DORA: what the regulation means for the financial sector and how to prepare
DORA (Digital Operational Resilience Act) changes the rules for banks, insurers and their IT suppliers. What you must meet, how it differs from NIS2 and where to start.
Viktor Bureš
Chief Technology Officer at Integrity. Works on security architecture, operational resilience and compliance with NIS2 and DORA.

While NIS2 reaches across industries, DORA targets the financial sector precisely, and it is more specific, stricter and directly enforceable. If you are a bank, an insurer, an investment firm, a payment institution or their IT supplier, this is the regulation that will not pass you by.
What DORA is
DORA (Digital Operational Resilience Act) is a European regulation on the digital operational resilience of the financial sector. Unlike a directive, it is not transposed into national law; it applies directly. The goal is for financial institutions to withstand a cyber incident or an IT outage without endangering clients or the market.
Who it applies to
The reach is wide: banks, insurers and reinsurers, investment firms, payment and e-money institutions, crypto-asset service providers, trading venues, and newly also the critical ICT suppliers of these institutions (cloud, hosting, data custodians). The extension to suppliers is the key change: if you deliver an IT service to a bank, DORA will most likely touch you too, if only indirectly through the contract.
Five pillars you have to cover
- ICT risk management. A framework you can evidence: asset identification, protection, detection, response, recovery. Management carries the responsibility, not "IT somewhere down the line".
- Incident reporting. Uniform classification and deadlines for reporting major ICT incidents to the competent authority.
- Resilience testing. Regular tests, from vulnerability scans to advanced penetration tests (for large players, threat-led penetration testing).
- Third-party risk management. A register of suppliers, contractual requirements, exit strategies, handling of concentration risk with key providers.
- Information sharing about threats between institutions.
How DORA differs from NIS2
Put simply: NIS2 is wide, DORA is deep. NIS2 sets a minimum bar across the economy; DORA goes into detail specifically for finance and is directly effective. Many financial institutions fall under both; then the principle applies that the more specific and stricter rule (DORA) takes precedence for ICT risk. In practice that means not building two separate projects but one framework that covers the requirements of both.
Where companies most often fall behind
- Resilience, not just security. DORA asks not only "are you protected?" but "can you withstand an outage and recover quickly?". That is about availability, network capacity and the ability to absorb an attack, not just prevention.
- Suppliers. The third-party register and contractual requirements tend to be the weakest spot. For critical ICT suppliers you also have to address concentration risk.
- Testing as a process. A one-off audit is not enough; DORA expects regular testing that can be evidenced.
Where to start
- Confirm the impact: are you in scope directly, or through a contract with a financial institution?
- Build a single ICT risk framework that covers NIS2 and DORA at once.
- Map your suppliers and add resilience requirements and an exit plan to the contracts.
- Secure the availability and resilience of your interfaces: web, API and protection against volumetric attacks, the most common cause of availability outages.
- Set up testing as a repeating cycle, not a one-off item.
Dealing with DORA and NIS2 at the same time and do not want to build two projects? We will show you how to cover protection, availability and interface resilience with one framework on the Cloudflare platform. Arrange a free pilot →
Integrity is a certified Cloudflare partner focused on the Czech and Slovak market.
Integrity
news
Articles from our blog. The latest about the Cloudflare platform and everything around it.
.jpg)

.jpg)



