← /episodes
[ S01E04 ]EN2026-06-1118:04

S01E04 - DORA in practice: five pillars, one burden of proof

S01E04 - DORA in practice: five pillars, one burden of proof
▶ play episode
Download ↓

The Digital Operational Resilience Act — Regulation EU 2022/2554 — has been in force since January 17, 2025, applying to approximately 22,000 financial entities across the EU: banks, insurers, investment firms, payment service providers, and their critical ICT third-party providers. Yet only half are fully compliant. Fines can reach 10% of global annual turnover, and national supervisors across all 27 member states have begun active enforcement. On November 18, 2025, the European Supervisory Authorities designated 19 critical ICT providers — including AWS, Microsoft Azure, and Google Cloud — now subject to direct EU oversight.

Michael and Nadine walk through all five DORA pillars in detail. Pillar 1 mandates a full ICT risk management framework with board-level governance responsibility. Pillar 2 requires standardized classification and prompt reporting of major ICT incidents to competent authorities without undue delay. Pillar 3 makes periodic resilience testing mandatory — including Threat-Led Penetration Testing (TLPT) for significant institutions. Pillar 4 holds financial entities accountable for the ICT risks of their suppliers: outsourcing is no longer a liability shield. Pillar 5 requires the structured sharing of cyber threat intelligence between financial entities.

The core insight of this episode: DORA does not ask for a one-time certification — it demands continuous, demonstrable evidence of operational resilience. That is exactly what Attesto delivers: tamper-evident event logging for Pillars 1 and 2, and the Proof of Evolution system for Pillars 3 and 4. The Nova/IVC cryptographic layer is already running live in production.