DORA is built on five pillars: (1) ICT risk management, (2) ICT-related incident management and reporting, (3) digital operational resilience testing, (4) ICT third-party risk management, and (5) information and intelligence sharing. Together they form one framework — not five separate projects.
DORA can feel sprawling, but it resolves into five connected pillars. Understanding them is the fastest way to see the whole obligation and work out where your firm needs to focus.
Pillar 1 — ICT risk management
The foundation. Financial entities must maintain a documented framework for identifying, protecting against, detecting, responding to and recovering from ICT risks, owned and overseen by the management body. It covers governance, asset and dependency mapping, protection and prevention, detection, response and recovery, and continuous learning.
See DORA ICT risk management framework. (Articles 5–16.)
Pillar 2 — ICT-related incident management and reporting
Firms must detect, manage and classify ICT incidents, and report the major ones to their competent authority within set timeframes. In Ireland, major incidents are reported via the Central Bank of Ireland Portal. Firms may also voluntarily report significant cyber threats.
See DORA incident reporting and classification.
Pillar 3 — Digital operational resilience testing
DORA requires a proportionate, risk-based testing programme. There are two tiers:
Baseline testing (Articles 24–25) — appropriate methods (which may include vulnerability assessments, network assessments, scenario-based and penetration testing) applied at least annually to systems supporting critical or important functions. This applies to most entities.
Threat-led penetration testing / TLPT (Articles 26–27) — an advanced, intelligence-led exercise required only for entities identified by their competent authority.
See DORA resilience testing and TLPT explained.
Pillar 4 — ICT third-party risk management
Firms must manage their technology suppliers actively: maintain a register of information of ICT contractual arrangements (Article 28), include prescribed clauses in contracts supporting critical or important functions (Article 30), and manage concentration and sub-outsourcing risk. Providers designated as critical are supervised directly at EU level.
See DORA third-party risk management.
Pillar 5 — Information and intelligence sharing
The one voluntary pillar. DORA encourages financial entities to share cyber-threat information and intelligence within trusted communities, to raise collective resilience. Participation is optional and subject to safeguards.
How the pillars connect
The pillars are interdependent. Identifying your critical or important functions (part of pillar 1 and the third-party register) determines what you test (pillar 3) and what you must report (pillar 2). Weakness in one pillar undermines the others — which is why DORA is best treated as a single programme.
Want to know which pillars need the most work at your firm? Book a readiness assessment.