Sprita iT

Regulation (EU) 2022/2554

DORA and application security

DORA requires financial entities and their ICT third-party providers to maintain a digital operational resilience framework: ICT risk management, incident handling and reporting, resilience testing, and structured management of third-party ICT risk. For software organizations this puts secure development, testing and dependency governance under financial supervision.

  1. 16 January 2023

    Regulation entered into force

  2. 17 January 2025

    Applies to financial entities and ICT providers

Primary source: Regulation (EU) 2022/2554 on EUR-Lex · Last reviewed 14 August 2026

Who is in scope

  • Financial entities across banking, payments, insurance, investment and market infrastructure
  • ICT third-party service providers serving those entities, including software vendors and cloud services
  • Critical ICT third-party providers, which face an additional EU oversight regime

Scope depends on your entity, sector and — for directives — national transposition. This page is informational, not legal advice.

What we produce

  • Application risk assessment across in-scope systems
  • Testing programme documentation: scope, method, cadence, findings, closure
  • Component and third-party dependency inventory
  • Remediation record with ownership and dates

We produce technical evidence and control narratives. We do not certify your compliance — that remains with you and your auditors.

What it requires from software teams

01

ICT risk management framework

A documented framework covering identification, protection, detection, response and recovery — applied to the applications and systems that support critical functions.

02

Digital operational resilience testing

A testing programme proportionate to the entity, covering application security testing among other techniques, with findings tracked to closure.

03

ICT third-party risk

Structured management of dependencies on ICT providers, including a register of information and contractual requirements — which cascades security expectations down the software supply chain.

04

Incident management and reporting

Classification and reporting of ICT-related incidents on defined timelines, which requires detection capability in the systems that produce them.

How Sprita iT Europe helps

  1. 1

    Assess application security posture across the systems supporting critical or important functions

  2. 2

    Establish an application security testing programme that satisfies resilience testing expectations

  3. 3

    Build the dependency and third-party component view that ICT third-party risk management requires

  4. 4

    Produce evidence packages that map engineering activity to the framework

Frequently asked questions

We supply software to a bank. Does DORA apply to us?

Directly, if you qualify as an ICT third-party service provider to a financial entity — and in that case DORA's contractual and oversight requirements shape your obligations. Even where the direct application is limited, financial clients must impose specific requirements contractually, so the practical effect reaches your delivery process either way.

Does DORA require penetration testing of our applications?

DORA requires a resilience testing programme proportionate to the entity's size, risk profile and role, using a range of techniques; advanced threat-led penetration testing applies to entities identified for it under the regulation. Application security testing is one component of the wider programme — check the requirements applicable to your entity against the text.

How does DORA interact with NIS2 for us?

For financial entities, DORA generally operates as the sector-specific regime for ICT risk. Many groups nonetheless face both across different legal entities. We scope the applicable set per entity rather than assuming one answer for the whole group.

Primary sources

We link legal texts and standards directly. This page is informational and is not legal advice; obligations depend on your entity, sector and national transposition.

Where do you stand against DORA?

A scoped assessment maps your estate to the obligations that actually apply to your entity — and produces the evidence trail.