DORA is dominating headlines and if you’re in the financial services space in the EU, it’s probably also dominating all boardroom discussions. The Digital Operational Resilience Act (DORA) came into force on 16th January, 2023 and has been fully applicable from 17th January, 2025.
DORA is a regulatory framework and one of the key components of the European Union Digital Finance Package. The vision behind the Package is to catalyse the digital transformation of the financial services space in the EU and also harmonise the regulatory requirements at all EU member states. The goal is to offer clarity to financial institutions on how they can enter into a new era of digitisation while staying secure from the threats that loom large across all digital frontiers.
Important 2026 Update: Since DORA became fully applicable in January 2025, organisations are now implementing the accompanying Regulatory Technical Standards (RTS) and Implementing Technical Standards (ITS). This guide has been updated to reflect current reporting expectations, documentation requirements and operational practices. Organisations should ensure their procedures reflect these standards rather than relying solely on the Regulation text.
The Act comes in the wake of major cybersecurity incidents with financial organisations the world over. The impact of a cyber-attack on a financial player, sadly, is never limited to the business alone and directly impacts the end-user or the citizen. To mitigate these risks and others arising from Information and Communication Technologies (ICT), the crux of the DORA requirements pertaining to operational resilience can be broken into two parts:
But how do you achieve these goals laid out by DORA and what does Digital Operational Resilience really mean? As experts in Cyber Incident Resilience Testing and creators of the NCSC Assured Training in Cyber Incident Planning & Response, we feel like we’re well-placed to explain both.
In this article, though, we are going to focus on the Act’s requirements pertaining to Business Continuity and Cyber Incident Response Plans. In the next article in this educational series on DORA, we take up Digital Operational Resilience Testing.
Chapter II of DORA covers ICT Risk Management in complete detail and emphasises on all aspects of Cyber Incident Response and Recovery, while Chapter IV is focussed on Digital Operational Resilience Testing. Article 11 (Chapter II) talks in detail about Cyber Incident Response Recovery. The gist is encapsulated in this sentence: “Financial entities shall implement the ICT business continuity policy through dedicated, appropriate and documented arrangements, plans, procedures and mechanisms.” Chapter IV is devoted
In essence, DORA formalises what we have been recommending to our clients for as long as we can remember - plan, plan and plan! If you fail to plan, plan to fail - at least when you’re embroiled in battle with an advanced criminal hacker.
As per DORA, a solid business continuity plan and cyber security incident response plan are essential to ensure recovery from a cyber incident as seamlessly as possible. The financial entity must be able to respond to and resolve any cybersecurity incident with the end-goal of mitigating damage and minimising disruption to services.
These plans should also clearly define communication channels and crisis communications management strategies. Communication plans must include all internal and external stakeholders in compliance with Article 14 of the Act. Article 19 (Chapter II) lays out the guidance on updating ‘competent authorities’ when a major ICT-related incident and/or significant cyber threat does emerge.
Chapter II on ICT Risk Management of the final text of DORA is detailed and exhaustive. It talks of every aspect of Cyber Incident Response - Identification (Article 8), Prevention (Article 9), Detection (Article 10) and Response and Recovery (Article 11), Lessons Learned (Article 13), Communication (Article 14) and so forth.
It can be daunting and overwhelming to grasp every detail of every Article. So much so, that we’ve actually met potential clients who haven’t even started readying themselves for DORA a year into its official announcement.
Lucky for you, though, that you’ve stumbled upon this article and we may be able to help in at least unravelling DORA requirements at the onset. Our objective in the next section is to simplify for you how you can get started on building an effective Business Continuity Plan and inch a step closer to becoming DORA compliant before 2025.
One of the biggest challenges organisations face during a cyber incident is balancing technical response with regulatory reporting. DORA establishes a structured reporting process for major ICT-related incidents, ensuring competent authorities receive timely information as the situation develops.
Rather than producing a single report, organisations should be prepared for a staged reporting process.
|
Report |
Timing |
Purpose |
|
Initial Notification |
As early as possible after classifying an incident as major, and no later than 24 hours after detection |
Alerts the competent authority that a major ICT incident has occurred. |
|
Intermediate Report |
Within 72 hours of submitting the initial notification |
Provides updated information on the incident, its impact, containment measures and any known root cause. |
|
Final Report |
Within one month of submitting the intermediate report |
Confirms the full impact, root cause analysis, remediation activities and lessons learned. |
Meeting these reporting deadlines requires far more than technical capability. Organisations should already have documented reporting procedures, decision-making authorities, contact lists and evidence collection processes in place before an incident occurs.
Waiting until a cyber incident happens to determine who approves reports, who contacts regulators or what information must be collected is likely to create unnecessary delays during the most critical stages of an incident.
Many of our clients whose teams have attended the NCSC Assured Training in Cyber Incident Planning and Response shared with us how significantly the course helped their staff to understand the real impact a cyber incident could have on their organisation. High-quality cybersecurity training in Incident Response really opens up the minds of employees about how much still needs to be done to bolster their defences against cyber crime.
The course also teaches you how to implement a well-defined and managed approach to dealing with a cyber-attack or data breach. Your team can learn how to put in place an effective Cyber Incident Response framework which can ultimately help you fulfil the requirements of the Digital Operational Resilience Act.
#2. Create or Review Your Cyber Incident Response Plan: An effective Business Continuity Plan and a Cyber Incident Response Plan are prerequisites of DORA. You need to make sure that you have a robust and fit-for-purpose cyber incident response plan as a financial entity.
The plan should actually help in case of an Incident to control the infection and mitigate any damage that it can cause. It must reflect the latest techniques and core principles of effective cyber incident response. It must also be in sync with the current cybersecurity threat landscape.
If you don’t have a plan, or are uncertain about the effectiveness of your existing plan, our cybersecurity consultants can help. Our Virtual Cyber Assistant Service is unlike anything in the market. You can hire deeply experienced cybersecurity experts for exactly the number of hours you need them.
You can choose to have them create a new Plan for you or review your existing plan and share their opinion on whether it is aligned with DORA or not. They can also help you refresh your plan to meet the requirements of the Act. But the services aren’t limited to just your Incident Response Plan.
Our expert cyber consultants can help you achieve significant improvements in your overall cybersecurity maturity. Ensuring Business Continuity within the context of cybersecurity is amongst the chief reasons why our clients enlist the services of our cybersecurity consultants. And this in turn brings you closer to achieving the goals laid out in the Digital Operational Resilience Act.
#3. Use our FREE Incident Response Plan Template: We understand that it may not be possible or feasible to immediately hire an external expert to advise you on your Cyber Incident Response Plan. This is why we’ve created an invaluable FREE resource - our Cyber Incident Response Plan template.
Created by the world leader in cybersecurity incident response and the creator of the NCSC Assured Training in Incident Response Planning, this free template is an extremely crisp, insightful and easily customisable resource. You can easily tailor it to your organisational structure, technology infrastructure and business context.
While it won’t replace the expertise of an external cybersecurity consultant, it’s a great starting point. It will show you what key elements of incident response to cover and what steps to take immediately in the aftermath of a cybersecurity incident. Use it in combination with our free Cyber Incident Response Checklist and you’ll feel more confident about becoming DORA compliant.
#4. Build Effective Playbooks in Conjunction with Plans: Though the DORA text doesn’t specifically mention Cyber Incident Response Playbooks, we recommend creating and/or refreshing yours in conjunction with your IR plans. Together, they can help you achieve the levels of digital operational resilience that DORA mandates.
Incident Response Playbooks contain immediate remediation steps based on pre-defined triggers. They also contain specific triggers for communication channels in case of a cyber incident - a stringent DORA requirement.
#5. Test your Response & Recovery Cybersecurity plans: Digital Operational Resilience Testing is a major part of DORA. And it is highly recommended to regularly test your cyber resilience through cyber crisis tabletop exercises. We cover this aspect of DORA requirements in greater detail in our next blog.
However, any conversation about cyber resilience and cyber incident response plans is incomplete without a mention of cybersecurity drills so we had to include this in the list of action items. In the context of IR plans, it has to be underlined that testing the plans against simulated cyber attack scenarios is critical.
Without cyber simulation drills, it’s impossible to know whether the plans are any good or not. It’s also the best way to familiarise your staff and key incident responders with what’s in the plans, processes and cybersecurity procedures.
An effective incident response capability is built long before an incident occurs. DORA expects organisations to maintain documented procedures that enable a rapid, coordinated and well-governed response when major ICT incidents arise. Refer to our DORA Incident Response Document Library for a full list of documents, policies and procedures you must have in order to be fully DORA compliant.
Typical documentation includes:
Many organisations discover during tabletop exercises that these documents either do not exist, are incomplete or have never been tested together. Having a complete and integrated document set significantly improves both operational response and regulatory readiness.
You should also download our DORA Incident Response Master Document Register. It is the operational control centre for your entire DORA incident response documentation estate. Instead of managing dozens of policies, procedures, playbooks, forms and registers individually, you manage everything through one structured register.
Since DORA became fully applicable, organisations have increasingly shifted their focus from creating policies to demonstrating that those policies work in practice. The same weaknesses continue to appear across many incident response programmes.
Common issues include:
Organisations often spend valuable time debating whether an incident is "major" rather than following a documented classification process.
If legal, compliance, cyber security and senior management have not agreed reporting responsibilities in advance, regulatory notifications can quickly become delayed.
Preparing reports from scratch during an active cyber incident increases pressure and creates unnecessary risk.
Incident response plans frequently exist without supporting playbooks, communication procedures, evidence logs or decision records.
Cyber incidents rapidly become business issues. Senior leadership should understand their responsibilities before an incident occurs, not during one.
Documentation alone is rarely sufficient. Regular tabletop exercises help validate whether procedures, reporting workflows and governance arrangements actually function under pressure.
Achieving DORA compliance is about much more than having an Incident Response Plan stored on a shared drive. Regulators increasingly expect organisations to demonstrate that their incident response arrangements are operational, documented and regularly exercised.
In practice, a mature DORA incident response capability typically includes:
Organisations that establish these capabilities before an incident occurs are generally able to respond more effectively, meet regulatory reporting obligations with greater confidence and demonstrate stronger operational resilience during supervisory reviews.
Meeting DORA's incident response requirements requires more than understanding the regulation. Organisations need documented processes, clearly defined governance, tested response procedures and evidence that these arrangements work in practice.
CM-Alliance has worked with organisations across regulated sectors to strengthen cyber incident response capabilities through a combination of practical documentation, independent assurance and realistic exercising.
Our support includes:
Rather than producing documentation simply to satisfy compliance requirements, our focus is on helping organisations build incident response capabilities that are practical, repeatable and capable of standing up to both real cyber incidents and regulatory scrutiny.
Whether an organisation is preparing for DORA implementation, reviewing existing incident response arrangements or strengthening operational resilience, combining robust documentation with regular exercising and independent assurance provides a far stronger foundation than relying on policies alone.
Cyber incident response planning is critical to the Digital Operational Resilience Act (DORA). It ensures that financial entities and service providers can effectively prepare for, respond to, and recover from cyber incidents.
Incident Response planning is essential for minimising the impact of cyber incidents on the financial markets, protecting consumers, and preserving the stability and resilience of the financial system.
By mandating robust incident response mechanisms and a robust Incident Response Plan, DORA aims to enhance the overall digital operational resilience of the financial sector. While complying with DORA is mandatory for financial entities in the EU, it is important to remember that by taking the actions mentioned above, you can also ensure that your business can withstand, respond to, and recover from adverse cyber events without significant disruption to financial services or loss of sensitive data.
1. What are DORA incident response requirements?
The Digital Operational Resilience Act (DORA) requires financial entities to establish and maintain documented incident response procedures for detecting, managing, classifying, responding to and recovering from ICT-related incidents. Organisations must be able to identify major ICT incidents, notify competent authorities within prescribed timelines, maintain appropriate records and continuously improve their incident response capability through testing and lessons learned.
2. What qualifies as a major ICT incident under DORA?
A major ICT incident is an ICT-related event that significantly disrupts or has the potential to disrupt a financial entity's operations, services or customers. DORA requires organisations to assess incidents against criteria such as the number of clients affected, service downtime, geographical spread, data loss, financial impact and reputational consequences. Incidents meeting the regulatory thresholds must be reported to the relevant competent authority.
3. What are the DORA incident reporting timelines?
DORA requires major ICT incidents to be reported through a staged reporting process. Organisations must submit an initial notification as soon as possible after classifying an incident as major, and no later than 24 hours after detection. An intermediate report follows within 72 hours of the initial notification, with a final report submitted within one month of the intermediate report. These reports provide progressively more detailed information as the incident investigation develops.
4. Who must report major ICT incidents under DORA?
Financial entities that fall within the scope of DORA are responsible for reporting major ICT incidents to their competent authority. This includes banks, investment firms, insurance and reinsurance companies, payment institutions, electronic money institutions, crypto-asset service providers and many other regulated financial organisations operating within the European Union.
5. What documentation is required for DORA incident response?
While DORA does not prescribe a fixed list of documents, organisations are expected to maintain comprehensive incident response documentation. This typically includes an Incident Response Plan, incident classification procedures, response playbooks, crisis communication plans, regulatory reporting procedures, escalation matrices, contact lists, evidence logs, incident registers, decision records and lessons learned documentation. Together, these documents help demonstrate that incident response arrangements are structured, repeatable and effective.
6. Does DORA require organisations to test their incident response plans?
Yes. DORA requires financial entities to regularly test their digital operational resilience, including their incident response capabilities. Organisations should conduct exercises such as cyber tabletop simulations, technical response testing and scenario-based exercises to validate that their procedures, governance arrangements and communication processes work effectively during real ICT incidents. Testing also helps identify gaps before they become regulatory or operational issues.
7. What is the difference between DORA incident response and NIS2 incident reporting?
Although both frameworks require organisations to manage and report significant cyber incidents, they apply to different sectors and have different objectives. DORA focuses specifically on the operational resilience of financial entities and establishes detailed requirements for ICT risk management, incident reporting, resilience testing and third-party ICT risk. NIS2 applies across a broader range of essential and important entities, with an emphasis on improving cybersecurity and resilience across critical sectors. Organisations that fall within the scope of both regulations should ensure their incident response procedures satisfy the requirements of each framework.
8. How can organisations prepare for DORA incident reporting before an incident occurs?