The Digital Operational Resilience Act (DORA) came into force on 17 January 2025. If you are a UK financial services firm with EU operations — a fintech with EU customers, a bank with an EU branch, or an insurer writing EU policies — you are in scope.
Brexit does not exempt you. DORA applies to any financial entity operating in the EU, regardless of where its headquarters are.
At Metaluxo we advise fintechs and financial services firms on EU cybersecurity regulation. DORA is the most significant new compliance obligation since GDPR. This post covers what UK firms actually need to do.
Who is in scope
DORA applies to:
- Banks and credit institutions
- Investment firms and asset managers
- Insurance companies and reinsurers
- Payment institutions and e-money institutions
- Crypto-asset service providers
- Central counterparties and trading venues
- Third-party ICT providers to the above (including cloud providers)
If your firm falls into any of these categories and serves EU customers, DORA applies. The threshold is not size — it is activity.
The five pillars of DORA
DORA is structured around five requirements:
1. ICT risk management
You must have a documented ICT risk management framework. This includes:
- An ICT risk assessment, updated annually
- ICT policies and procedures
- Asset inventory and classification
- Access control and identity management
- Network security and segmentation
- Data encryption and backup
For a small fintech, this maps closely to ISO 27001. If you are already certified, the gap is small.
2. ICT-related incident management
You must:
- Classify incidents by severity (minor, major, critical)
- Report major incidents to your lead regulator within 4 hours
- Submit an intermediate report within 72 hours
- Submit a final report within 1 month
- Maintain an incident register
The 4-hour clock starts when you classify the incident as major, not when you discover it. This means you need a clear classification procedure and an on-call escalation path.
3. Digital operational resilience testing
You must conduct:
- Annual vulnerability assessments
- Annual network security assessments
- Biennial penetration testing (or more frequent for critical firms)
- Threat-led penetration testing every 3 years for critical firms
The testing must be proportionate to your size and risk profile. A 20-person fintech is not expected to run the same testing programme as a global bank.
4. ICT third-party risk management
You must:
- Maintain a register of all ICT third-party providers
- Assess the criticality of each provider
- Include security requirements in contracts
- Monitor provider performance and incidents
- Have exit plans for critical providers
This is where most small fintechs struggle. You may have 20–30 SaaS providers (cloud, email, CRM, support, analytics) and no documentation of which ones are critical.
5. Information sharing
DORA encourages voluntary sharing of cyber threat information between financial entities. This is not mandatory for small firms.
The UK angle: similar rules, different name
The UK is not implementing DORA directly. Instead, it is updating the Financial Services and Markets Act and PRA/FCA rules to achieve similar outcomes:
- Operational resilience: Firms must identify important business services and set impact tolerances
- Third-party risk: The PRA SS2/13 and EBA guidelines on outsourcing already cover much of DORA’s third-party requirements
- Incident reporting: The FCA already requires notification of operational incidents
If you are a UK-only firm, you do not need DORA compliance. But if you have EU operations, you need both.
Practical checklist for a small fintech
Month 1:
- Confirm DORA scope with legal counsel
- Map existing ISO 27001 / SOC 2 controls to DORA requirements
- Create an ICT asset and vendor inventory
Month 2:
- Update incident response procedures with DORA classification and reporting timelines
- Review all third-party contracts for security clauses
- Schedule penetration testing if not already done
Month 3:
- Conduct a gap assessment against DORA’s five pillars
- Write missing policies (ICT risk management, incident classification, third-party risk)
- Train staff on new procedures
Month 4:
- Submit documentation to the lead regulator if required
- Set up ongoing monitoring and annual review calendar
At Metaluxo we run DORA readiness assessments for fintechs and financial services firms, typically delivering a gap report and remediation roadmap in four weeks. If you are unsure whether DORA applies to you or what you need to do, book a free 30-minute consultation and we will tell you exactly where you stand.
Common questions
Does DORA apply to UK companies?
DORA is EU law, but UK firms with EU operations, EU customers, or EU subsidiaries must comply. The UK is implementing similar rules through the Financial Services and Markets Act.
What is the DORA incident reporting deadline?
Major incidents must be reported to the lead regulator within 4 hours of classification, with follow-up reports at 72 hours and 1 month.
Do fintech startups need to comply with DORA?
If you are a crypto-asset service provider, a payment institution, or an investment firm with EU operations, yes. Pure UK B2C fintechs may be out of scope.