The DORA regulation is the European Union’s rulebook for keeping financial services running when technology fails. It is not UK law, and it still reaches plenty of British businesses: a group with a subsidiary authorised in a member state falls in scope directly, and a technology supplier serving a regulated financial client in Europe gets pulled in through that client’s contracts. One of those contract duties turns on identification.
Your client cannot file a valid Register of Information unless every entity in it carries the prescribed identifier, and for a UK supplier that means a Legal Entity Identifier (LEI). LEI24 acts as a registration agent for UK companies that need one.
What Is the DORA Regulation?
DORA, the Digital Operational Resilience Act, is Regulation (EU) 2022/2554 on digital operational resilience for the financial sector. It entered into force on 16 January 2023 and has applied since 17 January 2025. Being a regulation and not a directive, it lands in every member state directly, with no national transposition step. It replaces a patchwork of supervisory guidelines and national expectations with one binding framework covering ICT risk, incidents, testing, and suppliers.
Who Does DORA Apply To?
DORA names around 20 categories of regulated financial entity, then reaches past them into the technology supply chain. Requirements scale with size, so microenterprises follow a simplified ICT risk framework.
Financial Entities in Scope
Scope covers most of the regulated financial sector:
- Credit institutions, payment institutions, and electronic money institutions
- Investment firms, alternative investment fund managers, and UCITS management companies
- Insurance and reinsurance undertakings, plus their intermediaries
- Central securities depositories, central counterparties, trading venues, and trade repositories
- Crypto-asset service providers authorised under MiCA, and crowdfunding service providers
- Credit rating agencies, securitisation repositories, IORPs, and administrators of critical benchmarks
The smallest insurance intermediaries and pension institutions sit outside.
ICT Third-Party Service Providers
An ICT third-party service provider supplies digital and data services on an ongoing basis: cloud platforms, software vendors, data centres, managed service providers, analytics firms, and hardware support. Group affiliates count.
Most never deal with a European regulator. The contract does the work, because the financial entity has to extract specific terms and data from them. A small group sits differently: the European Supervisory Authorities designated the first 19 critical ICT third-party providers in November 2025, mostly cloud hyperscalers, data vendors, and post-trade infrastructure.
Does DORA Apply to UK Firms?
Whether DORA reaches a UK business depends on whether you are authorised in the EU or selling to someone who is.
British groups with EU operations face an authorisation test. An entity authorised in a member state counts as a financial entity on its own, and a UK parent cannot absorb the obligation for it.
British technology companies with EU financial clients meet DORA through the contract: mandated Article 30 terms, due diligence, audit rights, subcontracting notifications, exit support, and requests for the identification data your client needs for its register. Your client owes its supervisor a great deal of evidence, and a supplier who blocks it tends to get replaced.
The Five Pillars of DORA
DORA groups its requirements into five pillars: ICT risk management, incident reporting, resilience testing, ICT third-party risk management, and information sharing. The first four are mandatory and together map the shape of a DORA compliance programme: your systems, your incidents, your testing, and everything you outsource. The fifth is optional, and most firms leave it.
ICT Risk Management
Pillar one asks for a documented ICT risk framework covering strategies, policies, procedures, and tools, plus an inventory of ICT assets mapped to the business functions they support. It has to address prevention, detection of anomalous activity, business continuity, backup and restoration, and a feedback loop that turns incident findings into better controls. Ownership sits with the management body. Hand the technical work to your CISO by all means. The accountability stays where it is.
ICT-Related Incident Reporting
Every ICT incident gets classified against harmonised criteria: clients affected, duration, geographic spread, data losses, and economic impact. An incident that crosses the thresholds counts as major, and the reporting deadlines start running from the moment it is classified.
| Report | Deadline |
| Initial notification | Within 4 hours of classifying the incident as major, and no later than 24 hours from becoming aware of it |
| Intermediate report | Within 72 hours of the initial notification |
| Final report | No later than one month after the intermediate report |
Firms may also flag significant cyber threats voluntarily. The four-hour window causes the most trouble, since it forces a classification call out of people who already have a live incident on their hands.
Digital Operational Resilience Testing
Every in-scope entity runs a testing programme, reviewed at least annually and scaled to its size and risk profile, spanning vulnerability scans, network security assessments, source code review, and end-to-end tests. Competent authorities then identify the significant entities that must also run threat-led penetration testing every three years. TLPT is intelligence-led, runs against live production systems, follows a methodology aligned with TIBER-EU, and requires testers who meet defined competence and independence criteria.
ICT Third-Party Risk Management (Contracts and Oversight)
Financial entities assess concentration risk before signing, run due diligence on prospective providers, and record every ICT contractual arrangement.
Article 30 sets the floor for every ICT contract: service descriptions, where services are delivered and data is processed, service levels, notice periods, cooperation with supervisors, and termination rights. Contracts supporting a critical or important function carry more, including precise performance targets, unrestricted audit rights, and documented exit strategies. Designated critical providers sit above all of it, with a Lead Overseer, examinations by joint ESA and national teams, and annual oversight fees.
Information Sharing
Financial entities may exchange cyber threat intelligence among themselves. The arrangement has to run within a trusted community, protect confidentiality, respect competition and data protection law, and be notified to the competent authority when a firm joins or leaves.
DORA vs the UK’s Operational Resilience Rules
UK firms already answer to an operational resilience regime of their own, set by the FCA’s rules on building operational resilience in PS21/3 and the PRA’s SS1/21. Its transition period closed on 31 March 2025, so firms are expected to be living inside their impact tolerances now.
| UK rules (PS21/3 and SS1/21) | DORA | |
| Approach | Outcomes-based: identify important business services and set impact tolerances | Prescriptive: detailed obligations across ICT risk, incidents, testing, and suppliers |
| Incident reporting | Notification under existing supervisory rules, no single harmonised clock | Fixed 4 hour, 72 hour, and one month sequence for major incidents |
| Supplier registers | Not yet a standing requirement | Register of Information, mandatory and submitted annually |
| Supplier oversight | Critical third parties regime, first four providers designated by HM Treasury in July 2026 | Critical providers designated by the ESAs, first 19 designated in November 2025 |
| Testing | Scenario testing, with CBEST for larger firms | Annual testing programme, TLPT every three years for significant entities |
Evidence is where the two regimes part company. UK rules ask a firm to justify its own judgements about services and tolerances. DORA asks for populated registers, classified incidents, and completed tests in a prescribed format, the field-level discipline that already governs FCA transaction reporting under UK MiFIR.
The Register of Information: What Firms Must Record
The Register of Information is a machine-readable dataset covering every contractual arrangement a financial entity holds for ICT services. Article 28(3) requires it, and national competent authorities collect it once a year. It captures:
- The submitting entity and any branches in a consolidated submission
- Every direct ICT provider, with name, country, provider type, and criticality status
- Contract reference, dates, notice periods, and governing law
- Which functions each service supports, and whether they count as critical or important
- Subcontractors supporting critical or important functions
Supervisors join these registers across thousands of firms to find where the sector concentrates, which is how the first critical providers were identified. Accuracy therefore matters as much as in any other regulatory reporting submission, because identifier errors can trigger validation issues and lead to rejection or rework.
How an LEI Supports DORA Compliance (Register of Information)
No article of DORA tells you to get a Legal Entity Identifier, and no penalty attaches to going without one. The requirement arrives through the register instead. Entities recorded in the register must be identified using the prescribed identifier fields so supervisors can match records across submissions. Financial entities use their LEI. ICT providers inside the EU may use an LEI or a European Unique Identifier from the business register. For legal entities established outside the Union, only the LEI works.
UK suppliers land in that last category. Your EU client needs your LEI to file a valid register, and a Companies House number will not do the job. The reference data behind an LEI number is verified and has to be confirmed every year. A lapsed record still exists, but it is not valid and active, so it fails your client’s register the same way a missing one does.
Penalties for Non-Compliance
DORA hands the penalty question to member states. Article 50 requires each one to set administrative penalties and remedial measures, so the ceiling depends on where you are supervised. Authorities may order a firm to stop what it is doing, force changes to its arrangements, name it publicly, or pursue criminal penalties where national law allows. Designated critical providers face something sharper: periodic penalty payments of 1% of average daily worldwide turnover, charged daily for up to six months.
How to Prepare for DORA Compliance
Where you sit in the contract decides the work. Financial entities run a programme:
- Confirm scope entity by entity. Identify every authorised entity in the group and the member state supervising it.
- Map critical or important functions. Contract terms, testing scope, and register content all rest on this classification.
- Build the register from source data. Procurement records, contract repositories, and vendor spreadsheets rarely agree, and reconciliation eats more time than anyone budgets.
- Test contracts against Article 30. Legacy agreements rarely carry the full clause set, so start with renewals and critical arrangements.
- Rehearse the incident clock. Run a classification exercise and time the decision.
- Set the testing calendar and check whether you fall into the TLPT population.
Suppliers face a readiness exercise instead: due diligence questionnaires, audit and access clauses, register data requests, and questions about exit assistance. Prepared answers and an active identifier turn a slow procurement conversation into a short one.
The Future of Operational Resilience Regulation in the UK
UK supervision is converging on the same machinery. The FCA’s final rules on operational incident and third-party reporting, published in March 2026 alongside the PRA’s PS7/26, bring in a single standardised incident report across the FCA, PRA, and Bank of England from 18 March 2027, plus notification of new material third-party arrangements and an annual register of them. Fixed thresholds and a submitted supplier register are what DORA introduced two years earlier.
HM Treasury made the first critical third party designations on 10 July 2026, naming Amazon Web Services, Google Cloud, Microsoft, and Oracle, with Bank of England, PRA, and FCA oversight starting on 13 July 2026. The Cyber Security and Resilience Bill is meanwhile in the House of Lords after clearing the Commons in June 2026, with Royal Assent expected later this year and wider scope and tighter incident reporting when it lands.
Build for DORA compliance now and you are largely building for where UK rules are going.
Frequently Asked Questions
When did DORA come into force?
DORA entered into force on 16 January 2023 and has applied since 17 January 2025. Financial entities and their ICT arrangements were expected to comply fully from that date.
What is a critical ICT third-party provider (CTPP)?
A provider the European Supervisory Authorities designate as systemically important to the EU financial sector. Designated providers are directly overseen by the European Supervisory Authorities, while their clients still retain DORA obligations.
How quickly must ICT incidents be reported under DORA?
An initial notification is due within four hours of classifying an incident as major, and no later than 24 hours from becoming aware of it. An intermediate report follows within 72 hours.
Is DORA the same as NIS2?
No. NIS2 covers essential and important entities across many sectors. DORA is financial-sector specific and takes precedence for firms that would otherwise fall under both frameworks.
What is threat-led penetration testing (TLPT)?
Intelligence-led testing that simulates real attacker behaviour against live production systems. Significant financial entities run it at least every three years, using qualified and independent testers.
Do ICT providers need an LEI for DORA?
DORA places no direct stand-alone duty on providers to obtain an LEI. But where a UK supplier is a non-EU legal entity that must be identified in the Register of Information, its EU client may need a valid and active LEI for that record.



