Themio · Regulatory Guides

DORA: Digital Operational Resilience for Financial SMEs

DORA doesn't wait for you to reach bank scale. Who must comply, what to build, and where enforcement stands in 2026.

Visual showing the same digital resilience framework applying across financial organisations of different sizes
DORA at a glance

Operational resilience across the financial value chain

Direct EU Regulation

Regulation (EU) 2022/2554 applies directly across all 27 Member States since 17 January 2025. No transposition required.

No Size Exemption

Fintechs, payment institutions, brokers and insurers must comply regardless of size. Only narrow micro-entity relief under Art. 16.

ICT Third Parties Included

SaaS, cloud hosts and software vendors supplying financial entities are pulled in through mandatory contractual terms.

2026: Supervision Year

With ~44% of institutions reporting compliance gaps, supervisory authorities are actively checking resilience and registers.
Regulation (EU) 2022/2554

What is DORA

DORA (Regulation EU 2022/2554), the Digital Operational Resilience Act, sets ICT risk management, incident reporting and resilience-testing rules for the EU financial sector. It has applied directly, no national transposition needed, since 17 January 2025 .

Unlike GDPR or the AI Act, DORA doesn't carry a broad small-company exemption: a five-person fintech and a national bank answer to the same core rules, adjusted for scale, not exempted by it.

Scope & Entities

Who has to comply

Two distinct groups fall under DORA's binding perimeter:

1. Financial Entities

Banks, insurers, investment firms, payment institutions, electronic money institutions, crypto-asset service providers (CASPs) and more, regardless of size.

2. ICT Third-Party Providers

Any company—including an SME that has never called itself a financial company—that supplies cloud hosting, software, data analytics or other IT services to a financial entity under contract.

Article 16 Microenterprises:

If your client is a bank and DORA reaches into your contract with them, DORA reaches you. Article 16 gives genuine microenterprises a lighter regime, but it's narrow: check your headcount and balance sheet against the Regulation's own thresholds before assuming it covers you.

Mandatory Pillars

Core obligations

1

ICT Risk Management Framework

Maintain an ICT risk management framework covering your systems, applications and data, ensuring continuous identification, protection, detection and recovery capabilities.

2

Strict Incident Reporting Timelines

Report major ICT-related incidents to your competent authority on strict timelines (initial notification, intermediate report, and final post-incident root cause report).

3

Operational Resilience Testing

Test operational resilience regularly, including vulnerability assessments, software testing and, for larger or more critical entities, advanced threat-led penetration testing (TLPT).

4

ICT Third-Party Risk & Register of Information

Manage ICT third-party risk formally, with a comprehensive Register of Information covering every contract that touches your technology stack and critical functions.

Direct Management Body Accountability

Financial entities have to build this into governance, not treat it as an IT-department side project; DORA holds management bodies directly accountable for ICT risk oversight.

Four-stage visual of the core DORA operational resilience obligations
Supervision & Enforcement

Where enforcement stands in 2026

2025 was the implementation year. 2026 is the supervision year.

Industry surveys put roughly 44% of financial institutions short of full DORA compliance , with mid-sized firms in the hardest position: too large for the Article 16 micro-entity regime, too small to match the compliance resources of a major bank.

Regulators, including several Nordic national authorities, have named digital resilience a top supervisory priority for 2026, and operational resilience testing is moving from a paper requirement to something supervisors actually check in on-site and remote reviews.

Supply Chain Impact

If you're an SME supplying a financial client

You may not think of yourself as "in financial services," and DORA may still reach you.

Audit rights and contractual questionnaires:

If a bank, insurer or investment firm asks you to sign DORA-specific contract terms, accept an audit right, or complete a third-party risk questionnaire, that's not boilerplate. It's your client meeting their own Register of Information obligation, and your answers become part of their regulatory file.

Failing to provide structured assurance can result in procurement disqualification or blocked contract renewals.

Frequently Asked Questions

Common questions about DORA for SMEs

I run a 15-person fintech. Am I exempt from DORA?
Not automatically. DORA applies to financial entities regardless of size; only genuine microenterprises meeting Article 16's specific thresholds get a lighter regime, and even that regime still requires an ICT risk framework, just a simplified one. Check your entity type and size against the Regulation directly rather than assuming a size cutoff protects you.
We're a software company, not a bank. Why is a client asking us about DORA?
Because DORA treats your client's ICT third-party risk as their problem to manage, which makes it your problem to help solve. If you provide hosting, software or data services under contract to a bank, insurer or investment firm, that client needs contractual and operational assurances from you to meet their own Register of Information obligation. Expect this to show up in procurement and renewal conversations even if you never register as a financial entity yourself.
What's the difference between DORA and NIS2 for a company that might fall under both?
DORA is sector-specific and financial-services-only; NIS2 is broader, covering 18 critical sectors including finance. Where both apply, DORA generally takes precedence as the more specific regime (lex specialis), but the practical obligations, risk management, incident reporting, resilience testing, overlap closely enough that a genuine dual-scope company should build one integrated programme rather than two parallel ones.
What happens if we miss a DORA incident-reporting deadline?
Reporting requirements are strict and time-bound; supervisors treat missed or incomplete reports as a compliance failure in their own right, separate from whatever caused the underlying incident. As 2026 supervision intensifies, expect regulators to test this specifically rather than only reviewing incidents after the fact.

Not sure whether DORA, NIS2 or the AI Act applies to your business?

Map your contracts, assess your ICT resilience, and automate your compliance registers with Themio.