Digital Operational Resilience Act (DORA) penalty/fines and compliance scope explained
July 2, 2026 10 min read 429 views
DORA governs how financial entities depend on information and communication technology, recognizing that modern finance runs on digital infrastructure, and that infrastructure is itself a systemic risk.
DORA is no longer coming. It is here. The Digital Operational Resilience Act has been fully applicable across the EU since January 17, 2025, and 2026 is the year supervisors shift from readiness checks to active enforcement. The shift to active enforcement in 2026 marks a turning point in the regulatory landscape for European financial services, moving from self-assessment to supervised accountability.
That raises the stakes for every financial entity and its ICT providers. Non-compliance now carries real financial, administrative, and even criminal consequences. According to KPMG, only about a third of major European financial institutions were confident they could meet all DORA requirements by the deadline, so many firms are still exposed.
This guide breaks down the penalties and how to avoid them.
DORA compliance and DORA regulation: Key takeawaysOmnichannel fulfilment strategy: Key takeaways
- DORA has applied since January 17, 2025. The grace period is over.
- 2026 is the enforcement year. National authorities are using their full supervisory powers.
- Penalties are steep. Up to 2% of annual worldwide turnover for firms, up to EUR 1 million for individuals, and up to EUR 5 million for critical ICT providers.
- Oversight of big tech is real. In November 2025 the ESAs named the first 19 Critical ICT Third-Party Providers, including AWS, Microsoft, Google, and IBM.
- Readiness is uneven. Around half of institutions expected full compliance by the end of 2025, and the Register of Information remains the hardest requirement.
- Compliance with DORA is not a one-department task, it touches ICT, legal, risk, procurement, and the C-suite simultaneously.
The five pillars of the Digital Operational Resilience Act (DORA act)
DORA’s five pillars do not operate in isolation, together they form an integrated architecture for digital resilience that spans people, processes, and technology. The digital landscape changes. Threats become more complex. DORA is timely and imperative. DORA’s five pillars form a solid basis for cyber resilience in the European financial sector.
I. ICT risk management
DORA will greatly influence the ICT risk management standard. This standard mandates European financial institutions to assess, mitigate, and manage risks linked to their ICT systems. DORA requires each financial entity to maintain a documented, tested, and auditable ICT risk management framework, one that is reviewed at least annually and updated after every major incident.
DORA reinvents the EU’s financial organizations’ protection and rehabilitation pattern against digital threats. Institutions that already invested in mature risk management frameworks will find DORA’s requirements more familiar, but even well-prepared firms often discover gaps at the third-party and testing layers.
II. Incident reporting
DORA requires transparency about data security incidents for partners, employees, and clients. Under DORA, not every disruption triggers a full report, but classifying what constitutes a major ICT-related incident requires clear internal criteria, documented thresholds, and tested escalation paths.
Incident reporting is crucial for financial institutions under DORA. They must have robust systems to detect, report, and analyze ICT incidents. This framework ensures incidents are managed well to prevent future issues.
A strong foundation starts with data security in financial services.
III. Digital operational resilience testing
The European Commission will conduct more ad hoc testing to create a cybercrime-proof data environment. Digital operational resilience testing, mandated by DORA, is crucial. It ensures financial institutions’ systems can withstand cyber threats.
IV. Third-party ICT risk management
Third-party risk has moved from a footnote in risk registers to a board-level concern, DORA formalizes that shift with binding obligations and direct oversight. More accountability and responsibility for your third-party vendors is coming. Third-party ICT risk management is integral to the DORA framework, focusing on financial institutions’ relationships with external ICT service providers. This DORA element ensures third-party engagements don’t compromise the financial institution’s operational resilience.
According to Avenga experts, third-party ICT risk is where most institutions have the least visibility, and where supervisors will look first.
We break down the hardest parts in addressing key data pain points in DORA compliance.
V. Information sharing
Your organization must be ready to share more information and do it securely. Information sharing in the financial sector focuses on cybersecurity collaboration, as outlined in the DORA. This pillar fosters a community-driven approach by encouraging financial entities to share cyber threat information. This helps manage risks and build resilience.
The aforementioned pillars emphasize the EU’s commitment to protect its financial ecosystem with improved digital operational resilience. Financial entities adopting DORA will strengthen defenses. This leads to a more secure financial infrastructure in Europe. The ultimate goal of DORA is to raise the operational resilience of financial entities across the EU to a level where even severe ICT disruptions do not threaten market stability.
DORA is in force and enforcement is ramping up. Get your DORA readiness assessment from Avenga in under 10 minutes and close the gaps before supervisors find them.
DORA’s penalty regime and framework
DORA enforces a strict penalty regime to ensure digital operational resilience in financial regulations. Non-compliance has severe repercussions, reflecting the Regulation’s strict position on cyber resilience.
Financial penalties under DORA
DORA establishes rigorous financial penalties for violations of its requirements. A breach could see institutions fined up to 2% of their total annual worldwide turnover or up to 1% of the company’s average daily turnover worldwide. Individuals and companies could face fines of up to €1.000.000.
This oversight is now live. On November 18, 2025, the EBA, EIOPA, and ESMA published the first list of 19 designated Critical ICT Third-Party Providers, including AWS, Microsoft Azure, Google Cloud, IBM, Bloomberg, and the London Stock Exchange Group. The designation of critical third-party providers is one of the most consequential steps in the Oversight Framework, as it extends regulatory reach beyond the financial institution itself. These providers now face direct inspection and oversight powers from the European Supervisory Authorities.
The oversight regime for critical third-party ICT service providers gives the ESAs powers to request information, conduct on-site inspections, and issue recommendations, powers that apply even to providers headquartered outside the EU.
Since hyperscalers are now in scope, see our guide to cloud security for banks in a regulated environment.
For comparison, financial penalties associated with non-compliance with the General Data Protection Regulation (GDPR) can reach €20.000.000 in most severe cases or 4% of the total global turnover. One can anticipate that a company failing to comply with DORA and GDPR will face almost certain financial peril.
Authority to impose penalties
European Supervisory Authorities (ESAs) are responsible for imposing penalties. They are empowered by DORA to uphold digital operational resilience in finance. As stipulated in Article 97, competent authorities have the necessary supervisory and investigatory powers and the ability to publish notices of administrative penalties, ensuring transparency and accountability.
Designated entities and timeframe
These penalties were published in the Official Journal on December 27, 2022, under Regulation (EU) 2022/2554, and became enforceable on January 17, 2025. As an EU regulation, DORA applies directly in all member states without requiring national transposition, meaning the same rules, the same penalties, and the same supervisory expectations apply from Lisbon to Warsaw.
2025 was largely a transition year, with supervisors assessing frameworks and identifying gaps. 2026 marks the move to active enforcement, with national competent authorities ready to use formal actions and financial penalties.
Operational readiness and business presence
Critical ICT third-party service providers established outside the EU must ensure an adequate business presence within the Union to facilitate oversight and ensure that penalties can be effectively imposed and enforced. This provision, detailed in paragraph 81, requires designated critical service providers to establish a subsidiary in the EU within 12 months of their designation.
Hybrid funding for oversight tasks
The ESAs may incur costs before the start of the Oversight Framework, for which a hybrid funding model is proposed in paragraph 96. Contributions from the Union and national competent authorities will fund the development of dedicated ICT systems supporting oversight.
Hybrid funding for oversight tasks
Article 51 outlines how competent authorities should exercise their power to impose administrative penalties and remedial measures. These include:
- The nature of the breach — what rules or regulations were violated;
- The gravity of the breach — the seriousness and impact of the non-compliance;
- The duration of the breach — how long the non-compliance continued;
- The degree of responsibility of the offending party — their role and influence over the circumstances leading to the breach;
- The financial strength of the responsible party — their economic capacity to endure fines;
- The importance of gains or losses avoided — whether the breach led to an unfair financial advantage or prevented a loss;
- The level of cooperation with the supervisory authority — the offending party’s efforts to collaborate during the investigation and remedy the situation.
Understanding these factors is crucial for financial institutions as they navigate the requirements and implications of DORA’s penalty framework.
Criminal penalties and fines under DORA
The cost of non-compliance compounds over time: initial supervisory findings trigger remediation demands, repeat failures attract financial penalties, and persistent gaps can result in criminal liability for individuals. Member States can impose criminal penalties for breaches of DORA, as per Article 52. States must ensure measures are in place to enable liaising with judicial, prosecuting, or criminal justice authorities to implement these penalties effectively.
DORA’s penalty structure fortifies the financial sector against cyber threats. By integrating penalties with preventive measures and reporting obligations, experts behind DORA ensure a resilient economic ecosystem and maintain its participants’ integrity and trust. Without a doubt, this makes DORA readiness even more critical.
Is your organization DORA-ready? Get an initial estimate of your DORA readiness in less than 10 minutes. Our team of experts came up with a short yet comprehensive survey. Let us guide you on your journey toward painless and smooth DORA compliance. Take a survey
Readiness is still uneven. Around half of institutions expected to be fully compliant by the end of 2025, and nearly half name the Register of Information as their single hardest requirement. According to Avenga experts, this register, a full inventory of every ICT third-party contract, is where most firms underestimate the work.
FAQ
Conclusion
In our experience, the firms that handle DORA well treat it as an operating model change, not a one-time compliance project.
Contact our DORA compliance experts. Make sure your company aligns with DORA requirements and won’t face any problems during possible compliance checks.
Interested to learn more about inventory management and the omnichannel fulfillment approach? Contact Avenga, your trusted expert in retail fulfillment.