Fintech Regulation Is About to Get Serious: What the EU's DORA Means for Everyone
The Digital Operational Resilience Act went into full enforcement in January 2025. Most fintech companies - and more importantly, most of their technology vendors - are not adequately prepared. This is going to be painful.
DORA is not another checkbox compliance exercise. It is a fundamental restructuring of how financial institutions and their technology providers must think about operational risk, incident management, and third-party dependencies. It applies not just to banks and insurers, but to the entire chain of technology providers they depend on. If your company provides technology services to any financial institution operating in the EU, DORA applies to you - regardless of where your company is headquartered.
The regulation represents a philosophical shift from "protect against breaches" to "assume disruption will happen and prove you can survive it." That shift has profound implications for how fintech companies architect systems, manage vendors, and report incidents.
Why DORA Is Different

Financial services regulation isn't new. Banks have been dealing with compliance requirements for decades. So why does DORA matter more than the hundreds of other regulations that financial institutions already navigate?
It Covers the Entire Supply Chain
Previous regulations focused primarily on financial institutions themselves. If a bank had a security incident, the bank was responsible. What happened at the bank's cloud provider, or the cloud provider's data center operator, was largely outside the regulatory scope.
DORA changes this fundamentally. It creates a framework where the entire technology supply chain is within scope. If a bank uses a cloud provider, and that cloud provider uses a monitoring vendor, and that monitoring vendor has an outage that cascades into a disruption of the bank's services, DORA creates accountability at every level.
This means that technology vendors who previously operated outside financial services regulation are now, effectively, subject to it. The practical impact is staggering. A SaaS company that provides, say, document management to three European banks now needs to comply with DORA's requirements for ICT risk management, incident reporting, and operational resilience testing. That company may have ten employees and no compliance function. DORA doesn't care.
It Mandates Active Resilience Testing
DORA doesn't just require security controls - it requires proof that those controls work under stress. Specifically, it mandates threat-led penetration testing (TLPT) for systemically important financial entities, and regular resilience testing for everyone else.
This goes far beyond the typical annual penetration test that most companies treat as a checkbox exercise. TLPT is modeled on frameworks like TIBER-EU, where testing simulates realistic attack scenarios based on current threat intelligence. The tests are designed to break things, and the results must be reported to regulators.
For technology vendors, this means that their financial services clients will increasingly require them to participate in resilience testing exercises. The bank's annual TLPT may include testing scenarios that target the vendor's infrastructure. Vendors who can't support this - or who refuse to participate - will find themselves removed from approved vendor lists.
The Incident Reporting Requirements Are Unprecedented
DORA's incident reporting requirements are far more stringent than anything previously required of technology providers. Major ICT-related incidents must be reported to the relevant competent authority using standardized templates, with initial notification within tight timeframes.
The definition of "major incident" is broad. It includes service disruptions, data breaches, failed system changes, and any event that has a significant impact on the financial entity's ability to provide services. This isn't limited to security breaches - a failed deployment that causes four hours of downtime qualifies.
For technology vendors, this creates a new operational requirement: they need incident classification and reporting processes that align with their financial services clients' DORA obligations. When the vendor has an incident, the financial institution needs to know about it quickly, with enough detail to make its own regulatory reporting decisions.
This is a Premium Article
Sign up for a Premium membership to read this article and get full access to strategic intelligence on technology and business.
Already a member? Sign in