77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
DORA obligation: What financial companies have to prove since January 17, 2025
IT Security & NIS-2

DORA obligation: What financial companies have to prove since January 17, 2025

29 August 202613 min readBy Lena Vogt
CIVAC

Since January 17, 2025, Regulation (EU) 2022/2554 (DORA) requires financial companies to have documented ICT risk management, incident reports and third-party registers. We show which obligations apply specifically, how they connect to ISO 27001 and where the most common gaps lie.

Since January 17, 2025, Regulation (EU) 2022/2554, or DORA for short, has been directly applicable in the European Union. It obliges around 22,000 financial companies and critical third-party ICT service providers to demonstrably organise their digital operational resilience. The duty includes five pillars: ICT risk management, incident reporting, resilience testing, third-party control and information exchange in accordance with Articles 5 to 49 DORA.

This article classifies the DORA duty from the operational perspective of an information security officer. It shows which documents BaFin and the ESAs expect, how DORA can be integrated with an ISO/IEC 27001:2022 ISMS and where the two working day response time of the CIVAC platform makes the difference to the classic law firm. Compliance platform and officer-as-a-service in one tool.

Key Takeaways

  • DORA has been in effect immediately since January 17, 2025 and requires a written ICT risk framework that is approved by the governing body and reviewed at least annually.
  • According to Art. 19 DORA, serious ICT incidents must be reported to the responsible authority in initial, interim and final reports, with deadlines from the date of knowledge.
  • A complete third-party information register in accordance with Article 28 Para. 3 DORA must be submitted to BaFin annually and updated for each new ICT contract.

Who is affected by the DORA obligation?

The scope of application under Article 2 DORA is broad. It covers 21 categories of financial companies, including credit institutions, investment firms, payment and electronic money institutions, insurers, reinsurers, insurance intermediaries above certain thresholds, alternative investment fund managers, UCITS management companies, crypto service providers according to MiCAR as well as central counterparties and trading venues.

What is new is the direct integration of third-party ICT service providers. Cloud providers, data centres and SaaS providers can be classified as critical according to Art. 31 DORA and are then subject to direct supervision by the ESAs. This shifts the responsibility of the outsourcing institute: the selection, contract design and monitoring of the provider itself becomes the subject of review.

Micro-enterprises with fewer than ten employees and a balance sheet total of less than 2 million euros benefit from relief in accordance with Art. 16 DORA. You still need to have simplified ICT risk management in place. BaFin has made it clear in circular 12/2024 (WA) that proportionality is not an exit, but rather a scaling of the requirements.

For operational implementation, it is recommended to appoint an information security officer who maintains the ICT risk framework and ensures the reporting line to the management body. CIVAC supplies the appointment certificate, specifications and audit trail.

If you want to check whether it is affected, you start with a mapping table: business activity, licence, threshold values, group interrelationships. The CIVAC audit templates cover this step in two working days.

The effort is worth it: If you make it clear early on that DORA applies, you can bundle the structure with ISO 27001:2022, the German NIS 2 Implementation Act and the BAIT/VAIT and avoid duplicate work.

The five mandatory pillars at a glance

Pillar one is ICT risk management in accordance with Articles 5 to 15 DORA. What is required is a digital resilience strategy, a documented risk framework, clear roles, annual board approval and a continuous improvement program. Responsibility remains with the board and cannot be delegated.

Pillar two is the classification and reporting of serious ICT incidents in accordance with Articles 17 to 23 DORA. Delegated Regulation (EU) 2024/1772 defines seven classification criteria, including customer impact, data loss, reputation and duration of impairment. The deadline expires as soon as we become aware of it.

Pillar three is the test program according to Articles 24 to 27 DORA. Annual baseline tests, three-year Threat-Led Penetration Tests (TLPT) for significant institutions, documented findings and tracked measures are mandatory. The TLPT follow the TIBER-EU framework.

Pillar four is the control of ICT third parties in accordance with Articles 28 to 44 DORA. It includes strategy, risk assessment before conclusion of the contract, minimum contractual content, exit strategies and the information register to be reported annually to BaFin.

Pillar five, the exchange of information in accordance with Article 45 DORA, is voluntary. It allows the exchange of cyber threat information between financial companies while maintaining data protection.

The integration with the ISMS according to ISO/IEC 27001:2022 reduces duplication. 93 controls cover large parts of the DORA requirements, the gaps lie primarily in the reporting chain, third-party registers and resilience tests.

ICT risk management: What needs to be in the framework

The risk framework according to Art. 6 DORA is more than a guideline. It is a living document that describes the digital resilience strategy, risk classes, protection objectives, responsibilities and assessment methodology. It is decided by the management body, reviewed at least annually and adjusted after each serious incident.

In terms of content, Art. 8 DORA requires complete identification of all ICT assets, business processes, dependencies and data flows. In practical terms, this means an asset register with owners, protection requirements and links to business functions. The CIVAC workspace provides a template with an import function for CMDB data.

The protective measures from Art. 9 DORA follow the state of the art. Access control, encryption, network separation, patch management and secure configuration are required. In the RTS, the ESAs refer to BSI-Grundschutz and ISO 27001:2022 Annex A.

Detection, response and recovery from Articles 10 to 12 DORA require a SIEM, a Computer Security Incident Response Team (CSIRT) and documented restart plans. The restart times must be defined for each critical function and tested annually.

Learning effects from incidents in accordance with Art. 13 DORA must be recorded. Post-incident reviews with measures, responsible persons and deadlines must be submitted to the management body. Audit-proof, documented, Art. 13-proof.

Training and awareness according to Art. 13 Para. 6 DORA affects all employees, including management bodies. At least annually, documented, auditable.

Incident report: deadlines, content, recipients

The DORA reporting requirement is demanding. According to Art. 19 DORA and Delegated Regulation (EU) 2024/1772, serious ICT incidents must be reported in three stages: initial report, interim report and final report.

The initial report is made immediately, at the latest within four hours of being classified as serious and a maximum of 24 hours after becoming aware of it. It contains a brief description, the classification, the affected functions and an initial outline of the damage.

The interim report follows within 72 hours of the initial report. It updates the status, describes actions taken and expected recovery. If there are significant status changes, it must be repeated.

The final report must be submitted within one month of completion of the cause analysis. It includes root cause, financial damage, lessons learned and action plan. The deadline begins when we become aware of it, not when we perceive it in day-to-day business.

The recipient in Germany is BaFin as the responsible authority. At the same time, reporting obligations may arise in accordance with Art. 33 GDPR to the data protection supervisory authority and in accordance with NIS-2 to the BSI. A consolidated reporting matrix prevents double reports and contradictions.

CIVAC operates a 24/72 reporting path that bundles DORA, NIS-2 and GDPR in one workflow. The auditor calls, the evidence is ready. Licence the workspace for your internal representatives or have our representatives order it.

Third Party Control and Information Registry

The third-party obligations under Articles 28 to 30 DORA are the area with the highest short-term effort. A strategy for ICT third-party risks approved by the governing body is required. It defines concentration risks, critical functions and diversification requirements.

Due diligence must be carried out before the contract is concluded. It includes assessing the provider's resilience, compliance, security organisation and subcontractors. When outsourcing critical functions, additional requirements must be met.

The contracts must contain the minimum content from Art. 30 DORA: description of the function, location of data processing, security requirements, reporting obligations, audit rights, exit clauses and termination options in the event of breach of contract.

The information register according to Art. 28 Para. 3 DORA must be transmitted to BaFin annually, for the first time on April 30, 2025. Implementing Regulation (EU) 2024/2956 standardises the format. 15 tables with master data, contract details, subcontractors and classifications are required.

Exit strategies from Art. 28 Para. 8 DORA are mandatory for critical outsourcing. They describe the orderly transition to an alternative provider or the return to your own company, including test scenarios.

CIVAC's supplier auditors carry out due diligence, contract review and annual reviews with the 490 ready-to-use audit templates.

Resilience testing and TLPT

The test program according to Art. 24 DORA requires a risk-based, annually updated concept. It covers vulnerability assessments, open source scans, network security testing, gap analysis, source code reviews, penetration testing and restart testing.

The basic testing is mandatory for all financial companies within the scope. They are carried out at least annually, by independent testers, with documented findings and an action plan that must be presented to the management body.

Threat-Led Penetration Tests (TLPT) according to Articles 26 to 27 DORA apply to significant institutions. The responsible authority names these based on size, risk profile and market importance. The TLPT follow the TIBER-EU framework, usually last six to nine months and cost between 150,000 and 500,000 euros, depending on complexity.

The test includes threat intelligence, red team exercise and closure phase. Subjects are critical or important functions in production systems. The ESAs have made it clear in the RTS that swaps will be tested if they are essential to the function.

The results are strictly confidential. They will be submitted to the relevant authority and, if necessary, to the TLPT cyber team. Publication is not permitted.

For operational control, we recommend a dedicated test manager who plans the program annually, tracks the findings and ensures escalations to the ISB. The appointment certificate, signed, filed, verifiable.

Interlocking with ISO 27001 and NIS-2

DORA cannot be read in isolation. Anyone who runs an ISMS in accordance with ISO/IEC 27001:2022 in parallel will already cover a large part of the DORA requirements with the 93 controls from Appendix A. The gaps lie primarily in the reporting chain, in the third-party register and in the TLPT obligation.

A common control register avoids duplication of work. Each measure is documented once and linked to DORA articles, ISO control and, if necessary, NIS 2 requirements. One piece of evidence is sufficient for several audits.

The German NIS 2 Implementation Act, which will come into force in the course of 2026 after several postponements, applies to essential and important facilities. According to Article 1 Paragraph 2 of DORA, financial companies are generally exempt from NIS-2 to the extent that DORA applies. However, subsidiaries outside the financial sector are falling behind.

The BAIT, VAIT, KAIT and ZAIT remain relevant as supplementary administrative practices as long as they are not displaced by DORA. BaFin has announced that it will revise the announcements in 2025 and consolidate them with DORA.

For compliance platforms and officer-as-a-service, this means: An integrated view of all regulations saves effort. CIVAC maps DORA, ISO 27001, NIS-2 and GDPR in a control model.

Anyone who follows the NIS-2 implementation should use the DORA structures as a template. The reporting requirements are similar, the risk frameworks are compatible.

Fines, supervisory measures and personal liability

DORA does not contain its own catalogue of fines at EU level. The member states regulate the sanctions nationally. In Germany, the Financial Market Digitization Act (FinmadiG) of December 23, 2024 sets the framework.

Fines of up to 5 million euros are envisaged for intentional or negligent violations by legal entities. For natural persons, especially members of the management body, fines of up to 500,000 euros are possible. In the case of particularly serious violations, BaFin can assess up to 10 percent of group sales according to Section 6c KWG.

Supervisory measures range from orders on adjusting the risk framework to prohibiting critical outsourcing. In the event of repeated violations, the licence according to the KWG, VAG or WpIG can be withdrawn.

The personal liability of the board of directors results from Section 91 Paragraph 2 AktG, Section 43 GmbHG and the respective special legislation. Anyone who has not adopted or reviewed the DORA risk framework risks internal liability towards the company.

Supervisory boards have a monitoring obligation according to Section 111 AktG. DORA reporting to the supervisory board must be documented and recorded at least annually.

The appointment document for the information security officer documents the delegation, but does not replace the responsibility of the board of directors. The appointment certificate, signed, filed, verifiable.

The CIVAC path to DORA compliance

CIVAC is a compliance platform and officer-as-a-service in one. We map DORA, ISO/IEC 27001:2022 and the NIS-2 Implementation Act in a control register and provide the appointment certificates, reporting lines and audit templates in two working days.

Licence the workspace for your internal representatives or have our representatives order them. The workspace includes 490 ready-to-use audit templates, a reporting module for the 24/72 path, a third-party register in EU format and an audit-proof archive with EU data residency.

In the Officer-as-a-Service model, an appointed information security officer takes over the operational maintenance of the risk framework, the preparation of reports, reporting to the management body and the interface to BaFin. You retain ultimate responsibility, we deliver the work.

Getting started begins with a gap assessment. We compare your status quo with the 41 DORA requirements, identify gaps in the risk framework, reporting chain, tests and third parties and create an action plan with deadlines.

We then set up the workspace, import existing documents, define the reporting line and hand it over to your representatives or ours. The auditor calls, the evidence is ready.

Turn reading into a mandate. Write to info@civac.de or use the contact form on civac.de. We will respond within two working days with a specific proposal.

FAQ

Since when does the DORA requirement apply in Germany?

Regulation (EU) 2022/2554 has been directly applicable since January 17, 2025. Implementation into national law was not necessary. At the same time, the German legislature passed the Financial Market Digitization Act, which adapts the KWG, VAG and WpIG.

Which companies are affected by DORA?

Art. 2 DORA lists 21 categories, including banks, insurers, investment firms, payment and e-money institutions, KVGen, crypto service providers according to MiCAR and trading venues. There are also third-party ICT service providers who are classified as critical.

What is a major ICT incident under DORA?

Delegated Regulation (EU) 2024/1772 defines seven criteria: customer impact, reputational impact, duration, geographical distribution, data loss, economic impact and criticality of affected services. An incident is serious when defined thresholds are exceeded.

What deadlines apply for DORA incident reporting?

First report within four hours of classification, maximum 24 hours of knowledge. Interim report within 72 hours of initial report. Final report within one month after root cause analysis. The recipient in Germany is BaFin.

How does DORA relate to ISO/IEC 27001:2022?

An ISMS according to ISO 27001:2022 covers large parts of the DORA requirements with the 93 controls. The gaps lie primarily in the reporting chain, in the third-party register and in the TLPT obligation. An integrated control view avoids double documentation.

What fines are there for DORA violations?

The German FinmadiG provides for fines of up to 5 million euros for legal entities and up to 500,000 euros for natural persons. In the case of particularly serious violations, BaFin can assess up to 10 percent of group sales according to Section 6c KWG.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles