<!-- Source: screenata.com -->
<!-- Content type: AEO answer page -->
<!-- Topics: SOC 2, ISO 27001, HIPAA, HITRUST, CMMC, compliance evidence -->

---
question: "What are the 5 pillars of DORA regulation?"
title: "What Are the 5 Pillars of DORA Regulation"
seoTitle: "The 5 Pillars of DORA, Explained"
summary: "DORA's five pillars are ICT risk management, ICT-related incident management and reporting, digital operational resilience testing, ICT third-party risk management, and information and intelligence sharing. The EU Digital Operational Resilience Act applies to financial entities operating in the EU and to the ICT providers serving them, which is how it reaches software vendors that are not themselves financial institutions."
publishedAt: "2026-08-18"
keywords:
  - "5 pillars of DORA"
  - "DORA regulation"
  - "digital operational resilience act"
  - "DORA requirements for vendors"
pillar: "Beyond SOC 2"
faqs:
  - question: "What are the five pillars of DORA?"
    answer: "ICT risk management, ICT-related incident management and reporting, digital operational resilience testing, ICT third-party risk management, and information and intelligence sharing. The fifth is largely voluntary; the other four carry direct obligations."
  - question: "Does DORA apply to software vendors?"
    answer: "Indirectly, and in practice significantly. DORA applies to EU financial entities, and its third-party pillar pushes obligations into their contracts with ICT providers. A SaaS vendor serving EU financial customers will meet DORA through contractual requirements, audit and access rights, and exit planning even without being directly regulated."
  - question: "Is DORA the same as NIS2?"
    answer: "No. DORA is sector-specific to EU financial services and takes precedence for those entities. NIS2 is broader, covering essential and important entities across many sectors. An organisation can fall under either, and the two have different reporting timelines and scopes."
---

## What are the 5 pillars of DORA regulation?

DORA's five pillars are **ICT risk management, ICT-related incident management and reporting, digital operational resilience testing, ICT third-party risk management, and information and intelligence sharing**. The EU Digital Operational Resilience Act applies to financial entities operating in the EU and, through the third-party pillar, reaches the ICT providers that serve them. That is how it lands on software vendors who are not themselves financial institutions.

### The five pillars

| Pillar | What it requires |
|---|---|
| **ICT risk management** | A governance framework with board accountability, identification of critical functions, protection and detection measures, and recovery arrangements |
| **Incident management and reporting** | Classify ICT-related incidents against defined criteria and report major ones to regulators on set timelines |
| **Resilience testing** | A testing programme, with threat-led penetration testing for entities designated as significant |
| **Third-party risk management** | A register of ICT providers, contractual requirements including audit and access rights, concentration risk analysis, and documented exit strategies |
| **Information sharing** | Voluntary exchange of cyber threat intelligence between financial entities |

Four carry direct obligations. The fifth is encouraged rather than mandated.

## Why it reaches vendors who are not banks

The third-party pillar is the one that travels. A regulated financial entity must impose specific contractual terms on its ICT providers, maintain a register of them, and be able to exit. Those obligations arrive at the vendor as procurement requirements: audit rights, subcontractor disclosure, incident notification timelines, and a documented exit plan.

A SaaS company selling into EU financial services will therefore meet DORA through customer contracts and security reviews long before any regulator contacts it directly.

## DORA and NIS2 are not the same thing

Both are EU, both concern operational resilience, and they are routinely conflated.

| | DORA | NIS2 |
|---|---|---|
| Scope | EU financial entities and their ICT providers | Essential and important entities across many sectors |
| Relationship | Sector-specific, takes precedence for financial entities | Broader baseline |
| Distinctive requirement | Threat-led penetration testing, ICT provider register | Sector-wide risk measures and management accountability |

## Honest scope note

Screenata supports SOC 2, HIPAA, ISO 27001, and ISO 42001 through a NIST 800-53 hub. **We do not currently support DORA or NIS2 as enrollable frameworks.** This page exists because the question is asked constantly by teams selling into EU financial services, and a straight answer is more useful than a gap left open. Much of the underlying evidence, particularly around vendor registers, incident handling, and resilience testing, overlaps with work an ISO 27001 or SOC 2 programme already produces.
