# DORA × FINMA, Where the Regimes Overlap and Where They Don't

> DORA and FINMA compared: where the five DORA pillars and the FINMA circulars overlap, where they differ and how one programme can cover both.

- Source: https://www.sidd.swiss/en/insights/dora-finma-comparison/
- Language: en
- Published: 2026-05-24
- Last updated: 2026-05-24
- Author: Dr. Dr. Nino Jibuti
- Publisher: SIDD Institute for Data Protection and Data Security, a brand of Priverion GmbH, Zugerstrasse 32, 6340 Baar (ZG), Switzerland

## Introduction

DORA (Regulation (EU) 2022/2554) and the Swiss FINMA supervisory regime pursue the same goal: digital operational resilience in the financial sector. They differ markedly, however, in level of detail, sanctioning mechanics and tone of voice. Anyone advising Swiss financial entities with EU exposure must know both regimes in parallel, and above all where they converge, where they diverge, and where one materially overrides the other.

**This article covers:**

- The five DORA pillars and their FINMA counterparts.
- Detailed mapping FINMA Circular 23/01 (operational risk) ↔ DORA pillars 1-2.
- Detailed mapping FINMA Circular 18/03 (outsourcing) ↔ DORA pillar 4.
- Sanction systematics compared: the FINMA measures catalogue vs DORA fines.
- Three constellations in which DORA tightens the FINMA requirements.

Legal anchors are Regulation (EU) 2022/2554 with its 10 RTS/ITS, Federal Financial Market Supervisory Authority (FINMA) Circular 2023/1 "Operational Risks and Resilience – Banks," FINMA Circular 2018/3 "Outsourcing – Banks and Insurers," and the FINMA Supervisory Communication 05/2020 (cyber risks). Both regimes sit alongside Basel III (BCBS Principles for Operational Resilience, March 2021) and ISO/IEC 27001:2022.

## The five DORA pillars and their FINMA mirrors

A high-level comparison per DORA pillar:

- **Pillar 1, ICT risk management (Art. 5-16 DORA):** FINMA Circular 23/01 paras 8-65 (identify, protect, detect, respond, recover). High substantive overlap; FINMA principles-based, DORA more prescriptive via RTS/ITS.
- **Pillar 2, Incident handling and reporting (Art. 17-23 DORA):** FINMA Supervisory Communication 05/2020 plus 23/01 paras 49-58. FINMA requires reporting of material cyber incidents "without delay"; DORA imposes hard cascades (initial "without undue delay," intermediate 72h, final report one month).
- **Pillar 3, Resilience testing (Art. 24-27 DORA):** FINMA 23/01 paras 59-65 requires regular testing, including advanced threat/attack tests for Category 1-2 banks. DORA requires TLPT at least every three years for *significant* entities with prescribed methodology.
- **Pillar 4, ICT third-party risk (Art. 28-44 DORA):** FINMA Circular 18/03 (outsourcing). High overlap in strategy, contracting, sub-outsourcing. DORA adds the Register of Information, function classification, exit strategy and CTPP oversight.
- **Pillar 5, Information sharing (Art. 45 DORA):** No direct FINMA counterpart. Voluntary channels in Switzerland via the Federal Office for Cyber Security (BACS / NCSC) and sector associations (SwissBanking, SVV).

Overall, around 70-80% of DORA requirements can be mapped onto existing FINMA duties, the remaining 20-30% are exactly the operational sticking points: reporting flows, RoI, TLPT methodology, CTPP implications.

## FINMA Circular 23/01 versus DORA pillars 1-2

FINMA Circular 2023/1 entered into force on 1 January 2024 and replaced the prior 08/21. It establishes a modern operational risk and resilience framework for all banks (Categories 1-5). The key alignments with DORA pillars 1 and 2:

- **Governance:** FINMA explicitly requires management body responsibility (paras 8-9); DORA does the same (Art. 5(2)). Documentation requirements are similar.
- **Risk management framework:** FINMA requires risk appetite, risk capacity, inventory of critical functions (paras 22-30). DORA requires a documented risk management framework (Art. 6 DORA) plus annual review.
- **ICT lifecycle:** FINMA paras 38-48 (ICT risks). DORA Art. 8-14 is markedly more granular (identification, protection, detection, response and recovery, learning, communication).
- **Impact tolerances:** FINMA paras 31-37 require impact tolerances for disruption of critical functions. DORA refers to continuity plans with RTO/RPO.
- **Incident handling and reporting:** FINMA Supervisory Communication 05/2020 requires reporting of material cyber incidents. DORA Art. 19 imposes a three-stage report to the competent authority.

Convergence is high enough that a FINMA-compliant institution can build DORA pillar 1 on top of its 23/01 foundation. Recommendation: build both frameworks as one risk management system with a shared policy hierarchy and a dual reporting layer.

## FINMA Circular 18/03 versus DORA pillar 4

FINMA Circular 2018/3 "Outsourcing – Banks and Insurers" has long been the Swiss reference for outsourcing. It remains applicable but is increasingly overridden in substance by DORA pillar 4. Key alignments and differences:

- **Strategy:** FINMA paras 16-21 require an outsourcing strategy. DORA Art. 28(2) does the same but adds explicit function classification (critical/important vs other).
- **Due diligence:** FINMA paras 27-32; DORA Art. 28(4)-(5) with concrete criteria.
- **Contract drafting:** FINMA paras 38-49 on mandatory contract content; DORA Art. 30 with markedly more mandatory items (EU supervisor audit rights, service levels with KPIs, exit strategy, sub-outsourcing approval).
- **Register:** FINMA paras 33-37 require an outsourcing register. DORA Art. 28(3) requires the Register of Information using the ESA template (Commission Implementing Regulation (EU) 2024/2956), substantially broader and reported annually to the competent authority.
- **Sub-outsourcing:** FINMA para 23 with control duty; DORA Art. 29 with explicit prior approval for sub-outsourcing of critical functions.
- **CTPP oversight:** No FINMA counterpart; DORA Art. 31 ff. with direct ESA oversight of critical third parties.

A pragmatic solution is to expand the FINMA outsourcing register into a DORA-compliant RoI, with a FINMA-relevant view (outsourcing only) and a DORA-relevant view (all ICT services, not only outsourcing).

## Sanction systematics compared

The sanction architectures differ substantively:

- **FINMA:** The FINMA measures catalogue under Art. 31 ff. FINMASA is broad but does not include direct fines against institutions. The authority has declaratory and order proceedings, prohibition from practising a profession (Art. 33 FINMASA, against natural persons up to five years), prohibition from performing an activity (Art. 33a FINMASA), disgorgement (Art. 35 FINMASA), licence withdrawal (Art. 37 FINMASA). Publication of a supervisory ruling (Art. 34 FINMASA, "naming and shaming") is its own instrument.
- **DORA:** Art. 50 DORA refers to national sanctions regimes of the Member States. These must be "effective, proportionate and dissuasive." For CTPPs, DORA itself provides for periodic penalty payments up to 1% of average daily worldwide turnover (Art. 35(6)) imposable daily for up to six months, cumulatively up to 180% of daily turnover or roughly 50% of annual turnover.

In practice this means: Swiss institutions with EU exposure face dual sanction risk, FINMA measures in Switzerland, EU Member State sanctions for the EU entity, plus potential CTPP fines for group-affiliated ICT providers. Integrated risk governance with documented approval paths is therefore not just compliance tooling but active liability management.

## Three constellations where DORA tightens

Where DORA effectively overrides the FINMA requirements:

- **1. Contract standard for ICT third parties:** Art. 30 DORA imposes markedly more extensive mandatory clauses than FINMA Circular 18/03. A Swiss asset manager with a German subsidiary must have all of the subsidiary's ICT contracts compliant with Art. 30 DORA, which often triggers renegotiation with cloud providers, SaaS vendors and IT service providers.
- **2. Register of Information:** The DORA RoI is substantially broader (around 100 data points per contract on average versus around 20 in the FINMA register), requires a function-to-supplier mapping and annual reporting to the ESA (DE: BaFin/Bundesbank, LU: CSSF, AT: FMA).
- **3. TLPT methodology:** FINMA requires regular advanced testing but leaves methodology open. DORA references TIBER-EU and expressly requires segregation of red team, threat intelligence provider and white team. The test experience, including supervisor reporting, is significantly more structured.

For purely Swiss institutions without EU exposure, FINMA duties remain decisive. But anyone with or planning EU exposure should raise FINMA compliance to DORA level immediately, more sustainable than a FINMA-minimal setup with a later DORA upgrade.

## Practical integration in one programme

A proven integration architecture for a Swiss institution with an EU subsidiary:

1. **One risk management framework, two reporting paths:** A single methodology (identify, assess, treat, monitor) with dual reporting, FINMA report for the Swiss supervisor, DORA report for the EU authority.
2. **One policy hierarchy:** Group policy with shared principles, plus FINMA annex and DORA annex for jurisdiction-specific items.
3. **One consolidated RoI:** Extended FINMA outsourcing register that absorbs all DORA data points; filtered for each authority.
4. **One incident response platform:** Single classification, then automated generation of notification templates per authority (FINMA, ESA, BACS / NCSC, BSI, FDPIC / EDÖB, etc.).
5. **One testing programme:** Consolidated penetration test and TLPT programme covering both supervisory expectations.
6. **One governance structure:** A DORA-FINMA SteerCo with CRO, CIO, CISO, compliance and legal representation, at least quarterly, escalation to the management body.

This integration demonstrably reduces compliance cost by 25-40% versus two parallel programmes, largely through shared methodology, shared tooling investment and consolidated reporting.

## How SIDD supports you

SIDD supports Swiss financial actors in the integrated build-out of DORA and FINMA compliance. We start with a dual gap analysis (DORA pillars 1-5 and FINMA Circulars 23/01 and 18/03 plus supervisory communications), identify convergence and divergence, and deliver a single programme design that serves both supervisors efficiently.

For implementation we run programme management, design the integrated risk management framework, build the Register of Information (FINMA filter and DORA filter in parallel) and support contract renegotiation. For Threat-Led Penetration Testing under the TIBER methodology and classic penetration tests, see [penetration testing](https://www.sidd.swiss/en/services/penetration-test). For ongoing ICT risk management we can place an [external CISO or ISO](https://www.sidd.swiss/en/services/vciso).

Book a first conversation at [/kontakt](https://www.sidd.swiss/en/contact) or request a fixed-price quote for the dual gap analysis at [/offerte](https://www.sidd.swiss/en/quote). For ongoing mandates we recommend a quarterly effectiveness review where we recalibrate the integrated framework against updated regulatory expectations, including ESA Q&A and FINMA supervisory communications.

---

This document is the Markdown rendition of the page linked above. Please cite the HTML URL.
