Summary · cheatsheet · DORA / financial entity
Financial entity under Article 2 · Regulation (EU) 2022/2554 applies from 17 Jan 2025 · supervised by the Czech National Bank · ready to print as PDF
Obligations of a financial entity
An overview of the obligations that DORA places directly on a financial entity — for management, IT and compliance. Every point carries the article you can use to look the binding wording up.
The closed list sits in Article 2(1): points (a) to (t) are financial entities, point (u) covers ICT providers. Next to banks and insurers it takes in payment institutions and electronic money institutions including exempted ones, investment firms, trading venues, central securities depositories, central counterparties, fund managers, insurance intermediaries and crypto-asset service providers. The exclusions are in Article 2(3) — six points, among them insurance intermediaries that are microenterprises or small or medium-sized enterprises. Some entities only meet the simplified framework under Article 16 (last tile).
A documented ICT risk management framework as part of the overall risk management system, reviewed at least once a year and after major incidents (Article 6(1) and (5)). Entities other than microenterprises assign ICT risk management to an independent control function (paragraph 4) and subject the framework to internal audit with a formal follow-up on critical findings (paragraphs 6 and 7). It includes a digital operational resilience strategy (paragraph 8). Ultimate responsibility rests with the management body — it approves the framework, gives it a budget and keeps its own training up to date (Article 5(2) and (4)).
An incident is major where critical services are affected and, at the same time, either there was successful malicious unauthorised access that may result in data losses, or two or more other materiality thresholds are met (Article 8(1) of Regulation 2024/1772). Time limits under Article 5 of Regulation 2025/301: initial notification within 4 h of classification, and no later than 24 h from becoming aware; intermediate report within 72 h; final report within one month of the intermediate one. The deferral to noon of the next working day does not apply, for the first two reports, to credit institutions, central counterparties and operators of trading venues (paragraph 5).
A testing programme as part of the framework; the tests are carried out by independent parties, internal or external (Article 24). Cadence: at least yearly for all systems supporting critical or important functions (Article 24(6)). The top tier is TLPT — threat-led penetration testing (Article 26): once every three years, but only for entities identified by the competent authority; it applies neither to entities under Article 16(1) nor to microenterprises, and the identification criteria come from Regulation 2025/1190. It runs on live production and without the defenders knowing. The framework is TIBER-EU — the Czech National Bank joined it in September 2024 and issued the TIBER-CZ Implementation Guide in March 2025.
Responsibility always stays with the financial entity, even where the service is bought in (Article 28(1)). Before contracting: due diligence and a risk assessment covering the aggravation of ICT concentration risk and conflicts of interest (paragraphs 4 and 5); for critical or important functions, a tested exit strategy (paragraph 8). The contract has to carry the minimum content of Article 30. The register of information (paragraph 3) is kept at entity level and on a consolidated basis and distinguishes arrangements supporting critical functions; the format comes from Implementing Regulation 2024/2956 — fifteen interlinked templates, with identification by LEI code.
Taking part in arrangements for sharing indicators of compromise, tactics, techniques and procedures is voluntary — but participation has to be notified to the competent authority (Article 45(3)). It is the only hard obligation in the whole chapter and, because it hangs off a voluntary activity, it is the one most often overlooked. In the Czech Republic, failing to notify is a separate administrative offence.
It is not relief "for the small", it is a named list: small and non-interconnected investment firms, payment institutions exempted under Directive (EU) 2015/2366, institutions exempted under Directive 2013/36/EU for which the Member State did not exercise the option in Article 2(4), electronic money institutions exempted under Directive 2009/110/EC and small institutions for occupational retirement provision. Articles 5 to 15 do not apply to them — instead they meet eight obligations under the second subparagraph of Article 16(1) and are subject neither to TLPT nor to the strategy on ICT third-party risk (Article 26(1), Article 28(2)). Being a microenterprise does not mean the simplified framework — a microenterprise is not exempted, its scope is merely narrowed in places.
The competent authority is the Czech National Bank (Section 9 of Act No. 31/2025 Coll.). Fines under Section 18: up to CZK 50,000,000 for the ICT risk management framework (Article 6), the ICT business continuity policy (Article 11), reporting of major incidents (Article 19), testing and third-party risk management; up to CZK 20,000,000 for the remaining ICT risk management duties and for the incident management process and classification (Articles 17 and 18); up to CZK 10,000,000 for failing to notify information sharing and for not cooperating with the Czech National Bank. Compliance is enforced through coercive fines of up to CZK 5,000,000 individually and CZK 20,000,000 in aggregate (Section 14).
We can help with the implementation
We will assess your situation against DORA, prepare the inputs for the register of information, rehearse an incident report with you or go through the contract addendum from your bank. The consultation is non-binding.