DORA has applied since 17 January 2025, but it does not set a single EU-wide €10 million/2% maximum fine for every financial entity or a universal €1 million personal fine for directors. The answer depends on the type of person, the obligation infringed and the applicable national sanction law. A separate EU mechanism allows periodic penalty payments against designated critical ICT third-party providers for failure to comply with specified oversight requests.
This guide explains how to distinguish those mechanisms and assemble the evidence needed for a supervisory response. Start with Regulation (EU) 2022/2554, Articles 35 and 46–54, then identify the competent national authority and sanction provisions for the entity concerned.
What Is the DORA Penalty Framework?
Articles 50–52 require Member States to provide effective, proportionate and dissuasive administrative penalties and remedial measures, subject to the Regulation’s conditions and any permitted criminal-law approach. Article 50 lists investigative and corrective powers, including access to relevant information, inspections, orders to cease non-compliant conduct and requirements to remedy practices. National law supplies important detail about available fines and procedures.
Consequently, a risk paper should not multiply a bank’s turnover by 2% and label the result “the DORA fine”. It should identify the financial entity’s licence, Member State, competent authority, national provision and the particular infringement. Record whether the rule applies to the legal entity, responsible individuals, or both. Where the national position has not been verified, leave the monetary maximum unresolved instead of borrowing a GDPR or NIS2 number.
The existence of a sanction power does not establish that it will be exercised in every case. Article 51 requires consideration of circumstances such as the nature and gravity of the infringement, responsibility, financial strength, benefits or losses avoided, cooperation, previous infringements and losses to third parties. A remediation plan can be relevant evidence; it is not a statutory immunity or a replacement for meeting an obligation.
Management-body responsibility
Article 5 places ultimate responsibility for ICT risk management on the management body. Day-to-day work can be assigned, but that assignment must not leave governance unattended. Evidence includes approved risk tolerance, budgets, challenge of unresolved weaknesses, review of continuity arrangements and relevant training.
Whether a particular director or manager faces a personal monetary sanction must be assessed under the applicable legal provisions and facts. Do not present management accountability as an automatic €1 million fine. Equally, do not assume that delegating operational work to a supplier or security team eliminates responsibility. The ICT risk management guide explains the controls that management should be able to substantiate.
Critical ICT Provider Penalty Payments
Direct oversight applies to providers designated as critical under Article 31, with an ESA assigned as Lead Overseer. It does not make every ICT supplier subject to the same direct oversight simply because it serves a bank. Check the designation and legal entity concerned; a familiar group or product name is insufficient.
Article 35(6) concerns failure to comply, wholly or partly, with specified requests for information, investigations or inspections, or reports on action taken in relation to recommendations. After the statutory period of at least 30 calendar days from notification of the relevant measures, the Lead Overseer can adopt the decision imposing a periodic payment to compel compliance.
The payment can be up to 1% of the provider’s average daily worldwide turnover in the preceding business year, imposed daily until compliance and for no more than six months following notification of the penalty decision. Article 35 does not add a general alternative €5 million figure. The actual decision, calculation base, start date, procedural rights and compliance outcome matter more than an illustrative annual-turnover multiplication.
Recommendations and follow-up are a different mechanism
Article 42 requires a critical provider to notify its intention to follow recommendations or provide a reasoned explanation for not doing so within 60 calendar days. The Lead Overseer communicates the information to the relevant financial-sector authorities. Failure to notify or an insufficient explanation can lead to public disclosure under the Article’s conditions.
The competent authorities consider the risks for financial entities using the service. As a last resort and under the statutory process, they may require suspension or termination of an arrangement. This is not the same as the Lead Overseer directly cancelling a customer’s contract. A financial entity needs its own documented response to relevant supplier risks and a credible third-party exit strategy.
Who Enforces DORA?
Article 46 allocates competence by type of financial entity. National authorities have the relevant roles for banking, securities, insurance, pensions, payments and other covered sectors; the ECB has specified responsibilities for credit institutions under the Single Supervisory Mechanism. Follow the actual allocation and reporting arrangements for the entity. The UK FCA and PRA are not EU DORA competent authorities.
The ESAs’ Lead Overseer mechanism concerns designated critical ICT providers. A provider’s direct oversight does not replace the financial customer’s due diligence, contract and ongoing monitoring duties. Keep two records where necessary: the supplier’s oversight status and the financial entity’s assessment of the service it uses.
When a group operates in several Member States or through different regulated subsidiaries, prepare an entity-by-entity authority map. Include the relevant licence, reporting contact, official portal and internal owner. A central group team can coordinate responses without assuming that one regulator’s request covers every group entity.
How DORA, GDPR and NIS2 Sanctions Interact
GDPR fines have their own tiers under Article 83, including €20 million or 4% of preceding-year worldwide annual turnover for the higher tier, whichever is higher for an undertaking. That is not a DORA maximum. A security incident can reveal separate problems under the two regimes, but the legal classification and sanction analysis must be performed separately.
Do not assume that maxima can simply be added together for a single event, or that the prohibition on double punishment never matters between regulatory frameworks. The facts, the conduct sanctioned, applicable procedural protections and case law must be assessed. Budgeting should distinguish remediation and business loss from a legally supported range of possible sanctions. The DORA/GDPR comparison helps map the underlying obligations without inventing an aggregate fine.
Under NIS2, Article 34 sets minimum levels for national maximum fines: at least €10 million/2% for essential entities and €7 million/1.4% for important entities, using the higher figure in each pair. DORA Article 1(2) and NIS2 Article 4 establish the relevant sector-specific interaction. Do not assume a bank is subject to an additional identical NIS2 sanction merely because the same incident affects networks.
Responding to a Supervisory Finding
Create a response file linked to the exact request or finding. Record the issuing authority, legal entity, legal basis, information requested, deadline, response owner and secure submission route. Confirm receipt internally and preserve the original request. If clarification is needed, seek it early while continuing the work that is clear.
For a missing register entry, trace the arrangement from procurement to the service owner, determine the applicable fields, correct the register and check whether similar omissions exist elsewhere. For an overdue remediation, show the original finding, approved plan, work completed, remaining dependency and revised delivery evidence. Avoid presenting a policy revision as proof that an operational control now works.
For an incident-reporting failure, retain occurrence, awareness, classification and submission timestamps separately. Explain who knew what, when the major-incident threshold was met, why any deadline was missed and what now prevents recurrence. Portal receipts, on-call records and decision logs are stronger evidence than a retrospective statement that everyone acted promptly.
Use independent review where the correction needs challenge. A restore-test defect, for example, should be closed by a comparable successful retest and business-owner confirmation of data integrity. The resilience testing guide explains how findings should feed back into the risk framework. Preserve open items honestly, with accountable owners and dates; a green dashboard does not resolve an untested dependency.
Is There a Grace Period or Predictable First-Fine Date?
DORA’s application date is not a general supervisory grace period. Neither a forecast that “first fines will arrive in late 2026” nor an assumed comparison with GDPR’s enforcement trajectory is a reliable basis for postponing work. Check an authority’s actual statement or decision and distinguish its scope from general commentary.
For ongoing compliance, prioritise material gaps using affected services, legal obligations, people or customers exposed, and the feasibility of interim controls. Address the core risk-management, reporting, testing and third-party requirements. Article 45 information-sharing arrangements are voluntary, so participation should not be presented as an additional compulsory pillar with the same status as mandatory reporting.
Questions to Resolve Before Quoting a Fine
- Which legal entity and regulatory category are involved?
- Which obligation and national sanction provision apply?
- Is the measure a fine, a periodic payment, a remediation order or an operational restriction?
- What is the relevant turnover measure and period, if applicable?
- What procedural stage has been reached, and is a published decision subject to appeal?
- Which evidence supports remediation, cooperation and the present control position?
If the organisation is assessing non-compliance costs, keep these legal questions separate from downtime, recovery, customer redress and supplier-transition costs. This produces a budget that can be reviewed and updated without treating an unsupported penalty figure as a fact.