Financial institutions face the most demanding regulatory stack in the EU. DORA enters full enforcement in 2025. Combined with AVG, PSD2 and Basel IV, operational resilience is now a board-level obligation.
DORA requires ICT risk management, regular resilience testing (TLPT), incident classification within 4 hours and strict third-party oversight. Non-compliance with DORA carries unlimited fines based on annual turnover.