Skip to content
  • Services
    • Fintech Strategy
    • Fintech Regulation
    • Fintech Sourcing
    • Strategy Expert advice on markets, products and funding
    • Regulation Secure licenses and meet compliance obligations
    • Solutions Source reliable financial and technology solutions
  • Sectors
    • Payments
    • eCommerce
    • FinTechs
    • Crypto Assets
    • Lenders
    • Banks
    • Private Equity
    • Governments
    • Payments Launch fast, grow volumes and reduce financial crime
    • eCommerce Secure processing, increase conversions and reduce cost
    • FinTechs Integrated commercial, technology, and funding plans
    • Crypto Assets Capture financial, technology and regulatory opportunities
    • Lenders Grow lending, reduce NPLs and automate processes
    • Banks Offer personalised CX, improve efficiency and agility
    • Private Equity Access FinTech deal flow and maximise returns
    • Governments Craft policy to generate investment and jobs
  • Resources
    • Case Studies
    • Financial Services Insights
    • FinTech Marketplace
    • Case Studies 20-year track record with world-class clients
    • Blog Stay ahead of the market with data and insights
    • FinTech Marketplace Understand financial and technology solutions
  • About
    • Management
    • Why Us
    • Contact
    • Management Meet our financial services experts
    • Why Us Discover our attributes and values
    • Contact Request a call today

Get started

Give us a call or fill in the form below and we will contact you. We endeavor to answer all inquiries within 24 hours on business days.

Edit Content

0 / 180
Financial Services Regulation

EU DORA: What Financial Firms and FinTechs Must Know

December 16, 2025 neilmathieson Comments Off on EU DORA: What Financial Firms and FinTechs Must Know
EU DORA
  • Regulation applies to 20,000 financial institutions in the EU from 17.01.2025.
  • Third-party ICT suppliers also in scope, regardless of location.
  • EU DORA creates new requirements for the security and resilience of ICT networks and systems.
  • 5 pillars of EU DORA have higher and more prescriptive requirements than previously.
  • Some exemptions apply and EU DORA is applied proportionately.

What is EU DORA?

The EU Digital Operational Resilience Act (EU DORA) became mandatory on 17.01.2025 and seeks to improve operational risk and business continuity in EU financial services.

With 70+ pages and hundreds of requirements, EU DORA creates a higher regulatory standard for managing information and communication technology (ICT), especially for FinTechs in scope for the first time.

Why does EU DORA matter?

Digital financial services have increased, driven by innovation, efficiency, and client demands, reaching 99% in locations such as Estonia.

In parallel, ICT-related risks have also increased significantly:

  • Cyber-attacks and ransomware
  • System outages and data breaches
  • Failures at outsourced ICT providers
  • Operational disruptions with cross-border impact

As risks increase, so financial systems and transactions require greater protection and resilience to remain trustworthy.

Who does EU DORA apply to?

  1. credit institutions
  2. payment institutions
  3. electronic money institutions
  4. account information service providers
  5. investment firms
  6. crypto-asset service providers 
  7. central securities depositories
  8. central counterparties
  9. trading venues
  10. trade repositories
  11. managers of alternative investment funds
  12. management companies
  13. data reporting service providers
  14. insurance and reinsurance undertakings
  15. insurance intermediaries, reinsurance intermediaries and ancillary insurance intermediaries
  16. institutions for occupational retirement provision
  17. credit rating agencies
  18. administrators of critical benchmarks
  19. crowdfunding service providers
  20. securitisation repositories

FinTechs such as core banking, payments, hosting and ICT solution providers are also in scope.

5 pillars of DORA?

The requirements of EU DORA are assessed using five pillars:

ICT Risk Management

What governance, systems, tools, and processes are used to identify, protect, detect, and recover from ICT-related risks.

Incident Reporting

Regulated entities must notify their national competent authorities of major ICT-related incidents and cyber threats.

Digital Operational Reslience Testing

Regular, advanced testing to ensure security, improve resilience and recovery procedures.

3rd Party Risk Management

Development of frameworks to identify and mitigate risks arising from 3rd party suppliers of ICT.

Information Sharing

Voluntary sharing of data about cyber threats and vulnerabilities to enhance system defences.

Proportionality in EU DORA

Financial entities and technology providers are required to implement EU DORA using the principle of proportionality, meaning they consider their size and overall risk profile, and the nature, scale and complexity of their services, activities and operations.

  • Banks
  • Crypto Assets
  • Fintechs
  • Lenders
  • Payments
neilmathieson

Post navigation

Previous
Next

Search

Categories

  • Capital Markets (2)
  • Financial Services (1)
  • Financial Services Regulation (2)
  • Financial Technology (8)

Recent posts

  • European Financial Centres
    European Financial Centres: Driving Economic Development
  • An elegant Sovereign Wealth Funds building
    Sovereign Wealth Funds: Moving Capital Markets
  • EU DORA
    EU DORA: What Financial Firms and FinTechs Must Know

Tags

Banks Crypto Assets eCommerce Fintechs Governments Lenders Payments Private Equity

Continue reading

European Financial Centres
Financial Services

European Financial Centres: Driving Economic Development

January 6, 2026 neilmathieson Comments Off on European Financial Centres: Driving Economic Development

Financial Services are significant in Europe, accounting for over 9% of economic output. London and Frankfurt

EU DORA
Financial Services Regulation

EU DORA: Regulators announce Critical ICT Third-Party Providers

December 14, 2025 neilmathieson Comments Off on EU DORA: Regulators announce Critical ICT Third-Party Providers

On 18.11.2025 the European Supervisory Authorities announced 19 information and communications companies as Critical Third-Party Providers (CTPPs) under DORA.

Upward view of modern offices in Tallinn, capital of fintech in Estonia.
Financial Technology

Fintech in Estonia: Europe’s Digital Finance Leader

December 11, 2025 neilmathieson Comments Off on Fintech in Estonia: Europe’s Digital Finance Leader

Estonia has 200-250 fintech companies. Key segments of the industry are Digital Lending, Payments, Neobanking, Crypto Assets and Regtech. Understand the environment, trends and key players.

Want to receive news and updates?


    Profit at the intersect of finance and technology.

    Services
    • Strategy
    • Regulation
    • Solutions
    Sectors
    • Payments
    • Ecommerce
    • FinTechs
    • Crypto Assets
    • Lenders
    • Banks
    • Private Equity
    • Governments
    Resources
    • Case Studies
    • Blog
    • FinTech Marketplace
    • FinServ Marketplace
    About
    • Management
    • Why Us
    • Vacancies
    • Contact

    © 2005-2026. All Rights Reserved.

    • Terms & Conditions
    • Privacy Policy