# Digital Operational Resilience Act (Regulation (EU) 2022/2554)

> DORA obliges EU financial entities - banks, insurers, investment firms, payment service providers and others - to comply with uniform requirements for ICT risk management, incident reporting, resilience testing and the management of ICT third-party providers. The regulation has applied directly in the EU since 17 January 2025. For Swiss companies this is, per the client's assessment, a candidate not yet conclusively examined: relevant above all are Swiss financial institutions with an EU establishment, as well as Swiss ICT providers who supply financial entities in the EU/EEA.

- Type: Regulation, Statutory
- Scope: EU
- As of: 24 September 2026
- Page: https://sacosi.ch/en/norms/dora
- Regulatory Check: https://sacosi.ch/en/regulation#normencheck

## When does DORA apply to you?

- Industry: Financial services (Recommend individual review): As a financial entity with an establishment, subsidiary or branch in the EU/EEA, that entity is directly subject to DORA's requirements on digital operational resilience.
- Activity: Payment transactions (Recommend individual review): If you process payment transactions for or with EU financial institutions, DORA may affect you indirectly - for example as an ICT third-party provider under the oversight framework for critical providers. This needs to be checked case by case.
- Markets: EU (applies if additionally: Industry: Financial services) (Recommend individual review): If you provide services as a Swiss financial entity in the EU/EEA market, DORA can reach you via your customers' contractual requirements or via an EU establishment, even though not every detail of this was verified in the regulation's text itself in this research.
- Markets: EU (applies if additionally: Activity: Payment transactions) (Recommend individual review): If you provide services as a Swiss ICT or payment service provider (e.g. cloud, software, network, payment processing) for financial entities headquartered in the EU/EEA, DORA can reach you via your customers' contractual requirements, even without your own EU establishment.

## Exceptions

- According to the secondary sources examined, DORA is triggered by the financial entity's seat in the EU/EEA, not by the customer's seat - a Swiss financial entity without any EU establishment is accordingly not directly within scope.
- A Swiss bank or insurer without a subsidiary, branch or licensed establishment in an EEA member state is, on this understanding, not directly covered; the finer points were not checked in the regulation's text itself (Art. 2), only via secondary sources.

## Obligations

- Establish an ICT risk management framework (per secondary sources, including governance, identification, protection, detection, response and recovery).
- Report major ICT-related incidents to the competent supervisory authority.
- Conduct regular digital operational resilience testing, for significant institutions including threat-led penetration testing (TLPT).
- Manage ICT third-party risk, including contractual minimum requirements towards ICT providers.
- For ICT third-party providers from third countries (such as Switzerland) classified as 'critical': per a secondary source, EU financial entities may only use their services if the provider has established a subsidiary in the EU/EEA within twelve months of classification - this statement was not verified against the regulation's text (Art. 31) itself.

## Evidence

- Documented ICT risk management framework.
- Register of contracts with ICT third-party providers (per secondary sources part of DORA, not itself checked in the regulation's text).
- Evidence of resilience tests carried out.
- Reporting process for major ICT incidents.

## Deadlines

- 17 January 2025: DORA becomes binding and applicable in the EU/EEA (regulation in force since 17 January 2023, applicable from 17 January 2025 per the secondary sources examined).

## Penalties

The regulation's text itself (including Art. 50 on administrative sanctions) was not examined in full text in this research, as the EUR-Lex full text was not technically retrievable. Per secondary sources, national supervisory authorities can impose measures and sanctions on financial entities within the EU scope. For Swiss companies without their own EU scope, DORA, per the sources examined, does not act as directly enforceable, but primarily via EU customers' contractual requirements.

## Frequently asked questions

**Are we, as a Swiss fintech without an EU establishment, automatically exempt from DORA?**
Based on the source status examined here, yes, as long as you have no EU/EEA establishment and are not classified as a critical ICT third-party provider for EU financial entities. A conclusive case-by-case review against the regulation's text (Art. 2 and Art. 31 DORA) was not carried out in this research.

**Why is there no separate 'Finance' industry on the website yet?**
That is a deliberate, still open decision by the client (see the architecture document, item 13). This norm file has been researched and evidenced; the decision to show DORA and the FINMA circular on the website as a separate industry is a separate, outstanding matter.

## Open points of the research

- CANDIDATE STATUS: per the client's architecture decision, DORA has not yet been adopted into the website. No 'Finance' industry page exists yet; whether and how DORA applies to Swiss companies case by case has not yet been conclusively clarified (see ARCHITEKTUR-UND-CONTENT.md, item 13 and section 7.10).
- The EUR-Lex full text of the regulation (in particular Art. 2 scope and Art. 31 oversight framework for critical ICT third-party providers) could not be technically retrieved in this research (JavaScript requirement of the EUR-Lex page). The statements on scope, third-country rules and sanctions come from secondary sources and are marked 'pruefen' accordingly.
- The exact list of financial entity categories covered by DORA was taken not directly from the regulation's text but from secondary sources.
- Whether and how FINMA-supervised institutions are additionally affected by DORA on top of existing FINMA requirements was not examined.

## Sources

- [Verordnung (EU) 2022/2554 (DORA) – Übersichtsartikel](https://de.wikipedia.org/wiki/Verordnung_(EU)_2022/2554_(DORA)), Wikipedia (Sekundärquelle, nicht die Verordnung selbst), retrieved 24 September 2026
- [DORA und die Schweiz: Eine Analyse der EU-Verordnung und ihrer Auswirkungen auf Schweizer Unternehmen](https://www.lexcellence.swiss/de/dora-und-die-schweiz-eine-analyse-der-eu-verordnung-und-ihrer-auswirkungen-auf-schweizer-unternehmen/), LEXcellence (Anwaltskanzlei, Sekundärquelle), retrieved 24 September 2026
- [Regulation (EU) 2022/2554 (DORA) in the Official Journal of the EU](https://eur-lex.europa.eu/eli/reg/2022/2554/oj), Amt für Veröffentlichungen der Europäischen Union (EUR-Lex), retrieved 24 September 2026

---
A professional assessment based on publicly available sources, not legal advice. Whether a given rule applies in your specific case depends on circumstances that are not fully captured here.
Source: SACOSI, Situational Awareness Consulting by Ivo Schönberner (https://sacosi.ch).
