Key takeaway
DORA (the Digital Operational Resilience Act) is an EU regulation that has applied since 17 January 2025. It sets uniform rules for how financial entities and their technology suppliers manage ICT risk, so the sector can withstand, respond to and recover from disruptions like cyberattacks. In Ireland, the Central Bank of Ireland supervises it. Most Irish financial entities are in scope — though what you actually have to do depends on your size and type.
If you run compliance, security or operational resilience at an Irish financial firm, DORA is now part of your world — and it is more prescriptive than the guidance it replaced. This guide explains what DORA requires, who it applies to, how its testing obligations work (including the advanced testing only some firms must do), what the Central Bank expects, and how to prepare. Where the law matters, we cite it.
On this page
- What is DORA?
- Who does DORA apply to?
- The five pillars of DORA
- Security testing: the two tiers
- Threat-led penetration testing (TLPT)
- Third-party risk and the register
- Incident management and reporting
- Governance and board responsibility
- Penalties and enforcement
- DORA in Ireland: the Central Bank’s role
- Key deadlines
- How to prepare
- FAQs
What is DORA?
DORA is Regulation (EU) 2022/2554, the Digital Operational Resilience Act. It entered into force on 16 January 2023 and has applied across the EU since 17 January 2025, with no further grace period after that application date. Its purpose is to make sure financial entities can keep operating through ICT disruptions — cyberattacks, outages, third-party failures — rather than treating that resilience as an afterthought.
Before DORA, digital-resilience rules were scattered across different directives and national circulars, so requirements varied from country to country. DORA replaces that patchwork with a single, directly applicable rulebook for the whole EU financial sector. It is overseen at EU level by the three European Supervisory Authorities (the ESAs) — the EBA, EIOPA and ESMA — and enforced nationally by each country’s competent authority.
The regulation is deliberately broad. It is not just a cybersecurity rule for IT teams: it reaches into governance, procurement, contracts and board accountability. That breadth is why so many firms underestimated the work involved.
Source note: Regulation (EU) 2022/2554; entry into force 16 January 2023, application from 17 January 2025 (European Commission; ESMA; EIOPA).
Who does DORA apply to?
DORA applies to approximately 20 categories of financial entity. It also has significant consequences for the ICT third-party providers serving those entities — although most providers are affected through contractual and supply-chain requirements rather than direct regulatory supervision; only providers formally designated as critical enter the direct EU oversight framework. Because DORA includes exclusions, simplified regimes and national arrangements, scope should be verified rather than assumed.
The financial entities covered include:
- Credit institutions (banks)
- Payment institutions and electronic money institutions
- Investment firms
- Insurance and reinsurance undertakings, and intermediaries
- Crypto-asset service providers (CASPs)
- Central securities depositories and central counterparties
- Trading venues and trade repositories
- Fund managers (UCITS management companies, AIFMs)
- Credit rating agencies, and more
Irish exception: credit unions
Under Ireland’s implementing regulations (S.I. 20/2025), DORA does not apply to Irish credit unions until 17 January 2028. The Central Bank still expects credit unions to strengthen their digital resilience in the meantime. See DORA for Irish credit unions.
Obligations are proportionate — they scale with your size, risk profile and systemic importance. Micro-enterprises get some lighter-touch treatment, but “small” does not mean “exempt”: the core expectations around ICT risk management and baseline testing still apply widely.
DORA also reaches ICT providers. Providers designated as critical by the ESAs come under a direct EU oversight framework. Everyone else is affected indirectly but substantially, because DORA requires financial entities to put specific clauses into their ICT contracts — and those obligations flow down the supply chain.
In scope?
Not sure whether DORA applies to your firm — or whether you count as an affected ICT provider? Run our short DORA scope checker →
For the full breakdown by entity type, see Who does DORA apply to?
The five pillars of DORA

DORA is built on five pillars. Together they form one framework for operational resilience — not five separate projects.
- ICT risk management. A documented framework for identifying, protecting against, detecting, responding to and recovering from ICT risks — owned and overseen by the management body. (Articles 5–16.)
- ICT-related incident management and reporting. Processes to detect and classify incidents, and to report major ones to your competent authority within set timeframes.
- Digital operational resilience testing. A testing programme covering everything from vulnerability assessments to, for some firms, advanced threat-led penetration testing.
- ICT third-party risk management. Rules for managing your technology suppliers, including a mandatory register of information and prescribed contract clauses. (Articles 28–30.)
- Information and intelligence sharing. Voluntary arrangements to share cyber-threat information with trusted peers.
Each pillar is a topic in its own right. The rest of this guide walks through the ones that most affect Irish firms in practice, starting with the one CyberLabs is asked about most: testing.
For a fuller walkthrough, see The five pillars of DORA explained.
DORA and security testing: the two tiers

This is where a lot of firms get caught out, so it’s worth being precise. DORA creates two tiers of testing, and they are not the same obligation.
Tier 1 — baseline resilience testing. Under Articles 24–25, financial entities other than micro-enterprises must establish a risk-based digital operational resilience testing programme. At least annually, they must ensure that appropriate tests are conducted on all ICT systems and applications supporting critical or important functions. Depending on the entity’s risks and circumstances, those tests may include vulnerability assessments, network security assessments, scenario-based testing, end-to-end testing and penetration testing. Micro-enterprises must also test, but through a proportionate, risk-based approach. Tests may be carried out by independent internal or external parties. This is the tier most Irish financial firms need to focus on.
Tier 2 — threat-led penetration testing, or TLPT. Financial entities identified for TLPT by their competent authority must carry out this advanced testing at least once every three years, unless the authority adjusts the frequency based on the entity’s risk profile and operational circumstances. TLPT is a substantially more demanding, intelligence-led exercise conducted against live production systems. Only a subset of financial entities is identified for it.
Do you need TLPT — or baseline testing?
The honest answer for most firms is baseline testing. TLPT applies only to the subset of financial entities identified by their competent authority — most smaller firms are unlikely to be selected, but identification should not be inferred from size alone. In Ireland, the Central Bank engages directly with financial entities identified for TLPT. It repeats the identification exercise annually and contacts any additional firms identified. If you’re unsure which tier applies to you, that’s exactly the kind of question worth a short conversation. See our DORA testing services →
Learn more: DORA resilience testing: the baseline requirements
Threat-led penetration testing (TLPT)

TLPT is the advanced testing tier under DORA Articles 26–27. It is an intelligence-led red-team exercise conducted against live production systems, guided by real threat intelligence. The blue team — the personnel responsible for security detection and response — is not told in advance, while a small control team knows about the exercise and manages its safety and secrecy. That covertness is the point: TLPT measures genuine resilience, not a rehearsed response.
A few things firms frequently get wrong:
- It is not the same as a penetration test. A standard pentest scopes a defined system, runs for a week or two, and your security team knows about it. TLPT is covert, intelligence-driven, runs on live systems, and ends with a formal attestation from your competent authority. For an entity identified for TLPT, a normal pentest does not satisfy the TLPT obligation. See Pentest vs TLPT.
- Only entities identified by their competent authority must do it. The authority runs an assessment using regulatory categories and risk-related factors; the identified set is broader than just the largest banks, and identification should never be assumed from size alone. See Who needs to do TLPT?
- Independence rules apply. The threat-intelligence provider must always be external and independent. Internal red teams are permitted for up to two of every three cycles, but at least every third test must use an external red team.
- It follows TIBER-EU. DORA’s TLPT rules were designed to align with the ECB’s TIBER-EU framework; a TIBER-EU test (or Ireland’s TIBER-IE) may be used to meet the obligation insofar as it is consistent with DORA and the TLPT technical standard. Ireland’s implementation is TIBER-IE. See TIBER-EU & TIBER-IE explained.
A TLPT is a lengthy exercise. The active red-team testing phase alone must last at least 12 weeks, with preparation, reporting, replay, purple teaming and remediation work on either side. Firms identified for TLPT should therefore begin planning promptly after notification.
Source note: DORA Articles 26–27; TLPT Regulatory Technical Standards (Commission Delegated Regulation (EU) 2025/1190, applicable from 8 July 2025); ECB TIBER-EU framework (updated February 2025).
Full detail: Threat-led penetration testing (TLPT) explained
ICT third-party risk and the register of information
Modern financial services run on third parties — cloud platforms, software vendors, managed services. DORA treats that dependency as a core risk to be managed, not a back-office detail.
Two obligations stand out:
The register of information. Under Article 28(3), every financial entity must maintain a structured register of all its contractual arrangements with ICT third-party providers. It must distinguish arrangements that support critical or important functions (CIFs) from the rest, and be available to your competent authority on request in a specified format. In Ireland, firms submitted registers to the Central Bank in 2025, and this is now an ongoing obligation. See The DORA register of information.
Contractual requirements. Under Article 30, contracts for ICT services supporting critical or important functions must contain specific clauses — covering security, service levels, incident cooperation, audit and access rights, sub-outsourcing, exit strategies and, where relevant, cooperation with testing. Many firms are retrofitting existing contracts with DORA addenda.
Underpinning both is the task of identifying your critical or important functions — a foundational exercise that drives testing scope, third-party mapping and incident classification. It consistently takes longer than firms expect. See Mapping critical or important functions.
Learn more: DORA third-party risk management
Incident management and reporting
DORA requires financial entities to detect, manage and classify ICT-related incidents — and to report the most serious ones to their competent authority. The Central Bank has said it expects firms to have incident identification and reporting in place without delay.
- Classification. Incidents are assessed against criteria in the technical standards — factors such as the clients affected, duration, geographic spread, data losses and economic impact — to decide whether an incident is “major”.
- Reporting major incidents. Once classified as major, an incident must be reported to the competent authority within set timeframes and channels (in Ireland, via the Central Bank of Ireland Portal).
- Significant cyber threats. Entities may also voluntarily report significant cyber threats, supporting sector-wide awareness.
Source note: DORA Articles 17–19 and the related technical standards; Central Bank of Ireland reporting guidance.
See DORA incident reporting and classification.
Governance and board responsibility
DORA makes ICT risk a board-level responsibility, not something the management body can delegate and forget. Under Article 5, the management body must approve, oversee and remain accountable for the ICT risk management framework — and members are expected to keep their knowledge current, including through training.
In practice this means ICT risk has to appear on the board’s agenda, with documented oversight, clear ownership and evidence that leadership understands the firm’s ICT dependencies and risk appetite. For many boards, that is a genuine change in posture.
See DORA governance and board responsibility.
Penalties and enforcement
DORA gives supervisors real teeth. In Ireland, contraventions by regulated financial entities can be dealt with through the Central Bank’s Administrative Sanctions Procedure:
- For a firm, the maximum monetary penalty is generally EUR 10 million or 10% of annual turnover, whichever is greater.
- A responsible individual may face a monetary penalty of up to EUR 1 million, alongside other possible sanctions.
Critical ICT third-party providers are subject to a separate EU oversight framework, not the Irish regime. Where such a provider fails to comply with specified oversight measures, its Lead Overseer may impose a daily periodic penalty payment of up to 1% of its average daily worldwide turnover, for up to six months.
The point of citing these figures is not to alarm — it is to make the case for treating DORA as a genuine priority rather than a paperwork exercise.
Source note: S.I. 20/2025; section 33AQ of the Central Bank Act 1942; DORA Article 35(6)–(8) and Article 50.
See DORA penalties and enforcement.
DORA in Ireland: the Central Bank’s role
For Irish firms, DORA is not an abstract Brussels regulation — it is supervised locally by the Central Bank of Ireland (CBI).
- The CBI is the designated competent authority for DORA in Ireland. It supervises in-scope financial entities and oversees threat-led penetration testing locally.
- S.I. 20/2025 — the European Union (Digital Operational Resilience) (No. 2) Regulations 2025 — designates the relevant Irish competent authorities, provides supervisory and enforcement arrangements, and defers DORA’s application to Irish credit unions until 17 January 2028. (DORA itself is a directly applicable EU regulation, so it is not “transposed” in the usual sense.)
- Institutions for occupational retirement provision (occupational pension schemes) fall under the Pensions Authority rather than the CBI.
- Ireland’s threat-led testing runs under TIBER-IE, the local implementation of the ECB’s TIBER framework.
This local dimension matters when you choose advisers and testing partners: familiarity with the CBI’s expectations and the Irish framework is a practical advantage.
Source note: S.I. 20/2025 (published 11 February 2025); Central Bank of Ireland as competent authority.
See DORA in Ireland: the Central Bank’s role.
Key deadlines

DORA has no single “deadline” — it is a live obligation with a timeline of milestones.
| Milestone | Date |
|---|---|
| DORA adopted | 14 December 2022 |
| Entry into force | 16 January 2023 |
| Application date (compliance expected) | 17 January 2025 |
| Irish implementing & enforcement measures — S.I. 20/2025 | 11 February 2025 |
| TLPT Regulatory Technical Standards applicable | 8 July 2025 |
| First TLPT test (designated entities) | Set by your competent authority via notification — not a fixed date |
Because DORA has applied since 17 January 2025, its baseline obligations are already live. Financial entities identified for TLPT begin the formal process following notification from the relevant TLPT authority. Once subject to the requirement, they must normally repeat TLPT at least every three years, although the authority may adjust the frequency based on risk and operational circumstances.
Deadline watch
Dates and technical standards continue to evolve. Verify current details against the Central Bank of Ireland and official EU sources before relying on them.
See DORA timeline and key deadlines.
How to prepare: practical next steps
You don’t need to boil the ocean. A sensible sequence for most Irish firms:
- Confirm your scope and tier. Are you in scope? Do you face baseline testing only, or are you designated for TLPT? (Run the scope checker.)
- Map your critical or important functions. Everything else — testing scope, third-party register, incident classification — flows from this.
- Build or refresh your register of information. Get your ICT contracts and dependencies documented to the Article 28 standard.
- Run a gap analysis against the five pillars to find where you fall short.
- Establish your testing programme. For most firms, that means regular baseline resilience testing; for designated firms, planning the TLPT cycle early.
- Get board oversight in place so leadership can evidence accountability.
Not sure where you stand?
A readiness assessment maps your obligations and gaps in a few weeks, so you can prioritise with confidence. Book a DORA readiness assessment →
Frequently asked questions
What is DORA?
DORA (the Digital Operational Resilience Act, Regulation (EU) 2022/2554) is an EU regulation that sets uniform rules for how financial entities manage ICT risk. It has applied since 17 January 2025 and aims to ensure the financial sector can withstand, respond to and recover from ICT disruptions such as cyberattacks.
Who does DORA apply to?
DORA applies to around 20 categories of financial entity, including banks, insurers, investment firms, payment and e-money institutions, and crypto-asset service providers. It also affects the ICT providers serving those entities, although most providers are affected through contractual requirements rather than direct supervision. DORA includes exclusions and simplified regimes, so scope should be verified rather than assumed. In Ireland, DORA does not apply to credit unions until 17 January 2028.
Does every DORA entity need penetration testing?
No. DORA requires financial entities to conduct appropriate ICT testing, but it does not require every entity to perform a penetration test in every cycle. Article 25 lists penetration testing as one of several possible methods. Non-micro entities must ensure appropriate testing is conducted at least annually on systems supporting critical or important functions, while micro-enterprises follow a proportionate, risk-based approach. Only entities identified for TLPT must perform the advanced testing under Articles 26–27.
Who has to do TLPT?
Only financial entities identified for TLPT by their competent authority must perform it. Identification is based on the criteria in DORA and the TLPT technical standard, including the entity’s regulatory category, systemic importance, ICT risk profile and potential impact on financial stability. In Ireland, the Central Bank engages directly with identified firms and repeats the identification exercise annually.
What are the penalties for DORA non-compliance?
For financial entities supervised by the Central Bank of Ireland, contraventions may be dealt with through the Administrative Sanctions Procedure. The maximum monetary penalty for a firm is generally EUR 10 million or 10% of annual turnover, whichever is greater, while a responsible individual may face a monetary penalty of up to EUR 1 million. Critical ICT third-party service providers are subject to a separate EU oversight framework, under which a Lead Overseer may impose daily periodic penalty payments of up to 1% of average daily worldwide turnover, for up to six months.
Who regulates DORA in Ireland?
The Central Bank of Ireland is the designated competent authority for DORA in Ireland. It supervises in-scope financial entities and oversees threat-led penetration testing. Occupational pension schemes fall under the Pensions Authority instead.
Was there a grace period for DORA?
DORA entered into force in January 2023 and became applicable on 17 January 2025. There was no additional grace period after that application date, though some Level-2 technical standards were finalised later.
This guide is general information about the Digital Operational Resilience Act, not legal advice. For advice on how DORA applies to your specific organisation, consult a qualified legal or compliance professional. All regulatory facts were verified against primary sources (EUR-Lex, the European Supervisory Authorities, and the Central Bank of Ireland) at the time of writing; because DORA continues to evolve, check current sources before relying on any date or threshold.
Next step
Want to know exactly where your firm stands on DORA? Book a readiness assessment or run the scope checker to get started.
