Skip to main content
Category: Regulatory & Legal Obligations

Digital Operational Resilience Act

Also known as: DORA, Digital Operational Resilience Act
Simply put

The Digital Operational Resilience Act (DORA) is a European Union regulation that focuses on strengthening how financial sector organizations manage information and communications technology (ICT) risk and stay operational during disruptions. Its goal is to unify and improve the cyber resilience of the financial sector across the EU. Note that the term DORA is also used for unrelated things, such as a U.S. state regulatory agency and a software delivery research program, which should not be confused with this regulation.

Formal definition

DORA is an EU regulation targeting ICT risk management and operational resilience within the financial services sector, intended to enhance and harmonize cyber resilience requirements across EU financial entities. It addresses ICT risk and operational resilience as a governance and business-risk matter for in-scope financial organizations. Based on the available evidence, further specifics such as covered entity types, technical controls, reporting obligations, and enforcement mechanisms are not detailed here and should be confirmed against the regulation text and authoritative guidance before asserting compliance scope.

Why it matters

For financial sector organizations operating in the European Union, DORA elevates ICT risk and operational resilience from a purely technical concern to a governance and business-risk matter that demands executive attention. Because the regulation is specifically designed to enhance and unify the cyber resilience of the financial sector across the EU, in-scope entities can no longer treat operational disruption purely as an IT problem to be handled below the leadership level. The framing of resilience as a board- and officer-level accountability aligns with how security leadership is increasingly expected to function.

The practical significance is that a harmonized EU-wide expectation reduces the fragmentation that financial entities previously navigated across member states, but it also raises the baseline for what constitutes adequate ICT risk management. Organizations that have historically underinvested in operational resilience may face a meaningful gap between current practice and regulatory expectation. It is worth noting that the term DORA is also used for unrelated things, including a U.S. state regulatory agency and a software delivery research program, so leaders should confirm they are working from the EU regulation and not conflating it with similarly named references.

Who it's relevant to

EU financial sector organizations
Financial entities operating within the European Union are the primary audience, since DORA is specifically directed at ICT risk and operational resilience in financial services. These organizations should confirm their covered status against the regulation text rather than assuming inclusion or exclusion.
Security and risk leaders, including virtual and fractional CISOs
Because DORA frames resilience as a governance and business-risk matter, security leaders engaged to provide strategy and oversight may be asked to help interpret its expectations and guide program development. A virtual or fractional CISO can typically advise on readiness and governance direction, but accountability for regulatory compliance generally remains with the client organization and its officers unless a contract specifies otherwise, and the specific obligations should be validated against authoritative sources.
Boards and executive officers of in-scope entities
As DORA positions ICT risk and operational resilience as an organizational governance concern, boards and senior officers hold the accountability for how their organizations respond. This is a leadership responsibility that cannot be fully delegated to technical teams or to an external advisor.

Inside DORA

ICT Risk Management Framework
DORA (the Digital Operational Resilience Act) requires in-scope financial entities to maintain a documented framework for identifying, protecting against, detecting, responding to, and recovering from information and communication technology (ICT) risks. A virtual CISO can advise on developing and maturing such a framework, though accountability for adopting it typically remains with the entity's management body.
ICT-Related Incident Management and Reporting
The regulation establishes expectations for classifying, managing, and reporting major ICT-related incidents to competent authorities within defined timelines. A vCISO commonly supports the design of governance and reporting processes, but the execution of hands-on incident response and the actual regulatory submissions generally sit with the organization and its officers unless explicitly contracted otherwise.
Digital Operational Resilience Testing
DORA calls for regular testing of ICT systems, which may include vulnerability assessments and, for certain entities, advanced threat-led penetration testing. A virtual CISO typically directs and interprets testing strategy at a governance level rather than performing the technical testing personally.
ICT Third-Party Risk Management
The framework addresses oversight of ICT third-party service providers, including contractual provisions and monitoring of critical providers. A vCISO often advises on vendor governance and risk assessment approaches, which is a governance and business-risk function rather than a purely technical one.
Information Sharing Arrangements
DORA encourages, on a voluntary basis, the sharing of cyber threat information and intelligence among financial entities. A vCISO may help evaluate whether participation aligns with the organization's risk posture and governance model.
Governance and Management Body Responsibility
The regulation places responsibility for the ICT risk management framework with the entity's management body. This is important to separate from a vCISO engagement: a virtual CISO advises and directs, but legal and organizational accountability typically remains with the client organization and its officers unless a contract specifies otherwise.

Common questions

Answers to the questions practitioners most commonly ask about DORA.

Does DORA only apply to banks and large financial institutions?
No. DORA applies broadly across the EU financial sector, covering many types of financial entities as well as certain critical information and communication technology (ICT) third-party service providers. A common mistake is assuming it is limited to large banks; smaller financial entities and their technology suppliers may also fall within scope. Applicability and the specific obligations can vary by entity type and size, so organizations should confirm their status rather than assume exemption. A virtual CISO can help interpret how the regulation maps to a given organization, but scoping determinations often require legal and compliance input as well.
Can a virtual CISO make our organization DORA compliant or guarantee compliance?
Not in the sense of guaranteeing an outcome. A virtual CISO typically supports readiness by advising on governance, risk management, ICT risk frameworks, and program development aligned to DORA's expectations. However, legal and organizational accountability for compliance generally remains with the client organization and its officers. A vCISO advises and directs; they do not assume regulatory accountability unless a contract explicitly specifies otherwise. Achieved compliance also depends on organizational maturity, client cooperation, and the actions the organization ultimately takes.
How can a virtual CISO help us prepare for DORA?
In many engagements, a virtual CISO supports DORA readiness at the strategy and governance level, such as helping establish ICT risk management practices, reviewing incident reporting processes, advising on resilience testing approaches, and supporting oversight of ICT third-party relationships. The specific activities vary by provider and scope. Hands-on operational work, such as tool administration or executing tests, is typically out of scope unless separately contracted.
Where does a vCISO engagement typically end when addressing DORA's ICT third-party risk requirements?
A virtual CISO generally advises on the governance framework for managing ICT third-party risk, such as helping define oversight processes, contractual expectations, and risk assessment approaches. They typically do not perform ongoing operational vendor monitoring or day-to-day supplier management unless that is explicitly included in the engagement. Clarifying these scope boundaries in the contract helps avoid assuming the vCISO is functioning as a managed service.
What does a virtual CISO need from our organization to support DORA-related work effectively?
Engagement value often depends on defined scope, access to relevant stakeholders, and client cooperation. For DORA-related support, this typically includes access to leadership, information about existing ICT systems and third-party relationships, current risk management and incident processes, and involvement from legal and compliance functions. Without stakeholder access and organizational engagement, the ability of a vCISO to support readiness may be limited.
Does engaging a virtual CISO for DORA mean we no longer need an internal security team or other functions?
No. A virtual CISO provides executive-level strategy and governance guidance but does not replace an entire security team, nor do they function as a managed security service provider. DORA's expectations often touch operational, legal, and compliance functions that fall outside a typical vCISO scope. In many engagements the vCISO helps direct and coordinate these functions rather than performing all of the underlying work.

Common misconceptions

Engaging a virtual CISO for DORA readiness transfers regulatory accountability to the vCISO or their firm.
Accountability for the ICT risk management framework typically remains with the financial entity's management body and officers. A vCISO usually advises and directs on strategy, governance, and program development, and does not assume regulatory liability unless a contract explicitly specifies such an arrangement.
A virtual CISO can guarantee DORA compliance or perform all the required work end to end.
A vCISO engagement typically supports readiness rather than guaranteeing an outcome. Hands-on operational tasks such as resilience testing execution, incident response, and tool administration are generally out of scope unless explicitly contracted, and value depends heavily on organizational maturity, stakeholder access, and client cooperation.
A vCISO supporting DORA is equivalent to a managed security service provider handling operational resilience.
These roles differ. A virtual CISO provides executive-level strategy, governance, and risk direction, whereas ongoing monitoring, testing, and operational security services are functions more typical of an MSSP or internal team. Conflating the two often leads to unmet expectations about what the engagement delivers.

Best practices

Define engagement scope in writing, clearly stating which DORA-related governance and advisory activities the vCISO covers and which operational tasks (such as testing execution, incident response, and regulatory submissions) remain with the organization or other providers.
Confirm in the contract where accountability sits, ensuring the management body retains responsibility for adopting the ICT risk management framework while the vCISO advises and directs.
Frame the work as supporting DORA readiness rather than asserting guaranteed compliance, and set expectations that outcomes depend on organizational maturity and stakeholder cooperation.
Secure access to key stakeholders across risk, IT, legal, and the management body, since DORA's governance and third-party oversight elements require cross-functional business and risk decisions, not purely technical input.
Establish governance processes for incident classification, reporting timelines, and third-party risk oversight early, coordinating with the parties who will actually perform hands-on execution.
Use qualified language in reporting to leadership, distinguishing between readiness activities the vCISO can direct and testing or operational functions that require specialist teams or providers.