News

Titolo Principale

EU DORA Regulation: Mandatory Compliance for the Financial Sector by January 2025

By 17 January 2025, European financial institutions and their third-party technology service providers must ensure that their systems comply with the technical standards established by the Digital Operational Resilience Act (DORA), EU Regulation 2022/2554, which establishes a binding and comprehensive framework for managing information and communication technology (ICT) risks.

On 17 January 2024, the three European supervisory authorities (EBA, EIOPA and ESMA – the ESAs) published the first set of final draft technical standards provided for by DORA.

Contribution by Mariam Naveriani.

Strengthening the Digital Resilience of Financial Institutions

The proliferation of digital technologies continues to grow, including in the financial services sector, increasing the need for European financial institutions to be prepared to prevent and manage cyber incidents.

The DORA regulation, which is part of the broader European Commission package on digital finance launched in September 2020, introduces a robust regulatory framework, requiring financial entities to implement effective incident management processes and reporting protocols, as well as solid procedures for managing ICT risks.

The obligations provided for by the regulation apply to traditional financial institutions, including banks, payment institutions, investment firms and emerging new players such as crypto-asset service providers and crowdfunding platforms. Compliance is also required from third-party ICT service providers that offer cybersecurity systems and services, cloud, data center, credit rating and data analytics.

For the entities involved, the DORA regulation represents both a challenge and an opportunity. While ensuring compliance with the regulation requires significant investment in ICT infrastructure and solid cybersecurity practices, on the other hand it contributes to improving overall resilience.

Non-compliance with European regulations not only exposes entities to significant penalties, but also jeopardizes the trust that customers place in companies’ ability to protect their financial data. 

Handbook for Compliance with the Regulation

With the 2025 deadline now approaching, financial institutions must act immediately to ensure they are on track to meet the technical requirements for financial entities and ICT providers under the DORA regulation, which are divided into four areas:

  • – ICT risk management and governance
  • – Incident reporting and response
  • – Digital operational resilience testing
  • – Third-party risk management

The recipients of the regulation must develop and maintain a comprehensive ICT risk management system. This involves preliminary mapping of IT systems, identification and classification of potential vulnerabilities, execution of periodic risk assessments and definition of mitigation strategies.

Furthermore, financial institutions must establish a structured protocol for incident reporting to ensure timely and accurate communication of any disruptions to the European supervisory authorities (ESAs).

The regulation also requires the execution of basic digital operational resilience testing at least once a year; more critical financial entities must also undergo, every three years, advanced penetration testing to ensure system resilience.

It is also necessary to assess and manage risks arising from ICT service providers, ensuring that they comply with the same high standards of operational resilience.

The regulation finally encourages information sharing between financial institutions and ICT service providers to strengthen compliance and collective resilience against digital threats.