DORA Requirements: The Five Pillars
DORA's requirements are organised into five pillars. Together they require financial entities to govern ICT risk, report major incidents, test their resilience, manage third-party dependencies, and, optionally, share threat intelligence. Each pillar below links to a detailed deep-dive with the relevant articles.
The five pillars at a glance
ICT Risk Management
Article 6Governance, frameworks, and controls for managing ICT risk across the financial entity.
ICT Incident Reporting
Articles 17–23Classifying, managing, and reporting major ICT-related incidents to competent authorities.
Digital Resilience Testing
Articles 24–27Regular testing of ICT systems, including threat-led penetration testing (TLPT).
ICT Third-Party Risk
Articles 28–30Managing risk from ICT third-party providers, including the register of information.
Information Sharing
Article 45Voluntary exchange of cyber-threat intelligence between financial entities.
Where to start
Most entities begin with the ICT risk-management framework and the register of information, since these underpin the other pillars. Use our Readiness Score to see which pillars need the most attention, or work through the compliance checklist.
One pillar works differently: information sharing
Four of the five pillars create a build obligation: a framework to maintain, a process to run, a test to pass, a register to keep current. The fifth, information sharing under Article 45, does not. It authorises financial entities to exchange cyber threat indicators, tactics, and alerts within a trusted arrangement, but joining one is optional and scales with the same proportionality principle that runs through the rest of DORA. Entities that do join still take on real obligations: the arrangement itself needs documented rules protecting confidentiality and personal data, and the entity has to notify its competent authority when it joins and again if it leaves. Most entities join an existing structure, commonly FS-ISAC or a national CERT-run scheme, rather than building an arrangement from scratch. See our full explainer on Article 45 for the GDPR basis, the notification mechanics, and how to choose between a global and a national arrangement.
Frequently asked questions
How many pillars does DORA have?
DORA is organised into five pillars: ICT risk management, ICT incident reporting, digital operational resilience testing, ICT third-party risk, and information sharing.
Are all five DORA pillars mandatory?
Four are mandatory. The fifth, information sharing (Article 45), is voluntary; financial entities may exchange cyber-threat intelligence but are not required to.
Which DORA requirements should a firm address first?
Most entities begin with the ICT risk-management framework and the register of information, as these underpin incident reporting and resilience testing.
Why is the information-sharing pillar different from the other four?
It is the only pillar that authorises rather than mandates an activity. The other four pillars require an entity to build something (a framework, an incident-reporting process, a testing programme, a third-party register); Article 45 only removes the legal doubt around voluntarily exchanging cyber-threat intelligence.