DORA, Operational Resilience Duties for Swiss Financial Services

6 min readLast updated By Dominic Staiger

Introduction

Regulation (EU) 2022/2554 (DORA) has applied directly across the EU since 17 January 2025 and establishes a harmonised operational resilience regime for the financial sector. It addresses 21 categories of financial entities, from banks and insurers to investment firms, fund managers, crypto-asset providers, central counterparties and trading venues, plus critical ICT third-party providers (CTPPs), which fall under direct EU supervision by the ESAs. Swiss financial firms must work out where DORA hits them directly, where it reaches through group channels, where it enters via FINMA practice, and where FINMA Circular 23/01 already covers the ground.

This guide structures the DORA world for Swiss houses:

  • The five DORA pillars at a glance
  • ICT risk management and governance (Art. 5–14)
  • Incident reporting (Art. 17–23)
  • Threat-led penetration testing (Art. 26–27)
  • ICT third-party risk and Register of Information (Art. 28–30)
  • Interface with FINMA Circular 23/01 and Supervisory Communication 03/2024

We mark throughout whether the duty in question applies to Swiss houses directly, by contract pull-through or as a de-facto industry standard.

The five DORA pillars

DORA is structured around five pillars. They drive the logic of all the regulatory technical standards (RTS) and implementing technical standards (ITS):

  1. ICT risk management (Art. 5–16): governance, strategy, identification, protection, detection, response and recovery. The management body is explicitly accountable (Art. 5(2)). A simplified regime for micro-enterprises applies under Art. 16.
  2. ICT-related incident management and reporting (Art. 17–23): classification by severity (number of clients, reputational loss, data loss, duration, geographical reach, economic loss); staggered reporting (initial, intermediate, final).
  3. Digital operational resilience testing (Art. 24–27): baseline testing programme plus enhanced threat-led penetration testing (TLPT) for significant institutions every three years.
  4. ICT third-party risk (Art. 28–44): risk-based outsourcing governance, contractual minimum content (Art. 30(2) and (3)), Register of Information, concentration risk, substitutability, exit strategies, EU supervision over critical providers (CTPPs).
  5. Information and intelligence sharing (Art. 45): voluntary, secured sharing of cyber threat intelligence within trusted communities.

These pillars are not independent, reporting (pillar 2) feeds TLPT scenario selection (pillar 3), the ICT risk inventory (pillar 1) underpins the Register of Information (pillar 4), and intelligence sharing (pillar 5) feeds detection and response (pillar 1).

ICT risk management and governance

Art. 5 DORA requires an ICT risk management strategy approved and overseen by the management body. Specifically, the management body must:

  • define ICT risk appetite and a corresponding limit system
  • prioritise ICT investments through a resilience lens
  • monitor the outsourcing strategy and concentration risk
  • receive and document reporting at least annually
  • participate in training actively and demonstrably

Art. 6 requires a documented ICT risk framework with ICT security policy, business continuity plan, ICT emergency plan and recovery plan. Articles 8–14 detail the ICT risk management lifecycle steps: identification (full inventory of all ICT assets and their dependencies, classification of critical functions), protection and prevention, detection (continuous monitoring), response and recovery, learning and evolving, communication.

Operationally this means: without a modern IT asset inventory, a documented IAM, centralised logging, a tested BCM and a rehearsed incident response structure, Art. 5–14 is not satisfiable. For many Swiss wealth managers and FinTechs this is by far the largest investment track of the next 18 months.

Incident reporting under Art. 17–23

DORA establishes a harmonised incident reporting regime for ICT-related incidents and, voluntarily, for significant cyber threats. Classification under Art. 18 uses:

  • number and importance of affected clients
  • duration and geographical reach
  • data loss (availability, authenticity, integrity, confidentiality)
  • impact on critical services and reputational loss
  • economic impact

If the thresholds set by RTS are exceeded, the incident counts as major. Reporting then follows the staggered model:

  1. Initial notification: within 4 hours of classification as major, at the latest 24 hours from awareness
  2. Intermediate report: within 72 hours of the initial notification (or without delay on material status changes)
  3. Final report: within 1 month after first major status

Reporting uses the standardised EU template via the competent national authority. Swiss FINMA-supervised houses report in parallel to FINMA under Supervisory Communication 03/2024 (24 hours) and, where EU subsidiaries are affected, to EU supervisors. Anyone who does not synchronise both paths runs into inconsistency traps that are treated as aggravating in supervisory proceedings.

Threat-led penetration testing

TLPT under Art. 26–27 DORA carries forward the ECB's TIBER-EU framework, in place since 2018. Captured are ‘significant’ financial entities listed annually by the ESAs, not every DORA institution. In practice these are systemic banks, large insurers, central counterparties and trading venues.

Key features of a TLPT:

  • Threat-led: scenarios based on a current threat intelligence report (from an independent TI provider)
  • Live production environment, not a test set-up
  • Minimum scope: critical and important functions plus supporting third parties (with their consent)
  • Frequency: at least every three years
  • External testers, internal testers during a transition period, subject to conditions
  • The supervisor issues an attestation that is mutually recognised across the EU

For Swiss FINMA-supervised institutions TLPT is not yet mandatory, but in Supervisory Communication 03/2024 FINMA signalled that TLPT-equivalent exercises are part of the resilience review for systemic institutions. Groups with EU subsidiary banks or investment firms fall under the TLPT regime at group level and need a group-wide synchronised testing programme.

ICT third-party risk and Register of Information

Pillar 4 is operationally the heaviest. Art. 28 DORA requires an integrated ICT third-party risk programme; Art. 30 lists an extensive contractual minimum catalogue for every outsourcing contract that concerns ICT services, description of services, location of processing, service levels, availability requirements, encryption, sub-contractors, reporting, audit rights, termination and exit strategy.

The centrepiece is the Register of Information (Art. 28(3), ITS 2024/2956). It contains over 100 data fields per contractual relationship across 15 tables: B.01 contractual relationships, B.02 service categories, B.03 ICT services, B.04 provider, B.05 sub-contractors and so on. The register must be submitted to the competent national authority annually, semi-annually for large institutions. EBA, EIOPA and ESMA aggregate the registers to identify concentration risk (CTPP designation) across the EU.

Swiss houses without an EU subsidiary do not file the register, but FINMA practice has expected a similarly structured ICT third-party inventory since Circular 23/01. Groups with EU operations should immediately build a single, group-wide register, island solutions per subsidiary create data drift and supervisory friction.

Interface with FINMA Circular 23/01

FINMA Circular 23/01 ‘Operational risks and resilience, banks’ has applied since 1 January 2024 and concretises FINMA's expectations for operational resilience in banks and securities firms. Substantively it overlaps significantly with DORA, but:

  • 23/01 is principles-based; DORA is rule-based with detailed RTS/ITS.
  • 23/01 uses the concept of ‘critical operations’, comparable to DORA's ‘critical or important functions’.
  • 23/01 requires supervisory reporting of serious cyber incidents (Supervisory Communication 03/2024 specifies the format and the 24-hour deadline).
  • Supplier governance: FINMA Circular 18/03 ‘Outsourcing, banks and insurers’ remains in force; DORA contract annexes complement but do not replace it.

Operationally this means: a Swiss banking group with an EU subsidiary needs a consolidated resilience framework that serves both regimes in a single policy and control library. Supervisory Communication 03/2024 (FINMA) and Art. 17–23 DORA must run inside the same incident response workflow, with clear triage rules and reporting paths per authority.

How SIDD supports you

SIDD guides Swiss financial firms through a unified DORA / FINMA 23/01 programme. Methodology and steering come through our CISO / information security officer mandate, complemented by specialised FINMA supervisory experience. The ICT risk management base and the control framework we build on top of your existing ISO 27001 ISMS, extended for DORA conformance, with the Register of Information as an integral data model.

For the testing duties under Art. 24–25 DORA we provide continuous vulnerability scans and penetration tests; for TLPT-eligible institutions we coordinate the threat-intelligence and red-team setup with qualified third parties. Awareness duties are covered through our IT security workshops, with dedicated modules for the management body. A first DORA maturity baseline is reached via the contact form; a detailed fixed-price proposal with a 12-month roadmap follows via the offer.

Need help putting this into practice? SIDD operates the matching service.
See service →

DORA, Operational Resilience Duties for Swiss Financial Services

INSIGHT

InfoSec
24 May 2026
Dr. Dominic Staiger
DORA for Swiss financial service providers: the five pillars, ICT risk management, incident reporting, TLPT, third-party risk and the link to FINMA.

Subscribe to our newsletter for free here

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.