Skip to content
SOVEREIGNTYBALANE
Back to the wiki
Law · 1 min read · Updated 16 August 2026

DORA

In shortIn the financial sector a documented exit plan has been mandatory since 2025, not optional.

At a glance

Instrument
Regulation (EU) 2022/2554, applicable since 17 January 2025
Who is covered
Banks, insurers, payment institutions, investment firms and other financial entities — plus their ICT providers
Core outsourcing duty
Article 28: contract content, exit plans and risk assessment for ICT services
Exit plans
Mandatory for critical or important functions, documented and tested
Concentration risk
Must be assessed explicitly — dependence on a few large providers is a checkpoint of its own
Oversight of providers
ICT third-party providers designated as critical fall under direct European oversight

DORA governs how financial entities must handle disruption of their information technology. The regulation has applied directly in all member states since 17 January 2025, replacing a patchwork of national supervisory practice.

For this wiki it is interesting for one reason: it turns good practice into a legal duty. What appears elsewhere here as a recommendation — exit plans, knowing switching costs, mapping dependencies — is auditable requirement in the financial sector.

The four areas

ICT risk management. A documented framework, owned by the management body, with procedures for detection, response and recovery.

Incident reporting. Significant incidents must be reported to the supervisor in staged deadlines, against uniform criteria.

Testing. Regular resilience testing, extending to threat-led penetration testing for large institutions.

Outsourcing and third parties. The part that matters here.

Article 28 and the exit plan

For ICT services supporting critical or important functions, DORA requires specific contract content: service description, processing locations, access and audit rights, termination rights — and exit plans.

Those plans must be documented and tested. That is exactly what separates them from what most companies mean by a plan. How such a rehearsal runs is set out under Exit strategy.

On top comes the duty to assess concentration risk: do several critical functions sit with the same provider? That question forces a map of your own dependencies — and answers, incidentally, where Vendor lock-in would be most expensive.

Why this matters beyond finance

First through the supply chain: anyone supplying software or operations to a financial entity gets the requirements passed on contractually — comparable to the mechanism under NIS2.

Second as a benchmark. DORA describes, in statutory form, what a defensible approach to provider dependence looks like. Even those outside its scope can adopt the structure without carrying the audit duties.

Common questions

Does DORA reach providers outside finance?
Yes, indirectly and partly directly. Anyone supplying software or operations to a financial entity receives the Article 28 contract requirements by pass-through. Providers designated as critical are additionally subject to their own oversight.
What must an exit plan contain?
Triggers, target environment, data migration including format, time required, responsibilities, and evidence that the plan has been tested. A plan without a test does not serve the purpose of the provision.
Is DORA the same as NIS2?
No. NIS2 applies across sectors for cybersecurity; DORA applies specifically to finance and goes further there — particularly on outsourcing, testing and provider oversight. For financial entities DORA is the more specific rule.
What does concentration risk mean in practice?
That several critical functions sit with the same provider or in the same region. DORA requires assessing that, not prohibiting it. The assessment does force you to map your provider landscape at least once.

Sources

See also

Related terms