Keyfactor Tech Days 2027 – Be Part of The Trust Security Conference in San Diego Register now!

Digital Operational Resilience Act (DORA)

Cryptography and PKI for EU Financial Entities

Updated: August 24, 2026
RegionEuropean Union directly applicable in all EU member states; extends to ICT third-party providers regardless of where they are based)
ApplicabilityFinancial Entities: banks, insurers, investment firms, payment and e-money institutions, crypto-asset service providers, trading venues, and central counterparties — roughly 22,000 entities across 20 categories Critical ICT Third-Party Providers (CTPPs): cloud and technology providers designated for direct EU oversight, including major hyperscalers designated in November 2025 Management Bodies: executives who approve and bear ultimate responsibility for the ICT risk management framework
Relevant sectionsArticle 9: Protection and prevention — strong authentication and cryptographic key protection RTS Article 6: Encryption and cryptographic controls policy RTS Article 7: Cryptographic key management across the full lifecycle Articles 28–30: ICT third-party risk management and the Register of Information

Overview

The Digital Operational Resilience Act (Regulation (EU) 2022/2554) is the EU’s directly applicable regulation harmonizing ICT risk management across the financial sector. It entered into force on January 16, 2023, and has been applied since January 17, 2025, with no national transposition required and no further transitional periods available.

DORA organizes obligations into five pillars: ICT risk management, incident reporting, digital operational resilience testing, ICT third-party risk management, and information-sharing arrangements. Article 9 requires financial entities to implement strong authentication mechanisms and protection measures for cryptographic keys, and the accompanying Regulatory Technical Standards go further: Article 6 requires a documented, risk-based policy on encryption and cryptographic controls covering data at rest, in transit, and in use, while Article 7 requires formal cryptographic key lifecycle management, including a register of certificates and certificate-storing devices and prompt renewal ahead of expiry.

Why it matters 

DORA applies directly to an estimated 22,000 financial entities across the EU, with fines reaching up to 10% of annual global turnover for the most serious infringements. Enforcement is intensifying rather than settling: national authorities began collecting annual Registers of Information on ICT third-party arrangements in 2025, and current estimates suggest only about half of in-scope institutions are fully compliant even after the application date has passed.

The regulation’s third-party reach is a defining feature. In November 2025, EU supervisory authorities designated the first Critical ICT Third-Party Providers subject to direct oversight, including major cloud platforms, meaning a financial entity’s cryptographic assurance now depends on evidence it can extract from its vendors, not only from its own environment.

How this maps to cryptography 

DORA addresses cryptography through several interlocking control areas. The key areas with direct cryptographic implications are:

SectionFunctionWhat it saysSupporting Products
RTS, Article 6Encryption and Cryptographic Controls PolicyA documented, risk-based policy covering encryption of data at rest, in transit, and in use, tied to approved data classification and ICT risk assessment results.Command
RTS, Article 7Cryptographic Key Lifecycle ManagementControls protecting keys through their full lifecycle against loss, unauthorized access, and disclosure, with documented replacement procedures for lost, compromised, or damaged keys.EJBCA
RTS, Article 7(4)–(5)Certificate and Key-Storing Device RegisterA current register of every certificate and certificate-storing device supporting critical or important functions, with automated renewal well ahead of expiry.Command
Article 9(4)(d)Strong Authentication and Credential ProtectionCertificate-based, phishing-resistant authentication mechanisms and protection of the cryptographic keys underpinning them.EJBCA
Articles 28–30ICT Third-Party Cryptographic AssuranceA cryptographic component inventory that feeds vendor risk assessments and the contractual provisions required for ICT third-party agreements.AgileSec
Articles 24–27; threat-led penetration testingResilience Testing of Cryptographic AssetsCertificate infrastructure and cryptographic controls included in the scope of digital operational resilience testing and TLPT for significant entities.EJBCA / Command

Audit readiness

Assessments and examinations, whether self-conducted, performed by a regulator, or reviewed by an independent assessor, focus on demonstrated evidence rather than policy statements alone. Key areas that examiners and assessors commonly probe:

  • Encryption Policy Documentation:  Has the organization developed and documented a policy on encryption and cryptographic controls tied to its data classification and risk assessment?
  • Key Lifecycle Evidence:  Can the organization demonstrate controls protecting cryptographic keys against loss, compromise, and unauthorized disclosure across their full lifecycle?
  • Certificate and Key-Storing Device Register Currency:  Is there an up-to-date register of certificates and certificate-storing devices for assets supporting critical or important functions?
  • Authentication Standard Alignment:  Are strong authentication mechanisms based on relevant standards, with cryptographic keys protected accordingly?
  • Third-Party Cryptographic Due Diligence:  Are ICT third-party providers, including CTPPs, assessed for the strength of their cryptographic practices as part of the Register of Information and contractual review?
  • Resilience Testing Coverage:  Does digital operational resilience testing, including TLPT where applicable, cover certificate infrastructure and cryptographic controls?