As of January 2025, DORA mandates that financial institutions implement systematic ICT risk management across their entire supply chain with over 350 requirements and requires software-based third-party management processes.
DORA compliance is not synonymous with security – digital resilience emerges only through consistent, centrally controllable security architecture beyond checklists.
DORA compliance is necessary but insufficient for digital resilience – what is required is a consistently built and centrally controllable security architecture with a focus on identity and cryptography management.
DORA no longer treats humans as an unavoidable security risk, but mandates structured training and security culture as mandatory components of cyber resilience.
Data sovereignty through local cloud infrastructure is necessary but insufficient — true control requires robust identity governance and transparency over metadata, encryption keys, and access protocols.
Starting in 2025, 30,000 companies must implement NIS2 and DORA requirements, forcing CISOs to review their governance, incident management, and third-party dependency management.