Cleo
CompanyPricing
Request a Demo
Anaelle GuezNaomie Halioua
Request a Demo
Cleo

AI-powered regulatory intelligence.

contact@cleolabs.co

Solutions

  • Due Diligence
  • Product Compliance

Company

  • About
  • Research
  • Blog

Jurisdictions

  • ๐Ÿ‡ช๐Ÿ‡บ European Union
  • ๐Ÿ‡ซ๐Ÿ‡ท France
  • ๐Ÿ‡ฉ๐Ÿ‡ช Germany
  • ๐Ÿ‡ฌ๐Ÿ‡ง United Kingdom
  • ๐Ÿ‡บ๐Ÿ‡ธ United States

Legal

  • Privacy
  • Terms
  • Security

Events

  • VivaTech ParisJun 11โ€“14, 2026

ยฉ 2026 Cleo Labs. All rights reserved.

GDPREU Data
๐Ÿ‡ช๐Ÿ‡บEuropean Union

DORA compliance in European Union

DORA (Regulation 2022/2554) creates a unified ICT risk management framework for all EU financial entities. It applies to over 22,000 entities including banks, insurers, investment firms, crypto-asset providers, and their critical ICT suppliers.

Run a Free Scan
Anaelle GuezNaomie Halioua
or book a call

Enforcement authority

ESAs (EBA, ESMA, EIOPA) for oversight framework designation; national competent authorities (NCAs) for enforcement

Maximum sanctions

National authorities determine penalties. Critical ICT providers face fines up to 1% of average daily worldwide turnover for up to 6 months. Periodic penalty payments of up to 0.5% of daily turnover.

Key obligations

What DORA requires from organizations operating in European Union.

Implement a comprehensive ICT risk management framework with board-level oversight
Report major ICT incidents to national authorities within strict timelines
Conduct advanced threat-led penetration testing (TLPT) every 3 years for significant entities
Maintain a register of all ICT third-party contracts and conduct concentration risk analysis
Share cyber threat intelligence with other financial entities and authorities

Local context in European Union

DORA became applicable on January 17, 2025. The ESAs have published Regulatory Technical Standards (RTS) and Implementing Technical Standards (ITS) that detail specific requirements. Critical ICT third-party providers are directly supervised at EU level.

DORA by industry in European Union

Retail & Consumer GoodsReal EstateFinTechHealthTechInsuranceEnergy & UtilitiesSustainability & ESG

Frequently asked questions

How does DORA apply in European Union?

DORA (Regulation 2022/2554) creates a unified ICT risk management framework for all EU financial entities. It applies to over 22,000 entities including banks, insurers, investment firms, crypto-asset providers, and their critical ICT suppliers.

Who enforces DORA in European Union?

ESAs (EBA, ESMA, EIOPA) for oversight framework designation; national competent authorities (NCAs) for enforcement

What are the penalties for DORA non-compliance?

National authorities determine penalties. Critical ICT providers face fines up to 1% of average daily worldwide turnover for up to 6 months. Periodic penalty payments of up to 0.5% of daily turnover.

Read our complete DORA compliance guide

DORA in other jurisdictions

๐Ÿ‡ซ๐Ÿ‡ทFrance๐Ÿ‡ฉ๐Ÿ‡ชGermany๐Ÿ‡ฌ๐Ÿ‡งUnited Kingdom๐Ÿ‡บ๐Ÿ‡ธUnited States๐Ÿ‡ง๐Ÿ‡ทBrazil๐Ÿ‡ฆ๐Ÿ‡บAustralia๐Ÿ‡ฎ๐Ÿ‡ณIndia

Check your DORA compliance now

Run a free scan to see your risk score and applicable obligations.

Run a Free Scan
Anaelle GuezNaomie Halioua
or book a call