A regulation, not a directive
Unlike NIS2, DORA applies directly in every member state without transposition, and it is lex specialis for the financial sector: where both texts could apply, DORA governs. Its requirements are detailed by regulatory and implementing technical standards from the European supervisory authorities, which set the register of information templates, the incident classification criteria, the content of the ICT risk framework and the threat-led penetration testing regime.
The five pillars in practice
ICT risk management: a documented framework, approved by the management body, with identification and classification of ICT-supported functions, protection, detection, response and recovery. Incident management: classification of ICT incidents and reporting of the major ones to the competent authority on initial, intermediate and final reports. Testing: a program including threat-led penetration tests for the entities designated for them. Third-party risk: a strategy, the register of information, contract clauses, exit plans. Information sharing: voluntary exchange of threat intelligence.
What it demands from governance
DORA is explicit that the management body bears the ultimate responsibility for ICT risk, approves the framework and the strategy, sets the risk tolerance, is informed of major incidents and keeps its own knowledge current. For a board, that translates into a risk appetite for ICT, a reporting that measures against it, a register of critical ICT dependencies it has seen, and a testing program whose results it has read. The supervisor can ask for all four.