating agencies, among others. ICT third-party service providers fall within the oversight framework, and those designated as Critical Third-Party Providers (CTPPs) face direct EU-level supervision.

Six exemption paths exist under Article 2(3). Sub-threshold alternative investment fund managers, small insurance undertakings exempt under Solvency II, pension providers with 15 or fewer total members, micro and SME insurance intermediaries, certain MiFID II-exempt persons, and postal giro institutions are all fully excluded. If you operate in financial services and also need to clarify NIS2 applicability, check with the NIS2 Applicability Checker.

What Happens If You Fail to Comply with DORA

DORA does not set harmonised penalty amounts for financial entities. Article 50(3) requires each member state to establish “effective, proportionate and dissuasive” administrative penalties, but the regulation specifies no percentages, no fixed ceilings, and no turnover-based formulas. Figures like “up to 2% of annual turnover” that circulate across compliance websites are either national transposition figures or confusions with NIS2 or GDPR.

National penalty ceilings vary sharply. Among surveyed member states, maximum fines for legal persons range from €2 million in the Czech Republic to €20 million in Italy. Spain applies up to 5% of turnover or three times the profit gained from the infringement. Sweden goes up to 10% of turnover. For individuals on the management body, ceilings range from €100,000 in Finland to €5 million in Germany. Beyond financial penalties, regulators can order cessation of activities, require public disclosure of infringements, and impose personal sanctions on management body members (Article 50(4) to (5)). The only EU-harmonised penalty applies to designated CTPPs: periodic payments of up to 1% of average daily worldwide turnover, imposed daily for up to six months (Article 35(6) to (8)).

Does DORA Apply to Small Financial Entities

Yes. DORA contains no blanket SME exemption. Every financial entity within the 20 categories of Article 2(1) is in scope regardless of size, unless it falls under one of the specific exemptions in Article 2(3). Micro-enterprises (fewer than 10 employees, turnover or balance sheet up to €2 million per Article 3(60)) benefit from proportionality measures: no separate independent control function required, periodic rather than annual ICT risk framework reviews, and no obligation to define a third-party ICT strategy.

Certain smaller entity types qualify for the simplified ICT risk management framework under Article 16. These include small non-interconnected investment firms, payment institutions and electronic money institutions operating under regulatory exemptions, and pension providers managing schemes with fewer than 100 members. The simplified framework reduces obligations under Articles 5 to 15 but does not remove the entity from DORA’s scope entirely.

How to Comply with DORA Step by Step

Start with scope confirmation. Verify that your organisation falls within the 20 entity categories of Article 2(1) and does not qualify for an exemption under Article 2(3). Then classify your size under Article 3 and determine whether the simplified framework of Article 16 applies.

From there, work through the five pillars in order of regulatory urgency. Establish your ICT risk management framework (Articles 5 to 16) and get management body sign-off. Build your incident classification and reporting process using the quantitative thresholds from Delegated Regulation 2024/1772, and test the 4-hour initial notification timeline. Set up a risk-based testing programme covering vulnerability assessments and scenario testing (Articles 24 to 25). Compile the register of all ICT third-party arrangements in the format required by ITS 2024/2956 and review contracts against the mandatory clauses in Article 30. Finally, explore information-sharing arrangements with sector peers (Article 45). Track all relevant deadlines in one place with the EU Compliance Deadline Tracker.

How Do You Prove DORA Compliance

DORA compliance is demonstrated through documentation, not certification. There is no “DORA certified” badge. Your national competent authority assesses compliance during supervisory reviews, and the evidence they look for maps directly to the five pillars.

For ICT risk management, you need a documented and management-body-approved framework with risk assessments, asset inventories, and business continuity plans. For incident reporting, the key artifact is a documented classification procedure using the specific quantitative thresholds from the Delegated Regulation, along with records of past incident reports filed within the required timelines. For resilience testing, maintain your testing programme documentation, test results, and remediation tracking. For third-party risk, the information register (Article 28(3)) in the standardised ITS format is the central proof point, alongside contracts containing the mandatory DORA clauses. For information sharing, document any arrangements and the safeguards in place.

What Are the DORA Incident Reporting Deadlines

Financial entities must report major ICT incidents to their national competent authority within the timelines defined in Article 19 and RTS 2025/301. The initial notification must reach the regulator within 4 hours of classifying an incident as major, and no later than 24 hours from first detection. An intermediate report follows within 72 hours. The final report is due within one month.

An ICT incident qualifies as major when it affects critical or important services and meets at least two quantitative thresholds from Delegated Regulation (EU) 2024/1772, Article 9: more than 10% of clients affected, more than 100,000 clients affected, service downtime exceeding 24 hours (or 2 hours for critical functions), geographic spread across two or more member states, or economic impact above €100,000. A single threshold is sufficient where the incident involves malicious unauthorised access to network and information systems.

What to Do After Your Assessment

Your result identifies which DORA pillars need attention. Start with the highest-priority gaps. If your organisation has not yet started on ICT risk management or third-party oversight, those are likely your first two workstreams. If incident classification and reporting is the gap, the quantitative thresholds from Delegated Regulation 2024/1772 give you a clear specification to build against.

For a view of all current DORA and related EU compliance deadlines on a single timeline, use the EU Compliance Deadline Tracker.

DORA enforcement is underway and national supervisory authorities are reviewing compliance. Subscribe to RegDossier for monthly updates on enforcement actions, RTS developments, and a structured DORA compliance checklist covering all five pillars.