The EU rulebook

DORA for UK firms: the second regime you may be in

DORA, the Digital Operational Resilience Act, is the EU regulation governing how financial entities manage technology risk, in force since 17 January 2025. The UK sits outside it, but UK firms with EU entities in the group, EU clients, or a place in an EU firm's ICT supply chain are caught all the same.

First, the regulation itself

What DORA is, and why it crosses the Channel

DORA, formally Regulation (EU) 2022/2554, gives the EU financial sector a single rulebook for technology risk. It binds banks, insurers, investment firms, payment and e-money institutions, fund managers and crypto-asset providers, and, unusually for financial regulation, it reaches the ICT providers that serve them too.

The UK never onshored it, so there is no UK DORA. What there is instead is a regulation that follows EU financial entities through their group structures, their client bases and their supplier contracts. That is how a firm supervised in London ends up evidencing a Brussels rulebook alongside the FCA and PRA operational resilience rules it already answers to.

The three routes in

How a UK firm gets caught

Scope is decided by structure and contracts, not by where the board sits. Three routes pull UK firms in, and our decision tree tests each one in order, in about two minutes.

You have entities incorporated in the EU

Any EU-incorporated company in your group that meets DORA's definition of a financial entity is in scope in its own right, whatever the parent's postcode. In practice groups rarely run two ICT risk frameworks, so the EU entity's obligations tend to set the standard for everyone.

You serve clients in the EU as a financial entity

Serving EU clients lawfully after Brexit usually means an EU authorisation or branch sits somewhere in the structure, and that authorised entity is a DORA financial entity. The UK parent then finds its systems, suppliers and incident processes examined through the EU entity's compliance.

You sit in an EU financial entity's ICT supply chain

DORA regulates EU firms' technology suppliers through contracts. If you provide software, data, hosting or other ICT services to an EU financial entity, expect mandatory contract terms flowed down to you, a place in their register of information, and questions you must answer with evidence.

The substance

The five DORA pillars, summarised

Everything DORA demands hangs off five pillars. The testing pillar includes threat-led penetration testing, which we cover in depth, alongside the UK's CBEST and STAR-FS schemes, on our TLPT page.

Pillar What it requires
ICT risk management A documented framework owned by the management body: mapping of ICT assets and dependencies, protection and detection capability, response and recovery plans, and board-level accountability for all of it.
ICT incident reporting Incidents classified against harmonised criteria, with major incidents reported to the regulator in stages: an initial notification, an intermediate report and a final report, each on a fixed clock.
Digital operational resilience testing A proportionate testing programme across the estate, and for firms meeting the criteria, threat-led penetration testing (TLPT) on a supervisory cycle, modelled on the TIBER approach.
ICT third-party risk management A register of information covering every ICT contract, mandatory contractual provisions, exit strategies for critical services, concentration risk analysis, and EU-level oversight of the largest providers.
Information sharing Arrangements for exchanging cyber threat intelligence with other financial entities, voluntary but expected to be considered, with safeguards for confidentiality and competition.

Where the regime stands

The 2025 to 2026 state of play

DORA is past its application date and into enforcement. Each phase below has already happened or is under way.

Reviewed July 2026.

  1. 17 January 2025

    DORA applied in full across the EU. Financial entities and their ICT providers have been subject to its requirements since this date.

  2. 13 April 2025

    The subcontracting RTS, Regulation (EU) 2025/532, came into force, setting the rules for subcontracting ICT services that support critical or important functions.

  3. November 2025

    The European Supervisory Authorities designated 19 ICT providers as critical, bringing them under direct EU oversight.

  4. 2026

    The first oversight inspections of designated critical ICT providers are running. Supervisory attention has moved from paperwork to practice.

Two rulebooks, one control set

How DORA maps to the FCA and PRA rules

A dual-scoped firm should never run two resilience programmes. Much of DORA rhymes with what the UK regime already asks: important business services against critical or important functions, scenario testing against resilience testing, outsourcing rules against third-party risk. The working principle is comply once, evidence twice: build one control set and present it to each supervisor in their own vocabulary.

The regimes are converging from both ends. Where the ESAs now oversee designated critical ICT providers, the UK has built its own Critical Third Parties regime as the domestic mirror, putting the largest technology providers under direct supervision at home too. A UK firm that gets its third-party evidence in order serves both conversations at once.

If you want it settled

The fixed fee DORA gap analysis

As part of the Resilience Gap Analysis (£8,990 to £16,780 by scope) we settle the question and measure the distance. You get a written applicability note covering every entity in your group and the route by which DORA reaches it, a control assessment against the five pillars, a review of your ICT contracts against the terms EU counterparties will flow down, and a gap register with a remediation order. The findings arrive twice: practitioner detail for the people doing the work, and a board summary for the people funding it.

If you only need the scope question answered, start with the two minute decision tree. The fee appears, with every other published fee, on our pricing page.

Quick answers

DORA questions, answered

What is DORA?

DORA is the EU's Digital Operational Resilience Act, Regulation (EU) 2022/2554. It sets binding requirements for how financial entities manage technology risk, covering ICT risk management, incident reporting, resilience testing, third-party risk and information sharing. It has applied across the EU since 17 January 2025, and it reaches the ICT providers that serve financial entities as well as the entities themselves.

Does DORA apply to UK firms?

Not as UK law, because the UK never onshored it. But a UK firm is caught in practice through three routes: EU entities in its group, EU clients served through an EU authorisation, or a position in an EU financial entity's ICT supply chain. Our decision tree walks you through each route in order.

Work through the decision tree

What does a DORA gap analysis cover?

Four things. An applicability note confirming, entity by entity, which parts of your group DORA touches and through which route. A control assessment mapping what you already run against the five pillars. A contract review testing your ICT agreements against the flow-down terms EU counterparties will demand. And a gap register with a remediation order, plus a board summary, so the findings become a plan.

See the published fee

Rocket above the Operational Resilience UK call to action

Scope before spend

Find out if DORA is your second rulebook

A free 45 minute scoping call is usually enough to say which route, if any, brings your firm into DORA's reach, and whether the gap analysis or the UK regime should come first.