Skip to main content
DORA Auditor

DORA Requirements: The Five Pillars

Last updated: 1 authoritative sourceDORA Auditor Editorial Team

DORA's requirements are organised into five pillars. Together they require financial entities to govern ICT risk, report major incidents, test their resilience, manage third-party dependencies, and, optionally, share threat intelligence. Each pillar below links to a detailed deep-dive with the relevant articles.

The five pillars at a glance

Where to start

Most entities begin with the ICT risk-management framework and the register of information, since these underpin the other pillars. Use our Readiness Score to see which pillars need the most attention, or work through the compliance checklist.

One pillar works differently: information sharing

Four of the five pillars create a build obligation: a framework to maintain, a process to run, a test to pass, a register to keep current. The fifth, information sharing under Article 45, does not. It authorises financial entities to exchange cyber threat indicators, tactics, and alerts within a trusted arrangement, but joining one is optional and scales with the same proportionality principle that runs through the rest of DORA. Entities that do join still take on real obligations: the arrangement itself needs documented rules protecting confidentiality and personal data, and the entity has to notify its competent authority when it joins and again if it leaves. Most entities join an existing structure, commonly FS-ISAC or a national CERT-run scheme, rather than building an arrangement from scratch. See our full explainer on Article 45 for the GDPR basis, the notification mechanics, and how to choose between a global and a national arrangement.

Frequently asked questions

How many pillars does DORA have?
Are all five DORA pillars mandatory?
Which DORA requirements should a firm address first?
Why is the information-sharing pillar different from the other four?

Sources

  1. Regulation (EU) 2022/2554 (DORA), EUR-Lex