DORA — Digital Operational Resilience Act, Regulation (EU) 2022/2554 — is the European Union standard that establishes mandatory digital operational resilience requirements for the financial sector. Applicable since January 17, 2025, the regulation organizes ICT risk governance into five pillars: ICT risk management, incident reporting, resilience testing, critical third-party management, and threat intelligence sharing.
The Digital Operational Resilience Act (DORA) transforms digital operational resilience into a prudential requirement for banks, insurance companies, payment institutions, asset managers, investment firms, crypto-asset providers, and other regulated financial entities in the European Union.
In practice, DORA changes how financial organizations and their technology providers need to document, test, monitor, and demonstrate the continuity of critical digital services. The focus shifts from isolated cybersecurity to the ability to keep operations running even in the face of severe incidents, technological failures, provider unavailability, or cyberattacks.
For CIOs, CISOs, operations leaders, risk managers, compliance teams, and ICT vendors serving European financial institutions, DORA impacts contracts, audits, business continuity plans, incident management, asset inventory, CMDB, third-party dependencies, and operational evidence.
What is DORA?
DORA is the European regulation created to harmonize digital operational resilience requirements in the financial sector. Before it, European banks, insurance companies, and other financial institutions were subject to fragmented rules across different countries and local authorities.
With DORA, the European Union began requiring a common framework for financial institutions to prevent, withstand, respond to, and recover from incidents related to information and communication technologies (ICT).
The regulation entered into force on January 16, 2023, and became applicable on January 17, 2025. From that date, the entities covered must demonstrate compliance with the requirements for governance, risk management, reporting, testing, third parties, and supervision.
What is digital operational resilience?
Digital operational resilience is the ability of an organization to continue delivering critical services even in the face of technological failures, cyberattacks, system unavailability, supplier disruptions, or severe operational events.
In the context of DORA, this means that the financial institution needs to demonstrate, through formal processes and auditable evidence, that it knows its critical assets, systems, data, and dependencies; continuously monitors ICT risks; has structured processes for detecting and reporting incidents; regularly tests its response and recovery capabilities; controls risks associated with third-party ICT vendors; and maintains sufficient documentation, records, and audit trails for regulatory oversight.
The key point is that digital operational resilience doesn't depend solely on security tools. It requires integration between governance, processes, data, architecture, continuity, suppliers, and operations.
Who does DORA apply to?
DORA applies to financial institutions regulated in the European Union and to third-party ICT service providers that provide services to these institutions. Key groups covered include banks and credit institutions, payment and electronic money institutions, insurers and reinsurers, investment firms and asset managers, investment funds and administrators, crypto-asset providers, crowdfunding platforms, rating agencies, trading and securitization repositories, and third-party ICT service providers—including cloud, data centers, software, telecommunications, outsourcing, and critical digital services.
Although DORA is a European standard, its effects can reach Brazilian technology companies through contracts with financial institutions in the European Union. In these cases, the European client may require specific clauses regarding auditing, continuity, data localization, incident reporting, participation in testing, and evidence of operational controls.
The five pillars of DORA
1. ICT Risk Management
The first pillar requires the financial institution to have a formal ICT risk management framework. This framework must be approved, supervised, and reviewed by the organization's management body. In practice, the institution needs to maintain controls to identify critical assets, map technology-supported business functions, assess risks, implement protection and detection mechanisms, execute continuity plans, and maintain up-to-date documentation on systems, processes, and responsibilities.
2. Management, classification and reporting of ICT incidents
DORA requires financial institutions to establish processes for detecting, recording, classifying, managing, and reporting ICT-related incidents. Incidents classified as significant or major must be reported to the relevant authorities according to regulatory criteria and standardized templates. This increases the need for well-defined processes for ITSM, SecOps, observability, crisis management, communication, and event traceability.
3. Digital operational resilience tests
The regulation requires financial institutions to conduct regular digital operational resilience tests. These tests may include vulnerability assessments, scans, code analysis, continuity testing, simulations, crisis exercises, and recovery testing. For larger, more significant, or critical entities, DORA mandates Threat-Led Penetration Testing (TLPT) — penetration tests driven by threat intelligence that simulate realistic attack scenarios and must involve critical systems, processes, people, and, where applicable, ICT vendors.
4. ICT Third-Party Risk Management
Third-party management is one of the most important pillars of DORA. Financial institutions need to maintain control over their ICT contracts, assess concentration risks, monitor critical suppliers, and document relevant dependencies.
One of the central elements is the Register of Information (RoI), a structured record of contracts and arrangements with third-party ICT providers. This record should contain information about legal entities, supported functions, contracts, suppliers, services, data location, criticality, and operational dependencies. Contracts with ICT suppliers should include clauses such as service description, service levels, data processing and storage location, audit rights, cooperation obligations, incident support, continuity plans, subcontracting conditions, and exit strategies.
5. Sharing threat information
DORA also encourages the sharing of information and intelligence on cyber threats among financial institutions. The goal is to strengthen the sector's collective resilience, provided that rules of confidentiality, data protection, and competition are respected. This pillar reinforces the importance of integrated processes for threat intelligence, vulnerability management, incident response, and security governance.
Dora's timeline
| Date | March |
|---|---|
| September 2020 | Proposal from the European Commission as part of the digital finance package. |
| December 14, 2022 | Adoption of Regulation (EU) 2022/2554 |
| December 27, 2022 | Publication in the Official Journal of the European Union |
| January 16, 2023 | Entry into force of the regulation |
| 2024 and 2025 | Publication of regulatory technical standards, implementation standards and delegated acts. |
| January 17, 2025 | Start of mandatory DORA implementation. |
| November 18, 2025 | ESAs publish the first list of critical third-party ICT providers. |
| 2026 | Operational maturity phase, auditing, supervision and evolution of resilience programs. |
DORA and ServiceNow: where is the operational connection?
DORA does not require a specific technology. However, its requirements strongly align with operational capabilities typically implemented on the ServiceNow platform. For organizations already using ServiceNow, DORA compliance can be treated as a platform maturity journey, focusing on reliable data, auditable processes, evidence automation, and integration between risk, security, assets, suppliers, and operations.
| Pillar Dora | ServiceNow capabilities |
|---|---|
| Inventory of critical assets and functions | CMDB, CSDM, ITAM, HAM, SAM, Service Mapping |
| ICT risk management | IRM, Operational Risk, Policy and Compliance |
| Incident reporting and management | ITSM, Major Incident Management, SecOps, approval workflows |
| Resilience tests | Operational Resilience, Business Continuity, Vulnerability Response |
| Third-party management | Third-Party Risk Management, Vendor Management Workspace, Register of Information |
| Monitoring and response | ITOM, Event Management, AIOps, Observability, alert automation |
ServiceNow itself already offers applications and capabilities focused on digital operational resilience, including resources for managing legal entities, functions, third parties, contracts, and generating packages related to the Register of Information.
Impact on Brazilian ICT suppliers
Brazilian companies that provide technology, software, cloud, outsourcing, support, data center, integrations, or managed services to European financial institutions should pay close attention to DORA. Even when the Brazilian company is not directly regulated by a European authority, it may be impacted by contractual requirements from the European financial client.
These requirements may include specific audit and inspection clauses, evidence of business continuity and disaster recovery, information on data location and subcontractors, SLAs and incident support obligations, participation in resilience testing and TLPT, formal incident reporting processes, exit and controlled transition plans, and documentation of critical controls, risks, and dependencies.
Just as GDPR did with privacy, DORA is likely to influence global technology governance practices in the financial sector. For Brazilian suppliers, anticipating these requirements can become a competitive advantage in international contracts and relationships with regulated clients.
DORA, NIS2, ISO 27001, COBIT and other references
DORA does not replace frameworks such as ISO/IEC 27001, COBIT, ITIL, NIS2, or local security standards. It overlaps with these practices and establishes specific requirements for the European financial sector. Companies with ISO/IEC 27001 already have a relevant information security management base, but DORA requires an additional layer of operational evidence, especially in resilience testing, incident reporting, third-party management, continuity, and oversight. COBIT 2019 can support the governance of technology risks and assets. ITIL contributes with incident, change, problem, continuity, and service management processes. NIS2 overlaps with DORA in security and resilience, but DORA is the specific regime applicable to the financial entities covered.
How to begin a DORA compliance journey
A practical journey towards DORA compliance should begin with identifying critical functions, relevant assets, ICT suppliers, and associated contracts. Without this foundation, the other pillars become weak. An executive roadmap could follow these steps:
- Scope diagnosis: Identify the entities, services, critical functions, and contracts that are impacted.
- Mapping of assets and dependencies: Review CMDB, asset inventory, applications, integrations, and vendors.
- Gap assessment: Compare current processes with the pillars of DORA.
- Contract review: Adapt clauses regarding ICT, auditing, data, SLAs, subcontracting, and exit.
- Evidence automation: To structure workflows, records, dashboards, and audit trails.
- Tests and simulations: Execute continuity, incident response, and operational resilience exercises.
- Continuous governance: Establish indicators, committees, responsible parties, review cycles, and continuous improvement.
Conclusion
DORA represents a structural shift in how the European financial sector approaches technology, continuity, third parties, and operational security. More than a regulatory obligation, it creates a governance model that connects risk, operations, security, suppliers, and data into a single resilience agenda.
For companies using ServiceNow, the challenge is not only to implement new controls, but to raise the maturity of the platform as a digital governance operating system: reliable CMDB, well-classified assets, traceable incidents, controlled suppliers, evidenced risks, and auditable workflows.
4MATT, as ServiceNow Elite Partner in Brazil With over 80 certified specialists and recognized with the Technology Excellence Partner Award 2024–2025, it operates in the implementation and evolution of capabilities such as ITAM, CMDB, ITSM, SecOps, IRM and third-party management — essential pillars for organizations that need to transform regulatory compliance into measurable operational resilience.
Questions about DORA
What does DORA mean? DORA stands for Digital Operational Resilience Act. It is the European Union regulation that defines digital operational resilience requirements for the financial sector.
When did DORA become mandatory? The regulation entered into force on January 16, 2023, and became applicable on January 17, 2025.
What are the five pillars of DORA? The five pillars are ICT risk management, incident reporting, digital operational resilience testing, third-party ICT risk management, and threat intelligence sharing.
Does DORA apply to Brazilian companies? Brazilian companies may be impacted when providing ICT services to European financial institutions. The impact typically arises from contractual requirements imposed by the regulated client in the European Union.
What is Register of Information in DORA? Register of Information, or RoI, is the structured record of contracts and arrangements with third-party ICT suppliers. It gathers data on entities, functions, contracts, suppliers, services, criticality, location, and dependencies.
How does ServiceNow help with DORA compliance? ServiceNow can support DORA compliance through CMDB, ITAM, ITSM, SecOps, IRM, Operational Resilience, Third-Party Risk Management, Vendor Management Workspace, evidence automation, incident management, and compliance reporting.