DORA is enforced by designated regulators in each EU member state, known as competent authorities.  These competent authorities can request that financial organisations implement specific security measures and remediate vulnerabilities.  Meanwhile, EU member states can impose penalties on organisations that fail to comply.  The nature of these penalties is decided by each member state.  

ICT service providers classified as critical by the European Commission are directly supervised by the European Supervisory Authorities (ESAs), which have similar powers to competent authorities (i.e., requesting the implementation of security measures and the remediation of vulnerabilities).  ESAs also have the power to fine non-compliant ICT service providers up to 1% of their average daily worldwide turnover.

DORA - The Digital Operations Resilience Act

Published on
5 Jun
2025

URM’s blog discusses the EU’s Digital Operation’s Resilience Act (DORA), explaining who it will apply to, its requirements, how it will be enforced, and more.

Read more
"
We would like to pass on our gratitude to our consultant for all his hard work and advice during our 3-year re-certification and assessment against the new Standard. After seven days of auditing, we have two OFIs that the assessors have put forward from the audits. This pays testament to our URM consultant, his hard work, eye for detail and advice given, both during the audits and during all the works beforehand.
contact US

Let us help you

Let us help you in your compliance journey by completing the form and letting us know how we can best support you.