Not legal advice
This page is an editorial cross-mapping intended for practitioner use. It is not legal advice and does not substitute for qualified counsel and for your firm's regulatory affairs team. National competent authorities and the European Supervisory Authorities (ESAs) publish authoritative guidance; always defer to those primary sources.
DORA in 60 seconds
DORA is a regulation (not a directive), so it applies directly without national transposition. It entered into force on 16 January 2023 and has been applicable since 17 January 2025. Its purpose is to impose a uniform ICT operational-resilience regime across the EU financial sector, covering governance, risk management, incident management, resilience testing, and third-party risk, with particular focus on ICT third-party service providers that are critical to the financial system.
Who it applies to
DORA applies to a broad range of "financial entities": credit institutions, payment institutions, e-money institutions, investment firms, crypto-asset service providers, central securities depositories, central counterparties, trading venues, trade repositories, managers of alternative investment funds, UCITS management companies, data reporting service providers, insurance and reinsurance undertakings, insurance intermediaries, institutions for occupational retirement provision, credit rating agencies, administrators of critical benchmarks, crowdfunding service providers, securitisation repositories, and ICT third-party service providers themselves.
If your firm is supervised in the EU financial sector, assume DORA applies and verify with your regulatory affairs team.
The five pillars
- ICT risk management (Articles 5 to 16)
- ICT incident management and reporting (Articles 17 to 23)
- Digital operational resilience testing (Articles 24 to 27)
- ICT third-party risk management (Articles 28 to 44)
- Information-sharing arrangements (Articles 45 to 49)
Four of the five pillars have direct NHI implications.
ICT risk management × NHI (Articles 5 to 16)
Article 9 requires financial entities to implement "ICT security policies, procedures, protocols and tools" aimed at preserving the availability, authenticity, integrity and confidentiality of data. Article 9(4) specifically references:
- Identity management and access control
- Cryptography and encryption
- Monitoring and logging
| DORA requirement | NHI control interpretation |
|---|---|
| Identity management (Art. 9(4)(d)) | NHI inventory. Ownership records. Lifecycle processes. Distinct from human-identity controls but subject to the same rigour. |
| Access control (Art. 9(4)(d)) | Least-privilege enforcement on NHIs. Periodic access review. Just-in-time elevation where practical. |
| Cryptography (Art. 9(4)(c)) | Certificate lifecycle management. Key management. Secrets management. Workload identity where feasible. |
| Monitoring and logging (Art. 9(4)(e)) | Behavioural monitoring on NHIs. Audit logging of NHI authentication and privileged actions. Retention consistent with regulatory expectations. |
ICT third-party risk management × NHI (Articles 28 to 44)
DORA treats ICT third-party risk as its own pillar, with more detail than NIS2 provides. Financial entities must maintain a register of ICT third-party service arrangements (Article 28) and apply specific contractual safeguards (Article 30). The ESAs have issued regulatory technical standards (RTS) providing more detail.
For NHI, this is where post-Salesloft/Drift governance becomes compliance-grade:
- Register coverage. OAuth integrations and SaaS-to-SaaS connections supporting ICT-supported functions should be reflected in the Article 28 register, with classification by criticality.
- Contractual obligations. Article 30 specifies mandatory contractual terms, service description, data location, cooperation on incidents, termination rights, reporting obligations. Your contracts with SaaS providers holding OAuth tokens that grant access to financial-system data need to reflect these.
- Concentration risk. DORA pays explicit attention to concentration risk (Article 29). A single SaaS vendor holding tokens across multiple critical integrations is an accumulated-risk concern.
- Critical ICT third-party service providers (CTPPs). DORA creates an oversight regime for service providers designated as critical at EU level (Articles 31 to 44). Expect ongoing supervisory engagement with designated CTPPs.
ICT incident reporting × NHI (Articles 17 to 23)
DORA prescribes a structured incident-reporting regime with timelines. For major ICT-related incidents (defined in Article 3(8) and the associated RTS), reporting timelines are:
- Initial notification shortly after classification (specific timing per RTS)
- Intermediate report
- Final report with root-cause analysis
Operational implication for NHI: a compromise traced to an NHI (e.g. leaked credential, OAuth token abuse, service-account privilege escalation) that produces an impact meeting the major-incident threshold will trigger DORA reporting. Incident response needs to capture NHI-specific forensic artefacts, credential age, last rotation, ownership, scope of privileges, as part of the root-cause narrative.
Operational resilience testing × NHI (Articles 24 to 27)
DORA requires a testing programme proportionate to the entity's size and risk profile, including advanced threat-led penetration testing (TLPT) for larger or systemically important firms. TLPT exercises, conducted under TIBER-EU-aligned frameworks, will frequently exploit NHI paths, since that is what current attackers exploit. Test scope and remediation commitments should therefore include NHI-specific scenarios.
What evidence to keep
Practical artefacts your DORA-in-scope firm should be able to produce on request:
- Current NHI inventory with ownership, criticality classification, and last-review date
- Credential-age and rotation KPIs over time
- OAuth integration register with criticality, scopes granted, contract references
- NHI-related incident log with post-mortems and control changes
- Access-review evidence for high-privilege NHIs
- Board-level reporting on NHI programme status
- Third-party ICT register covering SaaS providers holding NHI credentials
Primary sources
- DORA regulation: eur-lex.europa.eu/eli/reg/2022/2554/oj
- ESA regulatory technical standards (ICT risk management, incident reporting, TLPT, third-party register)
- National competent authority guidance (e.g. BaFin in Germany, AMF in France, Central Bank of Ireland)