What is DORA? The EU rules on tech resilience for financial firms

By SendPay Business · · 2 min read

What is DORA? The EU rules on tech resilience for financial firms

DORA, the Digital Operational Resilience Act, is an EU law that makes financial firms prove they can withstand and recover from IT problems and cyber attacks. It has applied since 17 January 2025 and covers banks, payment and e-money institutions, crypto firms, insurers and more.

DORA's five main areasTech suppliers are in scope tooWhat it means for fintechs

DORA's five main areas

  1. ICT risk management: firms need a framework to identify, protect against and recover from tech risks.
  2. Incident reporting: major IT incidents must be classified and reported to regulators.
  3. Resilience testing: systems must be tested regularly, with advanced testing for larger firms.
  4. Third-party risk: contracts with tech suppliers, such as cloud providers, must meet set standards.
  5. Information sharing: firms are encouraged to share threat information with each other.

Tech suppliers are in scope too

DORA lets EU authorities directly oversee tech providers judged critical to the financial sector, such as major cloud platforms. That's new, as rules used to apply only to the financial firms themselves.

What it means for fintechs

Fintechs serving EU customers need clear records of their systems and suppliers, tested recovery plans and a way to report serious incidents quickly. Working with partners who already meet these rules takes much of that load off.

Where SendPay fits

SendPay lets you launch your own branded platform with GBP, EUR and USD accounts, transfers and branded Visa cards, powered by licensed partners.

Build it

Create your own financial platform.

Pick a template, name it, brand it, preview every page before you pay. Your brand, your users, your fees.

Build my platform →

Questions people ask

What is PSD2?

The EU law behind open banking and strong customer authentication.

What is PSD2? →
What is MiCA?

The EU's rules for crypto-asset firms.

What is MiCA? →
What is PCI DSS?

The security standard for handling card data.

What is PCI DSS? →

Read next

This guide is general information, not legal or financial advice. SendPay Business is a technology company, not a bank, and does not take deposits; regulated services on the platforms are provided by licensed partners. PayPal, Patreon and Substack are named as reference points only and are not affiliated with SendPay Business.