Cleo
CompanyLegal Data
Request a demo
Anaelle GuezNaomie Halioua
Request a demo
Cleo

AI-powered regulatory intelligence.

contact@cleolabs.co

Solutions

  • Product Compliance

Company

  • About
  • Research
  • Blog
  • Compliance Guides

Jurisdictions

  • 🇪🇺 European Union
  • 🇫🇷 France
  • 🇩🇪 Germany
  • 🇬🇧 United Kingdom
  • 🇺🇸 United States

Legal

  • Privacy
  • Terms
  • Security

Events

  • VivaTech ParisJun 11–14, 2026

© 2026 Cleo Labs. All rights reserved.

GDPREU DataSOC 2 Type IIISO 27001
🇺🇸United StatesActive

DORA compliance in the US

DORA (Digital Operational Resilience Act) applies to financial entities and their ICT third-party providers in the EU, ensuring digital operational resilience.

Start free scan
Anaelle GuezNaomie Halioua
or book a call

Enforcement authority

National financial supervisory authorities + ESAs (EBA, ESMA, EIOPA)

Maximum sanctions

Penalties determined by national competent authorities. Critical ICT providers face fines up to 1% of daily worldwide turnover.

Obligations

Key obligations

What DORA requires from organizations operating in the US.

Implement ICT risk management framework
Establish ICT-related incident reporting procedures
Conduct digital operational resilience testing
Manage ICT third-party risk with contractual provisions
Participate in threat-led penetration testing (TLPT)

Local context

Local context in the US

DORA applies from January 17, 2025. Financial entities must ensure full compliance with ICT risk management requirements.

Connects to

DORA by industry in the US

Retail & Consumer GoodsCosmetics & Personal CareElectronics & Connected DevicesFood & BeveragePet Care & Pet FoodSporting GoodsMedical DevicesDrugs & PharmaceuticalsInsuranceEnergy & Utilities

Frequently asked questions

How does DORA apply in the US?

DORA (Digital Operational Resilience Act) applies to financial entities and their ICT third-party providers in the EU, ensuring digital operational resilience.

Who enforces DORA in the US?

National financial supervisory authorities + ESAs (EBA, ESMA, EIOPA)

What are the penalties for DORA non-compliance?

Penalties determined by national competent authorities. Critical ICT providers face fines up to 1% of daily worldwide turnover.

Read our complete DORA compliance guide

DORA in other jurisdictions

🇪🇺European Union🇫🇷France🇩🇪Germany🇬🇧United Kingdom🇧🇷Brazil🇦🇺Australia🇮🇳India

Check your DORA compliance now

Start free scan to see your risk score and applicable obligations.

Start with 1 product
Start free scan
Anaelle GuezNaomie Halioua
or book a call