Regulation Statutory · EU
Digital Operational Resilience Act (Regulation (EU) 2022/2554).
DORA obliges EU financial entities - banks, insurers, investment firms, payment service providers and others - to comply with uniform requirements for ICT risk management, incident reporting, resilience testing and the management of ICT third-party providers. The regulation has applied directly in the EU since 17 January 2025. For Swiss companies this is, per the client's assessment, a candidate not yet conclusively examined: relevant above all are Swiss financial institutions with an EU establishment, as well as Swiss ICT providers who supply financial entities in the EU/EEA.
01 Triggers
When does DORA apply to you?
DORA may apply to you if one of these triggers applies. The Regulatory Check tests them against your details.
- Industry: Financial services (Recommend individual review): As a financial entity with an establishment, subsidiary or branch in the EU/EEA, that entity is directly subject to DORA's requirements on digital operational resilience.
- Activity: Payment transactions (Recommend individual review): If you process payment transactions for or with EU financial institutions, DORA may affect you indirectly - for example as an ICT third-party provider under the oversight framework for critical providers. This needs to be checked case by case.
- Markets: EU (applies if additionally: Industry: Financial services) (Recommend individual review): If you provide services as a Swiss financial entity in the EU/EEA market, DORA can reach you via your customers' contractual requirements or via an EU establishment, even though not every detail of this was verified in the regulation's text itself in this research.
- Markets: EU (applies if additionally: Activity: Payment transactions) (Recommend individual review): If you provide services as a Swiss ICT or payment service provider (e.g. cloud, software, network, payment processing) for financial entities headquartered in the EU/EEA, DORA can reach you via your customers' contractual requirements, even without your own EU establishment.
Exceptions
- According to the secondary sources examined, DORA is triggered by the financial entity's seat in the EU/EEA, not by the customer's seat - a Swiss financial entity without any EU establishment is accordingly not directly within scope.
- A Swiss bank or insurer without a subsidiary, branch or licensed establishment in an EEA member state is, on this understanding, not directly covered; the finer points were not checked in the regulation's text itself (Art. 2), only via secondary sources.
02 Obligations
What does DORA require?
- Establish an ICT risk management framework (per secondary sources, including governance, identification, protection, detection, response and recovery).
- Report major ICT-related incidents to the competent supervisory authority.
- Conduct regular digital operational resilience testing, for significant institutions including threat-led penetration testing (TLPT).
- Manage ICT third-party risk, including contractual minimum requirements towards ICT providers.
- For ICT third-party providers from third countries (such as Switzerland) classified as 'critical': per a secondary source, EU financial entities may only use their services if the provider has established a subsidiary in the EU/EEA within twelve months of classification - this statement was not verified against the regulation's text (Art. 31) itself.
03 Evidence
What evidence is needed?
- Documented ICT risk management framework.
- Register of contracts with ICT third-party providers (per secondary sources part of DORA, not itself checked in the regulation's text).
- Evidence of resilience tests carried out.
- Reporting process for major ICT incidents.
04 Deadlines
Which deadlines apply?
- DORA becomes binding and applicable in the EU/EEA (regulation in force since 17 January 2023, applicable from 17 January 2025 per the secondary sources examined).
Information as of: 24 September 2026. Past dates are grey, upcoming ones highlighted (as of when the page was built).
05 Penalties
What are the consequences of violations?
The regulation's text itself (including Art. 50 on administrative sanctions) was not examined in full text in this research, as the EUR-Lex full text was not technically retrievable. Per secondary sources, national supervisory authorities can impose measures and sanctions on financial entities within the EU scope. For Swiss companies without their own EU scope, DORA, per the sources examined, does not act as directly enforceable, but primarily via EU customers' contractual requirements.
06 Related
What is connected with it?
- FINMA Circular 2023/1 "Operational risks and resilience – banks": FINMA Circular 2023/1 sets out in detail, for Swiss banks under the Banking Act, how operational risks are to be managed - including ICT risk management, cyber risk management and business continuity management.
- Directive on measures for a high common level of cybersecurity across the Union (NIS2): The NIS2 Directive (Directive (EU) 2022/2555) obliges operators in critical and important sectors to manage risk and report significant security incidents.
07 Open
What is still uncertain?
- CANDIDATE STATUS: per the client's architecture decision, DORA has not yet been adopted into the website. No 'Finance' industry page exists yet; whether and how DORA applies to Swiss companies case by case has not yet been conclusively clarified (see ARCHITEKTUR-UND-CONTENT.md, item 13 and section 7.10).
- The EUR-Lex full text of the regulation (in particular Art. 2 scope and Art. 31 oversight framework for critical ICT third-party providers) could not be technically retrieved in this research (JavaScript requirement of the EUR-Lex page). The statements on scope, third-country rules and sanctions come from secondary sources and are marked 'pruefen' accordingly.
- The exact list of financial entity categories covered by DORA was taken not directly from the regulation's text but from secondary sources.
- Whether and how FINMA-supervised institutions are additionally affected by DORA on top of existing FINMA requirements was not examined.
08 Sources
Sources
Information as of: 24 September 2026.
- Verordnung (EU) 2022/2554 (DORA) – Übersichtsartikel, Wikipedia (Sekundärquelle, nicht die Verordnung selbst), retrieved on 24 September 2026
- DORA und die Schweiz: Eine Analyse der EU-Verordnung und ihrer Auswirkungen auf Schweizer Unternehmen, LEXcellence (Anwaltskanzlei, Sekundärquelle), retrieved on 24 September 2026
- Regulation (EU) 2022/2554 (DORA) in the Official Journal of the EU, Amt für Veröffentlichungen der Europäischen Union (EUR-Lex), retrieved on 24 September 2026
A professional assessment based on publicly available sources, not legal advice. Whether a given rule applies in your specific case depends on circumstances that are not fully captured here.
FAQ Answers
Questions about DORA.
Are we, as a Swiss fintech without an EU establishment, automatically exempt from DORA?
Based on the source status examined here, yes, as long as you have no EU/EEA establishment and are not classified as a critical ICT third-party provider for EU financial entities. A conclusive case-by-case review against the regulation's text (Art. 2 and Art. 31 DORA) was not carried out in this research.
Why is there no separate 'Finance' industry on the website yet?
That is a deliberate, still open decision by the client (see the architecture document, item 13). This norm file has been researched and evidenced; the decision to show DORA and the FINMA circular on the website as a separate industry is a separate, outstanding matter.
Does DORA apply to you?
The Regulatory Check gives an initial assessment. In a conversation, we clarify what really applies in your situation and in which order you address it.
