On 17 January 2025, Regulation (EU) 2022/2554 — better known as DORA, the Digital Operational Resilience Act — became fully applicable in all Member States.
No national transposition legislation was required as it is a European regulation, and it therefore became directly binding. Yet, months after it came into force, the prevailing view in many organisations remains the same: “DORA? That’s something for the banks.”
A mistake which, as we shall see, can prove costly.
The initial misunderstanding: DORA is not a banking regulation
DORA was established with a specific and ambitious aim: to harmonise the rules on ICT risk management in the financial sector at European level, thereby filling the regulatory gap that had in turn led to a patchwork of inconsistent national regulations.
Before DORA, each Member State had already developed its own standards, which were often incompatible with one another, leaving grey areas and systemic vulnerabilities within the digital financial ecosystem.
La risposta del legislatore europeo non è stata una norma ristretta alle banche, quanto una norma che ridisegna il perimetro del “settore finanziario” in senso molto più ampio di quanto ci si potrebbe aspettare.
The DORA Regulation applies to as many as 21 types of financial entities and covers virtually all EU financial institutions, such as banks, investment firms, insurance companies, pension funds, cryptocurrency providers and crowdfunding service providers.
The fact that there are so many categories is no coincidence, but rather an indication that the scope of application has been designed to cover all sectors related to finance, not just its traditional core.
Who is actually subject to DORA?
Il Regolamento DORA ha per questo un perimetro di applicazione estremamente ampio, che va a coinvolgere oltre 22.000 entità finanziarie in tutta Europa e i loro fornitori critici.
Who else, apart from banks, is included in the scope?
Insurance sector
IVASS is the competent DORA authority for the insurance sector, with supervisory powers over insurance and reinsurance undertakings governed by the Private Insurance Code. This means that every insurance company (non-life, life, reinsurance) is subject to direct supervision and is required to comply with all five pillars of the regulation.
Payment institutions and electronic money
Payment institutions, including those exempt from PSD2, and electronic money institutions are explicitly covered by the scope. Fintech companies operating in digital payments, e-wallets and instant payment platforms are all included.
Fund managers and asset management companies
Consob’s remit covers investment firms (SIMs), asset management companies (SGRs) and other market entities. Alternative fund managers (GEFIAs), SICAVs, SICAFs and central securities depositories also fall within its remit.
Fintech and crypto
The Fintech and crypto sector includes crypto-asset service providers (CASP), issuers of asset-backed tokens, crowdfunding service providers and data reporting service providers.
Pension schemes
Occupational or professional pension schemes with a significant number of members are included, subject to certain exemption thresholds for very small schemes.
ICT suppliers
A special case, but not a straightforward one. Here, the picture becomes more complicated. ICT suppliers do not have any direct regulatory obligations under DORA, unless they are designated as critical suppliers. However, suppliers are affected contractually: it is the responsibility of financial institutions to draw up compliant contracts, and, in the event of a failure to reach agreement, to decide whether to change suppliers.
In practical terms: a cloud provider, a SaaS provider or an IT outsourcer working with banks, insurance companies or asset management firms must be prepared to meet contractual requirements that are far more rigorous than those to which they were previously accustomed. And if they are designated as a critical provider by the European Supervisory Authorities (ESAs), they come directly under their supervisory remit.
The five pillars of operational obligations
DORA is not a particularly broad regulation on cybersecurity. The operational requirements it sets out are very specific and are organised into five areas.
ICT Risk Management
Every organisation must implement a documented framework for the identification, classification and ongoing monitoring of ICT risks. The implementation of structured frameworks and ongoing governance for technological and IT risks is required. It is not enough simply to ‘have an IT department’. Formal governance is required, with roles and responsibilities assigned right up to the level of the governing body.
Segnalazione degli incidenti
In accordance with the DORA Regulation, intermediaries report ICT incidents classified as “serious” to the Bank of Italy via the Infostat platform, using the reporting form entitled “DORA – Reporting of serious ICT incidents”. The deadlines are strict and are defined by regulatory technical standards (RTS). An initial notification must be made within 4 hours of the incident being classified as serious, followed by an interim report and a final report.
Digital operational resilience test
The Regulation requires all financial institutions to carry out basic digital operational resilience tests at least once a year, and threat-led penetration tests (TLPTs) at least once every three years for significant financial institutions. TLPTs (Threat-Led Penetration Tests) are realistic attack simulations conducted by accredited external red teams; they are therefore not merely vulnerability assessments, but attacks driven by real threat intelligence.
ICT Third-Party Risk Management
Financial institutions must also keep a record of information relating to contractual agreements with third-party ICT service providers, and report to the competent authorities, at least once a year, on the number of new contracts they have signed with ICT providers. Every contract with a provider that supports essential or important functions must include specific clauses on exit strategies, audit rights and security performance targets.
Sharing of information
Organisations may participate, on a voluntary basis, in structured mechanisms for sharing information on cyber threats, including indicators of compromise and attack tactics. This is an innovative approach that transforms compliance from an individual obligation into a collective, systemic safeguard.
The Italian framework: Legislative Decree 23/2025 and competent authorities
By Legislative Decree 23/2025, published in the Official Gazette on 11 March 2025, the Council of Ministers approved the decree and, as already mentioned, designated the competent Italian supervisory authorities:
- Bank of Italy for banks and financial intermediaries
- IVASS for the insurance sector
- Consob for investment firms, asset management companies and markets.
It has been stipulated that financial penalties shall also apply to third-party ICT service providers, depending on the category of the customer served. The legislative decree explicitly states that technology providers may be subject to administrative penalties.
And the penalties are certainly not merely symbolic: for banks and financial intermediaries, the most serious breaches can result in fines of up to 10% of annual turnover, whilst for investment firms (SIMs) and asset management companies (SGRs), fines can reach up to €5 million or 10% of turnover, whichever is higher.
What does all this mean in practice?
Outside the banking and insurance sectors, the level of maturity in structured ICT and cyber risk management is still far from the spirit and objectives of the DORA Regulation. This observation accurately reflects the current situation, in which many organisations subject to the Regulation have not yet undertaken an assessment of their scope, nor identified the gaps in relation to the applicable requirements.
This is not merely a compliance issue, but also an operational and reputational one. A serious ICT incident that is not reported within the prescribed timeframe exposes the organisation to direct penalties and puts suppliers and customers at risk of further breaches.
If a supplier is unable to comply with the contractual terms required by DORA, it risks losing clients in the financial sector. An insurance company that does not have a documented ICT risk management framework is already failing to meet the standards required by IVASS.
The principle of proportionality set out in DORA, which tailors obligations to the size and risk profile of the entity, does not exempt any entity within its scope from the fundamental obligations. At most, it may reduce the complexity of implementation, but certainly not the need to implement it.
Where to start
The starting point is not to overhaul all business processes. It is to understand exactly where you are, compared to where you need to be.
A DORA scope assessment enables you to answer three key questions: Is your organisation directly subject to the regulation? If so, what obligations apply to your specific category and size? What gaps exist between the current situation and the required compliance?
Only by starting with a detailed assessment can we develop a sustainable adaptation strategy — not a costly, ad-hoc project, but a structured programme that integrates DORA requirements into existing governance processes.
Rexilience helps organisations interpret DORA requirements, identify gaps and develop a sustainable compliance strategy – even if you’re not a bank.
Please contact us for an initial assessment of your site.