Topic: Recht & Aufsicht
What is DORA?
DORA (Digital Operational Resilience Act) is an EU regulation that has applied to financial entities in the EU since January 2025. It governs digital operational resilience — IT risk management, incident reporting, penetration testing and third-party risk — and complements national frameworks such as MaRisk and BAIT.
DORA rests on five pillars: ICT risk management, ICT incident management, resilience testing (TLPT), third-party risk management and information sharing on cyber threats.
For German institutions, DORA overlays existing MaRisk and BAIT requirements — which requirement prevails in a given case is one of the most frequent consulting topics for 2025/2026.
Related terms
- BaFinBaFin (Bundesanstalt für Finanzdienstleistungsaufsicht) is the German supervisory authority for banks, insurers, securities trading and payment services — based in Bonn and Frankfurt am Main, founded in 2002.
- BAITBAIT (Bankaufsichtliche Anforderungen an die IT) is a BaFin circular from 2017 (amended in 2021 and 2024) that specifies IT requirements for banks and financial services providers — complementing MaRisk AT 7.
- MaRiskMaRisk (Mindestanforderungen an das Risikomanagement) is a BaFin circular setting out the requirements for internal risk management at German banks and financial services providers — binding in substance since 2005, with regular amendments.
Last updated: 2026-05-05