Skip to content

This blog was first published in 2025 and has been updated. 

What is DORA and why does it matter for financial services?

The Digital Operational Resilience Act (DORA) is a live compliance obligation—enforcement began 17 January 2025—covering how financial institutions manage, monitor, and recover from ICT disruptions. For CISOs, it reframes identity not as an access tool but as a core operational resilience control.

Compliance is often seen as a necessary burden in financial services—a series of boxes to tick to avoid fines or reputational damage. But the Digital Operational Resilience Act (DORA) isn’t just another checkbox exercise. It represents a deeper shift in how regulators expect European organizations to manage digital risk.

What is DORA?

The Digital Operational Resilience Act (DORA) is EU Regulation 2022/2554, which requires financial institutions to demonstrate they can withstand, respond to, and recover from ICT disruptions. It covers five pillars: ICT risk management, incident reporting, resilience testing, third-party risk management, and information sharing.

For CISOs and identity leaders, DORA is an opportunity to turn compliance into a driver of long-term risk reduction and resilience. To realize that opportunity, they’ll need to start with identity.

Why is identity management critical for DORA compliance?

DORA’s ICT risk management pillar specifically requires strong access controls, multi-factor authentication, and audit-ready identity records—making identity the operational foundation of compliance, not a supporting function.

Every digital transaction within a financial institution begins with a basic security question: who is requesting access? In an increasingly hybrid, cloud-connected, and remote-enabled environment, verifying and controlling identity is more complex—and more critical—than ever.

DORA recognizes that without secure and resilient identity systems, no organization can maintain operational continuity during a crisis. If you lose control of identity, you lose control of the business.

What are the limitations of traditional IAM under DORA?

Traditional identity systems were not designed for today’s threat landscape or regulatory expectations. They are often reactive, policy-driven, and heavily reliant on passwords and manual processes.

Common gaps include:

  • Static access policies that don’t account for contextual risk
  • Lack of visibility into real-time identity behavior
  • Slow incident response due to siloed identity tools
  • No backup strategy if IAM systems go offline

DORA expects more. It expects institutions to proactively manage identity risk as part of their operational resilience program. Financial organizations operating in the EU must now be compliant with these requirements as 17 January 2025 marked the beginning of the enforcement stages of DORA.

How does identity risk management differ from traditional IAM?

Identity Risk Management moves beyond rule-based access control by continuously evaluating the risk level of each user, device, and access attempt—and dynamically adjusting authentication requirements in real time based on those signals.

For example:

  • Is a user logging in from a known location on a trusted device?
  • Is their behavior consistent with historical patterns?
  • Is there a rise in help desk requests that could indicate social engineering?

These signals help build a real-time risk profile that guides authentication and access decisions.

How des RSA support DORA identity compliance?

RSA solutions address each of DORA’s identity requirements—from phishing-resistant authentication and behavioral risk detection to hybrid failover and governance reporting:

Together, these tools allow institutions to manage identity as a dynamic, data-driven risk function.

How can organizations move beyond basic DORA compliance?

Meeting DORA’s minimum requirements is the floor, not the ceiling. Institutions that use DORA as a driver for identity modernization will emerge with fewer breaches, faster audits, and more resilient operations than those treating it as a checkbox exercise.

By investing in identity risk management now, CISOs can:

  • Reduce the likelihood and impact of breaches
  • Lower the cost and complexity of audits
  • Improve user experience through adaptive, passwordless access
  • Build lasting resilience across all digital operations

DORA is a wake-up call to rethink identity. Not just as an access gatekeeper, but as a critical risk signal and a cornerstone of resilience.

With RSA, financial institutions can rise to that challenge—and use identity not just to comply, but to lead.

Watch the RSA webinar, DORA & Digital Risk: Strengthening Identity Security in Financial Services, to learn what DORA compliance really means for Identity Security, best practices to prepare for DORA audits, and key compliance obligations related to user authorization, access, authentication, and business continuity.

Frequently asked questions
What is DORA compliance for financial services?

DORA—the Digital Operational Resilience Act—is EU legislation requiring financial institutions and their critical ICT third-party providers to demonstrate resilience against ICT disruptions across five pillars: risk management, incident reporting, resilience testing, third-party risk, and information sharing. Enforcement began 17 January 2025, making it a live regulatory obligation for institutions operating in the EU.

When did DORA compliance become mandatory?

DORA entered into force in January 2023 with a two-year implementation window. The enforcement date was 17 January 2025, meaning financial institutions are now subject to mandatory compliance requirements and active oversight by EU financial regulators.

How does identity management relate to DORA requirements?

DORA’s ICT risk management pillar requires strong access controls, multi-factor authentication, and complete audit trails for identity events. Without a resilient identity system, organizations cannot demonstrate the operational continuity DORA demands—or defend against the credential-based attacks that most often trigger the incident reporting DORA requires.

What are the penalties for DORA non-compliance?

EU regulators can impose fines of up to 1% of average daily worldwide turnover for ongoing violations, or up to €5 million for individuals in management roles. Beyond financial penalties, regulators can require institutions to suspend activities that breach DORA requirements.

How do I prepare for DORA identity audits?

DORA audits assess whether institutions can demonstrate real-time identity visibility, documented access controls, and tested incident response procedures. Organizations should ensure complete audit trails for all authentication events, regular user access reviews, and documented failover procedures for identity systems before an audit window opens.

What identity technologies are required for DORA compliance?

DORA requires phishing-resistant MFA, continuous monitoring of access behavior, and authentication that remains operational during outages. Hardware security keys, risk-based authentication, and hybrid failover capabilities—such as those in RSA ID Plus—are purpose-built to meet these requirements.

How is DORA different from GDPR?

GDPR governs personal data privacy: how it is collected, stored, and processed. DORA governs operational resilience: whether financial institutions can keep ICT systems running and recover from disruptions. The two frameworks overlap where identity data is involved, but DORA’s primary focus is business continuity, not data handling.

What is Identity Risk Management in the context of DORA?

Identity Risk Management means continuously evaluating the risk level of users, devices, and access attempts—and adapting authentication requirements in real time based on those signals. Under DORA, this approach is central to proactive ICT risk management rather than the reactive, policy-only model that traditional IAM tools provide.

See What's Possible with RSA

See the full RSA Unified Identity Platform—the products and solutions behind every story on this blog.
Explore RSA Solutions