DORA Compliance: A Guide for Irish Financial Firms

Ronan Short
September 28, 2026

DORA compliance means meeting the requirements of the Digital Operational Resilience Act, Regulation (EU) 2022/2554, which has applied to Irish financial entities since 17 January 2025. The Central Bank of Ireland supervises it, and the regulation never included a transitional period.

More than a year into full application, the supervisory question has changed. In 2025 the Central Bank asked firms to identify their gaps. Now it expects those gaps to be substantially closed, and it expects firms to produce the evidence on request, including the annual review report on the ICT risk management framework required under Article 6(5).

This guide covers who is in scope, what the five pillars actually require, the incident reporting clocks, and the part most smaller Irish firms underestimate: the obligations that follow the ICT services you buy in rather than run yourself.

What DORA Compliance Means for Irish Financial Firms

DORA compliance means running your firm so it can withstand, respond to and recover from ICT disruption, and being able to demonstrate that to your supervisor. The regulation sets binding rules across ICT risk management, incident reporting, resilience testing and third-party oversight for financial entities throughout the EU.

The distinction that trips people up is this. DORA is not a point-in-time certification. You cannot pass it once and file the certificate. The Central Bank has been explicit that firms are expected to keep enhancing their ability to assess, monitor, defend against and learn from ICT risk on an ongoing basis.

It also supersedes other regimes. DORA operates as lex specialis for NIS2 and for parts of the Critical Entities Resilience Directive, so the incident reporting and risk management measures in those instruments do not apply to financial entities. DORA applies instead. It has also replaced PSD2 operational and security incident reporting.

Which Irish Firms Fall Within DORA Scope?

Compliance officer checking a firm's authorisation type against DORA scope requirements

DORA applies to around 20 types of financial entity listed in Article 2 of the regulation. Scope follows your authorisation, not the activities you happen to carry out. So the first check is what your firm is authorised as, then whether that entity type appears on the Article 2 list, read alongside the definitions in Article 3.

Entity types commonly caught in Ireland include:

  • Credit institutions and credit unions
  • Investment firms, fund managers and UCITS management companies
  • Insurance and reinsurance undertakings, plus insurance intermediaries above the relevant thresholds
  • Payment institutions and electronic money institutions
  • Crypto-asset service providers authorised under MiCA
  • Crowdfunding service providers

Authorisation detail matters more than sector labels. The Central Bank's current understanding, set out in its DORA FAQ, is that fund administrators authorised solely under the national Investment Intermediaries Act are not in direct scope.

Do Smaller Firms Get an Exemption From DORA?

Proportionality is not an exemption. Smaller and less complex firms implement the requirements in a way that fits their size and risk profile, but they still implement them. Certain specific requirements fall away for microenterprises, and the regulation provides a simplified ICT risk management framework for some entity types.

Proportionality shows up in several practical ways. Only major incidents get reported. Only a small subset of firms carry out advanced threat-led penetration testing. Mandatory weekend reporting is narrowed to credit institutions, trading venues, central counterparties and entities with systemic national impact.

How DORA Applies to Branches and Passporting Firms

DORA obligations follow prudential supervision, so a branch operating in Ireland under freedom of establishment does not submit its own register of information to the Central Bank. The legal entity established elsewhere in the EU submits one covering the branch to its home competent authority.

Irish conduct of business rules still apply to that branch. The split catches firms out because the conduct supervisor and the DORA supervisor are not the same authority.

5 Pillars of DORA Compliance Explained

DORA is built on 5 pillars, and four of them carry hard obligations while the fifth is largely voluntary. Together they cover how you manage ICT risk, how you report incidents, how you test resilience, how you oversee suppliers, and how you share threat intelligence with peers.

The reach is wider than most firms expect. It runs from board-level risk appetite and impact tolerances through managed backup and recovery arrangements and out into every contract you hold for ICT services.

  1. ICT risk management. Identify, classify and document your ICT-supported business functions, the assets behind them and the dependencies between them, then review that classification annually.
  2. ICT incident management and reporting. Detect, classify and report major ICT-related incidents to the Central Bank against set criteria and time limits.
  3. Digital operational resilience testing. Run a testing programme scoped to your risk and the criticality of the assets involved. Advanced threat-led penetration testing applies only to a designated subset of firms.
  4. ICT third-party risk management. Manage supplier risk as part of your overall framework, maintain the register of information and meet the contractual requirements in Article 30.
  5. Information and intelligence sharing. Exchange cyber threat intelligence with other financial entities. Participation is voluntary but demonstrates a forward-leaning posture.

How to Report a Major ICT Incident Under DORA

DORA incident reporting timeline showing the 4 hour, 72 hour and one month deadlines

Three deadlines govern major incident reporting, and they are set out in Commission Delegated Regulation (EU) 2025/301. The initial notification is due within 4 hours of classifying an incident as major, and in any case no later than 24 hours after you became aware of it. Two further reports follow.

  1. Initial notification. As early as possible, within 4 hours of classification as major, and no later than 24 hours from awareness of the incident.
  2. Intermediate report. Within 72 hours of the initial notification, even where the status has not changed. An updated intermediate report is required once regular operations are restored.
  3. Final report. No later than one month after the latest updated intermediate report, once root cause analysis is complete.

Reports go to the Central Bank through its Portal using the harmonised templates the European Supervisory Authorities designed. 

The Central Bank publishes guidance on submitting major ICT-related incident reports alongside the templates themselves. Significant cyber threats may also be notified voluntarily.

Which ICT Incidents Count as Major Under DORA?

Classification runs against the criteria and materiality thresholds in Commission Delegated Regulation (EU) 2024/1772. The criteria look at clients and counterparts affected, transactions involved, duration and downtime, geographical spread, data losses, criticality of the services hit, and economic impact.

Early certainty is rare, so the rules allow you to classify using estimates or data from comparable periods. If better information later shows the incident was not major, you can reclassify it. The practical failure mode is waiting for perfect data while the 4 hour clock runs.

What Happens When an Incident Starts at Your IT Provider

Reporting duties sit with you regardless of where the incident began. If the impact on your firm meets the materiality thresholds, you report it as a major incident, even when the root cause lies entirely inside a third party's systems.

That has a direct consequence for how you buy IT. Your provider needs to tell you about incidents fast enough for you to classify and notify inside 4 hours. A provider who reports on the next business day makes your own compliance impossible.

What Goes Into a DORA Register of Information

Register of information spreadsheet listing ICT third-party providers under DORA

Every contractual arrangement for ICT services goes into the register. Article 28(3) requires financial entities to maintain and update a register covering all such arrangements, and the European Banking Authority has confirmed that reading. Registers are submitted annually.

Firms consistently under-scope this. The definition of an ICT service is broad. It means digital and data services delivered through ICT systems on an ongoing basis, including hardware as a service where the vendor supplies technical support or firmware updates. 

  • Every ICT contract, not just the critical ones, including the smaller software subscriptions nobody thinks of as outsourcing.
  • The subcontracting chain behind each provider, so you can see who your provider depends on.
  • Identifiers for each provider, with the legal entity identifier requirement treated as non-blocking in early submissions while firms catch up.
  • A link back to the functions each service supports, which is what makes the register usable rather than decorative.

What DORA Requires From Your ICT Provider Contracts

Article 30 sets out the contractual provisions your ICT agreements must contain, and responsibility for getting them in cannot be delegated. Firms using contracted ICT services remain fully responsible for compliance with every obligation under DORA and applicable financial services law. The supplier's failure is your finding.

Smaller regulated firms feel this most, because the outsourcing is total. A broker or advisory practice with no internal IT function depends on whatever its provider agreed to years before DORA existed, which is why IT support for financial advisors now gets assessed against regulatory obligations rather than uptime alone.

When reviewing contracts, look for:

  • Audit rights that let you or your appointed auditor examine the provider's controls.
  • Prompt incident notification fast enough to support the 4 hour clock.
  • Transparency of subcontracting and advance notice of any change to it.
  • Inclusion in your testing programme, covering business continuity tests and threat-led penetration testing where it applies.
  • Documented recovery capability with defined timeframes for restoring the services you rely on.
  • Regular performance reporting rather than reactive updates after something breaks.

Where Irish Firms Still Fall Short on DORA Compliance

Gaps cluster in the same three areas: third-party risk frameworks, register quality and advanced testing. The recurring shortfalls are practical rather than conceptual.

  • Critical or important functions never properly mapped, which leaves the register and the testing programme built on guesswork.
  • Contracts renewed unchanged, still missing audit rights and subcontracting transparency.
  • Detection gaps at the supplier boundary, where neither party is clearly responsible for spotting unusual activity. Firms without in-house capability generally close this through managed network security, which puts monitoring and alerting under a defined responsibility.
  • Recovery plans that exist on paper but have never been tested end to end with the provider involved.
  • No documented proportionality assessment, so the firm cannot explain why its approach fits its risk.

Getting Your ICT Setup Ready for DORA Supervision

Most of the work sitting in front of Irish firms right now is unglamorous. Map the functions, fix the contracts, get the register complete and accurate, and rehearse the incident process until the 4 hour clock stops feeling impossible. None of that requires a large compliance team, but it does require knowing exactly what your ICT estate contains and who supports each part of it.

If you have never had that estate documented independently, start there. Book a free IT audit and get a written picture of your systems, suppliers and recovery arrangements before your next supervisory engagement.

Get an IT Plan Today!

Call Us Today To Discuss Your IT Needs & Get a Plan Tailored To Your Business Needs!
Get A Free IT Audit

Frequently Asked Questions

When did DORA come into effect in Ireland?

DORA has applied since 17 January 2025 and there was no transitional period. Most requirements in the level 1 regulation have been in force since January 2023. Firms are now more than a year into full application and supervisory assessment.

Who is the competent authority for DORA in Ireland?

The Central Bank of Ireland is the competent authority for financial entities falling within DORA scope in Ireland. It is also the designated authority for threat-led penetration testing and holds the Irish seat on the DORA Oversight Forum.

Does DORA apply to small financial firms?

Yes. Proportionality allows smaller firms to implement requirements in a way that matches their size and risk profile, and some specific requirements do not apply to microenterprises. That is a lighter implementation, not an exemption from the regulation.

How quickly must a major ICT incident be reported?

An initial notification is due within 4 hours of classifying the incident as major, and no later than 24 hours after you become aware of it. An intermediate report follows within 72 hours, and a final report within one month.

Does DORA replace NIS2 for financial firms?

For financial entities in the scope of DORA, yes. DORA acts as lex specialis, so the incident reporting and risk management measures under NIS2 do not apply to them. DORA also replaced the operational and security incident reporting required under PSD2.

Does DORA apply directly to our IT provider?

Providers designated as critical ICT third-party providers come under direct EU oversight. Everyone else is reached through your contracts. You stay fully responsible for compliance, so the obligations pass to your provider through the terms you agree.

Get a FREE Quote

Fill out the form below and we’ll get back to you!

Check - Elements Webflow Library - BRIX Templates

Thank you

Please check your inbox to download your Free EBook!
Oops! Something went wrong while submitting the form.

Get Free Audit From IT Support

Contact us today to inquire about our Managed IT Solutions. We usually get back within 24 hours.

Company Size:
Check - Elements Webflow Library - BRIX Templates

Thank you

Please check your inbox to download your Free EBook!
Oops! Something went wrong while submitting the form.
Ronan Short
Founder @ IT Support 4U

Ronan Short, the founder of IT Support, is a trusted authority in the IT industry, passionate about providing top-tier tech support at IT Support. Dedicated to solving complex problems with simplified solutions, catering to all your SME IT needs with cost-effective solutions.