DORA’s long arm: why US finance faces EU resilience rules

DORA

The EU’s Digital Operational Resilience Act (DORA) has stopped being a purely European concern.

Since becoming enforceable on 17 January 2025, the regulation has steadily pulled US financial institutions into its orbit, and risk teams across New York, Chicago and San Francisco are now being asked by European counterparts to evidence operational resilience controls that many have never had to demonstrate before, said AscentAI.

AscentAI recently discussed DORA for US financial firms, and who’s impacted and what’s at stake.

As Risk Publishing put it in June 2026, “The Digital Operational Resilience Act was no longer a European problem.”

Adopted in 2022, DORA requires financial institutions to withstand, respond to and recover from information and communication technology (ICT) disruptions. Crucially, its scope goes well beyond cybersecurity. IT system failures, power outages and third-party provider incidents all fall within its remit — anything capable of disrupting a financial entity’s digital operations.

The regulation was designed to replace a patchwork of inconsistent, often non-binding EU guidelines that varied by member state and sector, creating a single framework across all EU states and financial sectors. Its extraterritorial reach captures a broad range of US organisations: banks with EU subsidiaries, cloud providers serving EU banks, FinTechs with EU clients, insurers with EU reinsurance arrangements and asset managers running EU funds.

These firms must comply with DORA’s five pillars: ICT risk management, incident reporting to competent authorities within prescribed timelines, resilience testing (including threat-led penetration testing at least every three years for significant entities), third-party risk management via a Register of Information, and voluntary cyber threat intelligence sharing.

Recent survey data suggests US firms’ readiness is lacking, particularly around resilience testing and third-party risk. Organisations already operating under ISO 27001, NIST CSF or SOC 2 have a head start, with an estimated 70-80% of Pillar 1 requirements already addressed for those certified to ISO 27001 or aligned to NIST CSF 2.0.

FinTechs with less mature GRC capabilities face a steeper climb. Recommended steps include determining which DORA provisions apply (smaller organisations may qualify for a simplified framework under Article 16), performing a gap assessment, developing a documented ICT risk management framework with board-level governance, building a third-party register, preparing for regular testing, establishing incident reporting processes and training staff.

The penalties sharpen the incentive. Financial entities face fines of up to 2% of total annual worldwide turnover for ICT risk management or incident reporting failures, alongside public disclosure of breaches and suspension of ICT service agreements. Critical third-party ICT providers risk fines of up to €5m per entity or €500,000 per individual, plus daily penalty payments of 1% of average daily worldwide turnover for up to six months. Senior managers can be held personally liable for up to €1m each.

For US institutions serving EU customers, DORA now sits alongside FINRA and SEC obligations as a core part of the compliance stack. Finance operates across borders — and so does this regulation.

Read the daily RegTech news

Copyright © 2026 RegTech Analyst

Enjoyed the story? 

Subscribe to our weekly RegTech newsletter and get the latest industry news & research

Copyright © 2018 RegTech Analyst

Investors

The following investor(s) were tagged in this article.