The EU's Digital Operational Resilience Act (DORA) has been in force since January 17, 2025. For financial entities and the ICT providers that serve them, the work has shifted from preparing for the regulation to proving, on an ongoing basis, that ICT risk management, incident reporting, resilience testing, and third-party oversight are actually operating, not just documented.
This matters most for Enterprise Architects, CIOs, and CISOs in the financial sector because DORA compliance is fundamentally an architecture problem. Evidence has to trace back to real applications, real vendors, and real dependencies, not a static policy binder.
See how Ardoq helps organizations evidence DORA compliance across their application estate: How to Evidence DORA Compliance
Jump to:
Evidencing DORA compliance means being able to show, for any application in your estate, which regulatory requirement it's tied to, which controls apply, when it was last tested, and who owns it. A policy document that says risk management happens isn't evidence. A live record connecting each critical application to its ICT risk assessment, its resilience test results, and its supporting vendor contracts is.
Ardoq approaches this by modeling DORA's requirements directly against the application and business capability landscape, rather than keeping compliance records in a separate system disconnected from what's actually running. That means a criticality assessment, a vendor risk record, or a testing result stays linked to the application it describes as that application changes.
Dedicated GRC and compliance-automation platforms are built to manage the audit and evidence workflow itself, and many organizations run one alongside their architecture tooling. Ardoq's role is different: it's the layer that keeps the underlying architecture data, what depends on what, which vendor supports which capability, current enough that whatever evidence system you use is drawing on an accurate picture rather than a stale one.
This is the same principle behind Ardoq's approach to compliance becomes operational, not reactive: connecting risks, controls, and regulatory requirements across the organization instead of managing them as a separate exercise.
The sections below cover the five DORA pillars in more detail and the specific steps for setting this up in Ardoq.
DORA establishes a robust regulatory framework that aims to prevent, detect, and respond to cyber threats and operational disruptions. Here's an overview to explain what DORA is and what it entails at a high level:
The Digital Operational Resilience Act applies to a wide range of financial institutions, including banks, payment service providers, and critical infrastructure providers within the financial sector. Additionally, any third-party service providers delivering Information and Communication Technology (ICT) services to these financial institutions fall under DORA's purview. KPMG has a detailed list of entities impacted by DORA.
Modern finance thrives on robust digital infrastructure. Banks, payment services, and investment firms rely heavily on technology to deliver core services. From secure online banking platforms to real-time transactions, these systems underpin the smooth functioning of the financial ecosystem.
This dependence on technology brings inherent risks. Cyberattacks are a constant threat, with the potential to cripple financial operations, compromise sensitive data, and erode consumer confidence. Additionally, IT disruptions caused by technical failures or natural disasters can have equally devastating consequences, the kind a resilient enterprise security architecture is designed to withstand.
According to a Lloyds of London scenario analysis:
"If a cyber attack on a major financial services payment system were to take place, the global loss could reach $3.5 trillion over a five-year period."
DORA has been introduced in an attempt to mitigate this tremendous potential cost to organizations and to the larger economy, while also safeguarding the security and privacy of individual citizens and the services upon which they rely.
In 2020, the FBI determined that business email compromise remains the most significant cyber threat. The UK's National Cyber Security Centre (NCSC) also warned about phishing campaigns and issued guidance that includes deploying the global industry standard protocol, DMARC, as the first line of defense.
Businesses, however, generally have been slow to address significant cyber threats. While the Digital Operational Resilience Act presents challenges for IT leaders in the financial sector, it also brings the opportunity to address potential security weaknesses. Though meeting DORA's requirements takes effort, the benefits are substantial:
The EU's Digital Operational Resilience Act (DORA) establishes a comprehensive framework to strengthen the digital resilience of the financial sector. DORA's regulatory framework rests upon five key pillars:
This pillar focuses on establishing a robust and consistent approach to managing risks associated with ICT. DORA mandates financial institutions to develop a comprehensive ICT risk management framework. This framework should include:
This pillar introduces a structured approach to identifying, managing, and reporting ICT-related incidents. Key aspects include:
This pillar emphasizes the importance of proactively testing and verifying an institution's ability to withstand and recover from disruptions. DORA mandates:
Recognizing the interconnectedness of the financial ecosystem, DORA also focuses on managing risks associated with third-party ICT service providers. Key elements include:
This pillar aims to foster collaboration and information exchange within the financial sector to combat cyber threats more effectively. DORA encourages:
By addressing these five pillars, DORA fosters a holistic approach to managing digital operational risks and building a more secure and resilient financial ecosystem in the European Union.
The unique aspect of the DORA regulation is its introduction of a Union-wide Oversight Framework on critical ICT third-party providers, as designated by the European Supervisory Authorities (ESAs).
| DORA Pillar | Where Ardoq Provides Evidence |
|---|---|
| ICT Risk Management | Risk assessments modeled against real business capabilities and applications, not a standalone spreadsheet |
| Incident Management, Classification & Reporting | Incident processes documented against the ITSM practice already in place, so reporting reflects the actual estate |
| Digital Operational Resilience Testing | Testing results and TLPT cycles recorded against the applications they tested |
| ICT Third-Party Risk Management | Vendor assessments and criticality ratings linked to the applications and capabilities each vendor supports |
| Information Sharing Arrangements | Modeled processes showing how threat and vulnerability information moves between teams and external bodies |
DORA entered into force on January 16, 2023, and became fully applicable on January 17, 2025. That preparation window is over. Supervisory attention has moved to whether ICT risk frameworks, incident reporting, and resilience testing are actually running, not whether they were planned.
Since the application date, national competent authorities and the European Supervisory Authorities have been reviewing financial entities' registers of information, the records that map ICT services, providers, and which business functions depend on them. Entities designated as significant are also working through requirements for threat-led penetration testing (TLPT), which has to be repeated on a regular cycle rather than completed once.
For most organizations, this means the compliance question has changed from "do we have a plan" to "can we show, for any critical application, what regulation it's tied to, when it was last tested, and who's accountable." That's a data and architecture problem as much as a policy one.
DORA EU regulation represents a significant shift for financial institutions. Here's how it continues to shape operational practice:
These requirements bring substantial benefits, for individual institutions and for the financial ecosystem as a whole:
If your organization falls under DORA, ongoing compliance comes down to three things:
The EU's Digital Operational Resilience Act (DORA) significantly affects the financial sector, demanding a paradigm shift in how large organizations approach cybersecurity and operational resilience. While the Act lays a comprehensive foundation, mapping and maintaining compliance with DORA requires a strategic and coordinated effort. This is where Enterprise Architecture (EA) steps in, playing a crucial role in navigating DORA's complexities and ensuring long-term compliance.
Enterprise Architecture provides a holistic view of an organization's IT landscape, encompassing applications, data, infrastructure, and business processes. This unique perspective makes EA ideally suited to lead DORA mapping and compliance efforts within large organizations. Here's how:
Beyond DORA compliance, EA fosters a culture of digital resilience within large organizations. EA provides the organizational and process awareness to follow regulations, a strong technical foundation to scale, and the insights to support innovation and new opportunities.
Here are some key ways EA contributes to digital resilience:
Combining EA with collaborative business process management establishes a common language throughout a company, so more informed decisions become the norm. Agility is easier when you can see how changes in any one area affect others.
Maintaining DORA compliance and building digital resilience require collaboration across various departments. EA can act as a central hub, facilitating communication and information sharing between IT, security, risk management, and business units. This collaborative approach ensures a holistic and coordinated effort toward achieving DORA compliance and fostering a culture of digital resilience within the organization.
By leading DORA compliance efforts and improving digital resilience, Enterprise Architecture can empower large organizations in the financial sector to navigate the evolving regulatory landscape and thrive in an increasingly complex digital landscape.
Ardoq can support organizations across all five key areas covered by DORA. Ardoq helps organizations meet DORA's requirements by identifying, documenting, and managing the impact of this regulatory change. Ardoq also complements and enhances incident management practices by modeling the existing IT Service Management (ITSM) practice and relevant frameworks, such as NIST or ISO27001.
Most compliance-automation tools manage the audit workflow well but treat the underlying architecture as a static input. Ardoq's difference is keeping that architecture live, so the evidence a compliance tool surfaces is only ever as current as the last real change to the estate. Ardoq's capabilities here include:
Learn more about how Ardoq enables organizations to achieve and demonstrate DORA compliance more effectively: The Digital Operational Resilience Act (DORA) and Ardoq
One of the companies already leveraging Ardoq to prepare for DORA is a Norwegian pension company. They have used Ardoq Discover to prepare criticality assessments for the business and their applications.
"We've gained significant momentum using Discover, partly due to requirements outlined in the EU's DORA regulation, which mandates criticality assessments for both the business area and underlying applications. The solution has performed very well, even for non-technical users."
- Chief Enterprise Architect
Ardoq currently counts numerous financial service companies as customers, including MUFG, OMERS, IG Group, and WSECU. They have leveraged the unique flexibility of the Ardoq platform towards key business goals such as:
"One of Ardoq's strengths is easing the pain of compliance. The collaborative features and flexibility of the platform make it adaptable to the specific needs of different regulatory frameworks, including DORA."
- Sean Gibson, Senior Enterprise Architect at Ardoq
Ardoq has developed a framework that helps organizations address the regulatory requirements for the EU Digital Operational Resilience Act (DORA). Ardoq's step-by-step approach can be customized to the needs of different organizations, enabling businesses to smoothly integrate DORA's requirements into existing processes. Here is a high-level overview of how to map DORA requirements in Ardoq.
Learn more about how organizations can leverage Ardoq to address the EU Digital Operational Resilience Act (DORA) regulatory requirements: Implementing the Digital Operational Resilience Act in Ardoq
DORA reshaped operational practice for financial institutions across the EU, and compliance is now an ongoing responsibility rather than a one-time deadline. CIOs and Enterprise Architects in the financial sector are the ones best placed to keep risk management, incident reporting, and resilience testing tied to a real, current picture of the application estate, so evidence holds up under review rather than degrading between audits.
To learn more about how Ardoq can support compliance and risk management, see our solution for Application Risk Management or get in touch for a demo.