Screenata

Beyond SOC 2

What are the 5 pillars of DORA regulation?

August 18, 20262 min read

What are the 5 pillars of DORA regulation?

DORA's five pillars are ICT risk management, ICT-related incident management and reporting, digital operational resilience testing, ICT third-party risk management, and information and intelligence sharing. The EU Digital Operational Resilience Act applies to financial entities operating in the EU and, through the third-party pillar, reaches the ICT providers that serve them. That is how it lands on software vendors who are not themselves financial institutions.

The five pillars

PillarWhat it requires
ICT risk managementA governance framework with board accountability, identification of critical functions, protection and detection measures, and recovery arrangements
Incident management and reportingClassify ICT-related incidents against defined criteria and report major ones to regulators on set timelines
Resilience testingA testing programme, with threat-led penetration testing for entities designated as significant
Third-party risk managementA register of ICT providers, contractual requirements including audit and access rights, concentration risk analysis, and documented exit strategies
Information sharingVoluntary exchange of cyber threat intelligence between financial entities

Four carry direct obligations. The fifth is encouraged rather than mandated.

Why it reaches vendors who are not banks

The third-party pillar is the one that travels. A regulated financial entity must impose specific contractual terms on its ICT providers, maintain a register of them, and be able to exit. Those obligations arrive at the vendor as procurement requirements: audit rights, subcontractor disclosure, incident notification timelines, and a documented exit plan.

A SaaS company selling into EU financial services will therefore meet DORA through customer contracts and security reviews long before any regulator contacts it directly.

DORA and NIS2 are not the same thing

Both are EU, both concern operational resilience, and they are routinely conflated.

DORANIS2
ScopeEU financial entities and their ICT providersEssential and important entities across many sectors
RelationshipSector-specific, takes precedence for financial entitiesBroader baseline
Distinctive requirementThreat-led penetration testing, ICT provider registerSector-wide risk measures and management accountability

Honest scope note

Screenata supports SOC 2, HIPAA, ISO 27001, and ISO 42001 through a NIST 800-53 hub. We do not currently support DORA or NIS2 as enrollable frameworks. This page exists because the question is asked constantly by teams selling into EU financial services, and a straight answer is more useful than a gap left open. Much of the underlying evidence, particularly around vendor registers, incident handling, and resilience testing, overlaps with work an ISO 27001 or SOC 2 programme already produces.

Connect and see

See your SOC 2 with your real systems.

Connect GitHub and cloud read-only. Vera shows your control matrix, policy gaps, and prioritized next actions before you commit to anything.