← All terms

Digital Operational Resilience Act (DORA)

DORA (EU 2022/2554) is the EU regulation making financial entities manage ICT risk — with compulsory security awareness training for all staff and management.

The Digital Operational Resilience Act (Regulation (EU) 2022/2554) is the European Union's ICT-risk law for the financial sector. It applies directly — no national transposition needed — to banks, insurers, investment firms, payment institutions, crypto-asset service providers and their critical ICT vendors, and has applied in full since 17 January 2025. Where the NIS2 Directive sets cybersecurity duties for 18 critical sectors, DORA goes deeper for one: finance, the sector where a successful social-engineering attack converts to money fastest.

How it works

DORA is built on five pillars: ICT risk management, incident classification and reporting, digital operational resilience testing, third-party risk management, and information sharing. The management body carries ultimate responsibility for ICT risk and must keep its own knowledge current. The regulation is unusually explicit about the human layer: Article 13(6) requires financial entities to build "ICT security awareness programmes and digital operational resilience training as compulsory modules in their staff training schemes," applicable to all employees and to senior management, with depth proportionate to each role. Third-party exposure is regulated too — critical ICT providers fall under direct EU oversight, and training can be extended to them, reflecting how often incidents arrive through a supply chain attack.

How to defend and comply

For security teams, DORA turns awareness training from a best practice into a supervisable obligation with a paper trail. A compliant program covers everyone — including the board — recurs on a defined cadence, scales content to role risk, and produces records an examiner can inspect. The strongest programs pair that training with realistic testing of the human attack surface: phishing simulations targeting finance-specific lures like invoice fraud and payment-diversion pretexts, feeding a human risk score that shows resilience improving over time. Because DORA and NIS2 overlap for many groups, the pragmatic route is one program that satisfies the stricter rule — our guide to NIS2's human-risk requirements covers how the two laws converge on a trained, measured workforce.

Related terms

NIS2 DirectiveThe NIS2 Directive (EU 2022/2555) is the EU cybersecurity law for 18 critical sectors, mandating risk management, training and 24-hour incident reporting.Cyber HygieneCyber hygiene is the set of routine practices — updates, strong authentication, least privilege, awareness — that keeps users and systems resistant to attack.Supply Chain AttackA supply chain attack compromises a trusted vendor, software update, or service provider to reach that supplier's customers — trust as the attack vector.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo