For years, operational resilience in finance was a matter of good practice: sensible firms invested in it, others hoped they would never be tested. The European Union’s Digital Operational Resilience Act (DORA), Regulation (EU) 2022/2554, ends that discretion. Since it began to apply on 17 January 2025, the ability of a financial firm to withstand, respond to and recover from an information and communication technology (ICT) disruption is a legal obligation, supervised and enforceable (European Union, 2022).
Fintechs are not a footnote to this. Payment institutions, e-money institutions, crypto-asset service providers and many others sit directly within DORA’s scope, often without the compliance machinery a large bank takes for granted. For a fast-moving fintech built on cloud services and third-party APIs, DORA is not a box to tick once; it is a way of running the business that the regulator now expects to see evidence of.
What DORA is, and who it covers
DORA is a single, harmonised EU regulation for the digital operational resilience of the financial sector. Its premise is that a firm can be perfectly solvent and still fail its customers, and its market, if its technology stops working, so it treats ICT risk as a first-class prudential risk rather than an IT housekeeping matter.
Crucially, it applies proportionately. The full weight of the obligations falls on larger, more complex entities, while smaller firms face a lighter version calibrated to their size and risk. That proportionality is a relief for a small fintech, but not an exemption: the core expectations still apply, and “we are small” is not a defence for having no resilience programme at all.
The five pillars
DORA is built on five connected pillars, and a fintech’s programme has to address each.
1. ICT risk management
A governance framework for identifying, protecting against, detecting, responding to and recovering from ICT risk. It expects mapped critical functions, a risk assessment behind the controls, and, notably, that the firm’s management body owns it.
Firms must detect, classify and manage ICT incidents, and report major ones to their competent authority within defined timeframes. Ad hoc, undocumented incident handling does not meet the standard; a real process, with classification criteria and reporting paths, does.
3. Digital operational resilience testing
Resilience must be tested, not assumed. This ranges from vulnerability assessments and scenario tests for all firms, up to threat-led penetration testing (TLPT), an advanced, intelligence-driven exercise, for the most significant entities. The principle is the one that recurs across every resilience framework: an untested plan is a hope, not a control.
4. ICT third-party risk management
Firms must manage the risk from their ICT providers, cloud platforms, payment processors, SaaS vendors, through a maintained register of arrangements, prescribed contractual terms, and credible exit strategies. DORA also introduces direct EU oversight of critical ICT third-party providers, the largest cloud and technology firms the whole sector depends on.
Firms are encouraged to share cyber threat intelligence with one another, recognising that resilience is partly a collective effort.
The third-party trap, and why it matters most for fintechs
For a fintech, the third pillar is usually the sharpest, because a fintech is often more integrator than infrastructure owner. The product runs on a cloud provider, payments flow through a processor, identity is verified by a vendor, and messages are sent by another. Each of those is an ICT third party, and DORA holds the fintech responsible for the resilience risk they introduce.
This is the same principle that runs through every serious framework: you can outsource the work, but not the accountability. Moving core functions to a cloud provider does not move the obligation to ensure they keep working, to have a way out if the provider fails, and to have assessed the concentration risk of depending on one platform. DORA turns that principle into concrete requirements, a register you must keep, contracts you must have, exit plans you must be able to execute.
DORA moves operational resilience from a good idea to a legal duty, and puts the accountability squarely on the management body, not the IT team.
For fintechs the practical implications are pointed: know exactly which providers underpin your critical functions, ensure the contracts give you the rights DORA requires (audit, access, termination, data return), and have an exit strategy that is more than a paragraph, because a provider failure with no way out is precisely the scenario DORA exists to prevent.
Governance: the board cannot delegate this away
A recurring theme in DORA is that ICT risk is a governance responsibility. The management body is explicitly accountable for the ICT risk management framework, must approve key elements, and is expected to maintain sufficient knowledge to challenge them. Resilience is not something the board signs off to the IT department and forgets; it is a duty the board itself carries, in the same way it carries financial risk.
Getting ready, and how to assess it
For a fintech approaching DORA, or an auditor assessing readiness, the work is concrete:
- Map critical functions to the ICT that supports them. You cannot protect or test what you have not identified, the first control in resilience as in compliance.
- Build the third-party register and fix the contracts. Identify every ICT provider behind a critical function, and confirm the contractual rights and exit strategies DORA requires.
- Make incident handling real and reportable. Classification criteria, response process, and the reporting path to your competent authority.
- Test, at the right level. Vulnerability assessments and scenarios as a baseline, TLPT where you fall into scope.
- Put the framework in front of the board, and record it. The accountability is theirs, and DORA expects the evidence.
Conclusion
DORA reframes a fintech’s relationship with its own technology. Resilience is no longer a maturity goal to reach eventually; it is a regulated obligation with a register to keep, incidents to report, tests to run, third parties to control, and a board that must own all of it. The through-line is familiar to anyone who has audited a modern financial firm: identify what is critical, control the providers you depend on without pretending you have handed them the accountability, and prove your plans work rather than assuming they do. For a fintech built on other people’s clouds and APIs, DORA is simply the law catching up with how much rests on making that stack resilient.
References
- European Union. (2022). Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA). Official Journal of the European Union.
- European Supervisory Authorities. (2024). Joint Regulatory Technical Standards under DORA. EBA, EIOPA and ESMA.
- ECB. (2023). TIBER-EU Framework: Threat Intelligence-Based Ethical Red Teaming. European Central Bank.