Digital Operational Resilience Act (DORA)
Cryptography and PKI for EU Financial Entities
| Region | European Union directly applicable in all EU member states; extends to ICT third-party providers regardless of where they are based) |
| Applicability | Financial Entities: banks, insurers, investment firms, payment and e-money institutions, crypto-asset service providers, trading venues, and central counterparties — roughly 22,000 entities across 20 categories Critical ICT Third-Party Providers (CTPPs): cloud and technology providers designated for direct EU oversight, including major hyperscalers designated in November 2025 Management Bodies: executives who approve and bear ultimate responsibility for the ICT risk management framework |
| Relevant sections | Article 9: Protection and prevention — strong authentication and cryptographic key protection RTS Article 6: Encryption and cryptographic controls policy RTS Article 7: Cryptographic key management across the full lifecycle Articles 28–30: ICT third-party risk management and the Register of Information |
Overview
The Digital Operational Resilience Act (Regulation (EU) 2022/2554) is the EU’s directly applicable regulation harmonizing ICT risk management across the financial sector. It entered into force on January 16, 2023, and has been applied since January 17, 2025, with no national transposition required and no further transitional periods available.
DORA organizes obligations into five pillars: ICT risk management, incident reporting, digital operational resilience testing, ICT third-party risk management, and information-sharing arrangements. Article 9 requires financial entities to implement strong authentication mechanisms and protection measures for cryptographic keys, and the accompanying Regulatory Technical Standards go further: Article 6 requires a documented, risk-based policy on encryption and cryptographic controls covering data at rest, in transit, and in use, while Article 7 requires formal cryptographic key lifecycle management, including a register of certificates and certificate-storing devices and prompt renewal ahead of expiry.
Why it matters
DORA applies directly to an estimated 22,000 financial entities across the EU, with fines reaching up to 10% of annual global turnover for the most serious infringements. Enforcement is intensifying rather than settling: national authorities began collecting annual Registers of Information on ICT third-party arrangements in 2025, and current estimates suggest only about half of in-scope institutions are fully compliant even after the application date has passed.
The regulation’s third-party reach is a defining feature. In November 2025, EU supervisory authorities designated the first Critical ICT Third-Party Providers subject to direct oversight, including major cloud platforms, meaning a financial entity’s cryptographic assurance now depends on evidence it can extract from its vendors, not only from its own environment.
How this maps to cryptography
DORA addresses cryptography through several interlocking control areas. The key areas with direct cryptographic implications are:
| Section | Function | What it says | Supporting Products |
| RTS, Article 6 | Encryption and Cryptographic Controls Policy | A documented, risk-based policy covering encryption of data at rest, in transit, and in use, tied to approved data classification and ICT risk assessment results. | Command |
| RTS, Article 7 | Cryptographic Key Lifecycle Management | Controls protecting keys through their full lifecycle against loss, unauthorized access, and disclosure, with documented replacement procedures for lost, compromised, or damaged keys. | EJBCA |
| RTS, Article 7(4)–(5) | Certificate and Key-Storing Device Register | A current register of every certificate and certificate-storing device supporting critical or important functions, with automated renewal well ahead of expiry. | Command |
| Article 9(4)(d) | Strong Authentication and Credential Protection | Certificate-based, phishing-resistant authentication mechanisms and protection of the cryptographic keys underpinning them. | EJBCA |
| Articles 28–30 | ICT Third-Party Cryptographic Assurance | A cryptographic component inventory that feeds vendor risk assessments and the contractual provisions required for ICT third-party agreements. | AgileSec |
| Articles 24–27; threat-led penetration testing | Resilience Testing of Cryptographic Assets | Certificate infrastructure and cryptographic controls included in the scope of digital operational resilience testing and TLPT for significant entities. | EJBCA / Command |
Audit readiness
Assessments and examinations, whether self-conducted, performed by a regulator, or reviewed by an independent assessor, focus on demonstrated evidence rather than policy statements alone. Key areas that examiners and assessors commonly probe:
- Encryption Policy Documentation: Has the organization developed and documented a policy on encryption and cryptographic controls tied to its data classification and risk assessment?
- Key Lifecycle Evidence: Can the organization demonstrate controls protecting cryptographic keys against loss, compromise, and unauthorized disclosure across their full lifecycle?
- Certificate and Key-Storing Device Register Currency: Is there an up-to-date register of certificates and certificate-storing devices for assets supporting critical or important functions?
- Authentication Standard Alignment: Are strong authentication mechanisms based on relevant standards, with cryptographic keys protected accordingly?
- Third-Party Cryptographic Due Diligence: Are ICT third-party providers, including CTPPs, assessed for the strength of their cryptographic practices as part of the Register of Information and contractual review?
- Resilience Testing Coverage: Does digital operational resilience testing, including TLPT where applicable, cover certificate infrastructure and cryptographic controls?
TAKE THIS TO MANAGEMENT
DORA has applied without exception since January 17, 2025, and it names cryptography directly: Article 9 and its supporting technical standards require a documented encryption policy and a managed key lifecycle, not a general commitment to “appropriate” security. Fines reach 10% of our global annual turnover, and roughly half the sector is still working through the gap between what they have documented and what they can actually demonstrate.
The third-party dimension is the one most likely to catch us out. Our cryptographic assurance now has to extend into our cloud and technology vendors’ environments, several of which are now directly overseen by EU authorities. If we cannot show a current certificate and key-storing device register alongside evidence of our vendors’ cryptographic practices, we cannot complete our Register of Information filing with confidence.


