Heads-up, European financial services firms. The Digital Operational Resilience Act (DORA), adopted on 16 January 2023, is set to go into effect on 17 January 2025. That is only 57 days away. DORA is a regulation specific to the financial services industry, which has been under siege from cybercriminals for years now, and whose data management and security practices have come under increasing scrutiny over the idea that a serious incident could result in widespread economic chaos. DORA compliance is an issue financial services firms need to take seriously. As the DORA website explains:
“DORA explicitly refers to [information and communication technology] ICT risk and sets rules on ICT risk-management, incident reporting, operational resilience testing and ICT third-party risk monitoring. This Regulation acknowledges that ICT incidents and a lack of operational resilience have the possibility to jeopardise the soundness of the entire financial system, even if there is ‘adequate’ capital for the traditional risk categories.”
Following the regulation’s adoption, and with the goal of establishing precise and consistent guidelines across all sectors of the financial services industry, the European Banking Authority (EBA), European

DORA Compliance: someone had to do it.
Insurance and Occupational Pensions Authority (EIOPA), and European Securities and Markets Authority (ESMA) all clarified their individual applicable technical standards to help eliminate confusion.
Rigorous Criteria, Stiff Penalties
DORA compliance sets rigorous criteria for the internal and external digital resources that financial services rely on for their IT operations. That means organizations will not only be held responsible for their own standards and practices, but will also be expected to conduct the due diligence necessary to provide “a clear and complete description of all functions and ICT services to be provided by the ICT third-party service provider.”
For those organizations that have not yet examined their security and data management practices, taken the time to map out their digital supply chains, and undergo a thorough risk assessment—time is running out. And when the deadline arrives, there will be a price for failure to comply. Much like the financial penalties under Europe’s General Data Protection Regulation (GDPR), fines levied for DORA violations can be substantial as they are proportionate to the size of the organization. In its summary of DORA, law firm Grant Thornton says that:
“The European Supervisory Authorities (ESAs) have the power to impose fines for noncompliance. Firms that violate DORA’s requirements face fines of up to two percent of their total annual worldwide turnover, and an individual faces a maximum fine of 1,000,000 euro.
“Third-party providers designated as critical by the ESAs face even higher fines for noncompliance— up to 5,000,000 euro or, for an individual, a maximum fine of 500,000 euro. If a financial entity fails to report a major ICT-related incident or threat, the ESAs can also impose a fine.”
Fortunately, as we observed earlier this year, the number of companies that have inquired about our capabilities as a managed file transfer platform consistent with DORA’s strict standards, it seems many have taken DORA compliance seriously.
Trusted to Support Compliance
Coviant Software is well-versed in what it takes to provide a secure, managed file transfer (MFT) platform that supports our customers’ regulatory compliance goals. For more than two decades, we have been working with enterprises in highly regulated industries, including financial services, to keep their sensitive data transfers secure. Our Diplomat MFT platform is focused specifically on securing all aspects of the file transfer process, and as far as that function is involved in DORA compliance, we’ve got it locked down.
Security and resiliency in managed file transfer comes through building a secure-by-design product that relies on secure protocols like SFTP, automated encryption management, and complete visibility into the file transfer process—and capturing that information automatically as a safeguard should a security audit be necessary. To prove compliance, you need to provide evidence of compliance. Diplomat MFT does that automatically. And since many of our customers rely on Diplomat MFT to help them maintain compliance programs for regulations like HIPAA and GDPR, we are confident in our ability to support DORA compliance, too.
DORA’s Five Pillars
At its core, DORA is meant to ensure European financial services organizations have a consistent standard for security and operational resilience that helps minimize the risk of economic chaos in the event of a cyberattack or other incident that could disrupt the flow of financial transactions. DORA defines five pillars on which organizations must build their compliance programs, including:

The Deadline for DORA compliance is January 17, 2025.
-
Set-up and maintain resilient ICT systems and tools that minimize the impact of ICT risk.
-
All sources of ICT risks should be continuously identified in order to set-up protection and prevention measures.
-
A prompt detection of anomalous activities should be established.
-
Dedicated and comprehensive business continuity policies and disaster and recovery plans should be in place, ensuring a prompt recovery after an ICT-related incident.
-
Establish mechanisms to learn and evolve both from external events as well as the entity’s own ICT incidents.
Many financial services organizations already maintain secure and resilient digital operations based on existing industry-specific frameworks such as those available through the Basel Committee, U.S. Federal Reserve, and Bank of England. It is still important for those institutions to evaluate their compliance programs against provisions specific to DORA. Global consulting firm PwC warns that DORA contains “a very specific set of criteria, templates and instructions” for managing cyber risks, and overlooking those criteria could put firms at risk of being found non-compliant.
It’s also important to recognise that DORA compliance hinges on maintaining a secure network of third-party service providers, and so ensuring trading partners and the digital supply chain security is vital. Establishing standards for file sharing as a condition for doing digital business is not unprecedented, and Diplomat MFT is used by banks and other commercial enterprises for file sharing where file and transmission encryption are required.
DORA Compliant File Transfers
If you are looking for a file transfer solution that is secure and able to conform with DORA requirements, or if you need to replace an existing solution that is unreliable or unsecure, Coviant Software can help. We have a twenty-year track record of secure, reliable operation and rock-solid customer service. Furthermore, our Diplomat MFT product is backed by the industry’s best customer and technical service, and we offer Diplomat MFT at an ethical value that is a fraction of what the big brands charge.
A thorough DORA compliance program should be advised and implemented by credentialed experts, whether in-house or by a third-party. When that plan is in place, Coviant Software is ready to make sure your file transfers are managed securely and in a manner consistent with your needs. You can even test Diplomat MFT for free so that you have confidence in its performance. Contact us for more information, to walk through a live demonstration, or simply download a free trial.
