# FINMA and DORA, Operational Resilience for Swiss Financial Institutions 2026

> FINMA Circular 2023/01 and DORA (EU 2022/2554) from 2025: ICT risk management, TLPT, third parties, reporting. 2026 guide for Swiss financial institutions.

- Source: https://www.sidd.swiss/en/insights/finma-dora-guide/
- Language: en
- Published: 2026-05-24
- Last updated: 2026-06-19
- Author: Dr. Dominic Staiger
- Publisher: SIDD Institute for Data Protection and Data Security, a brand of Priverion GmbH, Zugerstrasse 32, 6340 Baar (ZG), Switzerland

## FINMA and DORA, the dual regulatory framework for Swiss financial institutions

Since 2024/2025 Swiss financial institutions have operated within a dual regulatory framework for operational and digital resilience. Domestically, the Swiss Financial Market Supervisory Authority (FINMA) imposes binding requirements through its circulars on the management of operational risks, on ICT security and on critical outsourcing. Internationally, EU Regulation 2022/2554 (Digital Operational Resilience Act, DORA) has applied directly since 17 January 2025 to every Swiss establishment in the EU, and indirectly through contractual relationships with EU-regulated financial undertakings.

FINMA and DORA pursue the same protective goal: maintaining critical financial services under cyber, ICT and third-party risks. They differ markedly, however, in method. FINMA Circular 2023/01 "Operational risks and resilience, banks" (in force since 1 January 2024) follows a principles-based approach with pronounced proportionality by supervisory category. DORA, by contrast, is rules-based, refined by Delegated Regulations (RTS and ITS) of the ESAs (EBA, ESMA, EIOPA), and contains detailed duties on contract drafting, incident reporting and threat-led penetration testing.

For Swiss institutions with an EU nexus this means: both regimes must be satisfied in parallel, but may be documented in consolidated form. A well-designed ISMS in accordance with ISO/IEC 27001:2022, detail in the [ISO 27001 guide](https://www.sidd.swiss/einblicke/iso-27001-leitfaden/), forms in practice the load-bearing structure on which both the FINMA and the DORA requirements can be mapped. This guide situates both regimes, shows the mapping and provides a 10-step checklist for implementation.

## Which entities are subject to FINMA supervision?

Under Art. 3 FINMASA, FINMA supervises all entities subject to the Swiss financial market acts. These include banks (BankA), insurance undertakings (ISA), securities firms, trading venues and central counterparties (FinMIA), fund management companies and managers of collective assets (CISA), portfolio managers and trustees (FinIA), as well as insurance intermediaries. The scope is cross-sectoral and ranges from the globally active universal banking group to the small independent portfolio manager.

**Banks (BankA).** Supervised in full by FINMA, classified into five supervisory categories by size, complexity and risk. The supervisory category determines the intensity and granularity of the FINMA requirements, in particular in operational risk management.

**Insurers (ISA).** Life, non-life and reinsurers domiciled or active in Switzerland are subject to the Insurance Supervision Act. The FINMA circulars on governance, operational risks and outsourcing apply to them in adapted form.

**FinTechs and licence holders under Art. 1b BankA.** Providers that accept public deposits of up to CHF 100 million without conducting active lending business in the sense of a bank have, since 2019, been regulated under the "FinTech licence" and are subject to a proportionally reduced but substantial FINMA regime.

**Collective investment schemes (CISA).** Fund management companies, managers of collective assets (asset managers), SICAVs, limited partnerships for collective investment, and custodian banks are FINMA-licensed and supervised.

**Portfolio managers and trustees (FinIA).** Subject to authorisation under FinIA since 1 January 2020; ongoing supervision is carried out by a FINMA-recognised supervisory organisation (SO). FINMA remains the licensing and enforcement authority.

For each of these sectors the operational resilience requirements apply; the granularity and frequency of the evidence depend on the supervisory category and FINMA's risk assessment.

## Which entities are subject to DORA?

Under Art. 2 of Regulation (EU) 2022/2554, DORA applies to a broad spectrum of financial undertakings domiciled in the EU, supplemented by critical ICT third-party service providers. The Regulation defines more than 20 categories of "financial entity", among them credit institutions, payment institutions, e-money institutions, investment firms, trading venues, central counterparties, central securities depositories, management companies for UCITS and AIFs, insurance and reinsurance undertakings, rating agencies, crypto-asset service providers and crowdfunding service providers.

**Territorial scope.** DORA is an EU regulation and has applied directly in all EEA Member States since 17 January 2025. It attaches to the seat of the financial entity in the EU/EEA, not to the seat of its customers.

**Swiss institutions, direct scope.** A Swiss bank or insurer with its own subsidiary, branch or authorised establishment in an EEA Member State is, through that establishment, directly subject to DORA. The duties apply to the establishment as a locally authorised financial entity, depending on the individual case also at group level via EU supervision.

**Swiss institutions, indirect scope.** Where a Swiss institution has no EU establishment, DORA does not apply directly. DORA does, however, require EU-regulated financial entities to bind their ICT third-party service providers, including Swiss providers, contractually to certain minimum duties (Art. 28 et seq. DORA). Swiss houses that supply EU financial entities with cloud, SaaS, outsourcing or IT services are drawn contractually into the DORA regime.

**Critical ICT third-party service providers.** Under Art. 31 DORA, certain ICT third-party service providers may be designated as "critical" by the ESAs (Critical Third-Party Provider, CTPP). These are subject to direct oversight by a lead ESA with powers of information, investigation and sanction. Providers domiciled outside the EU as well (such as globally active hyperscalers) are covered, provided they serve EU financial entities.

## FINMA Circular 2023/01, operational risks and resilience

FINMA Circular 2023/01 "Operational risks and resilience, banks" has been in force since 1 January 2024 and replaced the earlier Circular 2008/21. It consolidates the FINMA requirements on the management of operational risks within a contemporary framework and explicitly integrates ICT and cyber risks as well as operational resilience as a cross-cutting theme.

**Scope.** The addressees are banks under BankA. Insurers are governed analogously by FINMA Circular 2017/02 "Corporate governance, insurers" and other relevant circulars. For portfolio managers and FinTechs, proportionate requirements apply through the respective supervisory organisations or directly through FINMA.

**Core duties.** Circular 2023/01 requires: an integrated framework for operational risks (Operational Risk Management Framework); a dedicated ICT risk management with an inventory of critical data and processes; a cyber risk management with threat intelligence and monitoring; a management of critical data ("critical data"); a business continuity management (BCM) including cyber resilience; and the definition and steering of critical functions from the perspective of operational resilience.

**Operational resilience.** The bank must identify critical functions, define their maximum tolerable period of disruption (impact tolerance) and demonstrate through scenario testing that this tolerance can be maintained even under severe but plausible stress events.

**Proportionality.** The requirements are differentiated by supervisory category. Large, systemically important banks (categories 1 and 2) fulfil the full set of duties; smaller institutions (categories 4 and 5) benefit from simplifications, for example in the density of internal reporting and scenario testing.

**Interlock with ISO 27001 and DORA.** Circular 2023/01 does not name any standard explicitly as binding, but in supervisory practice it accepts ISO/IEC 27001 as a recognised framework for ICT security. For Swiss institutions with DORA exposure an integrated framework serving both regimes in parallel is advisable.

## ICT risk management under DORA (Art. 5–15 DORA)

Articles 5 to 15 DORA form the core of the ICT risk management framework and are binding for every financial entity within scope. They require a documented, holistic and enterprise-wide consistent framework for the identification, protection, detection, response and recovery in respect of ICT risks, structurally compatible with the NIST Cybersecurity Framework (Identify-Protect-Detect-Respond-Recover).

**Governance and strategy (Art. 5 DORA).** The management body bears ultimate responsibility for ICT risk management, sets the ICT risk tolerance, approves the digital resilience strategy and oversees its implementation. The personal responsibility of senior management is explicitly stipulated.

**ICT risk management framework (Art. 6 DORA).** Documented in writing, reviewed at least annually, and reassessed after significant incidents or regulatory directions. The framework comprises strategies, policies, procedures, ICT protocols and tools.

**Identification (Art. 8 DORA).** Inventory of all ICT assets, functions, processes, dependencies and ICT third-party contracts. Identification and classification of critical or important functions.

**Protection and prevention (Art. 9 DORA).** Implementation of ICT security policies and tools: network segmentation, access management, encryption, secure configuration management, patch management, endpoint protection.

**Detection (Art. 10 DORA).** Mechanisms for the early detection of anomalous activity, including SIEM functionality, thresholds and alerting processes.

**Response and recovery (Art. 11 DORA).** ICT business continuity policy, recovery plans, RTO/RPO definitions, regular tests including full recovery from backups.

**Backup, restoration and learning (Art. 12 DORA).** Encrypted, segregated and integrity-protected backups; tested recovery procedures; lessons learned after every major incident.

**Communication (Art. 14 DORA).** Crisis communication plan for internal and external stakeholders, including customers, supervisors and the media.

The detailed requirements are refined by RTS Delegated Regulations of the ESAs, in particular on the ICT risk management framework and on the simplified framework for small and non-interconnected investment firms.

## Incident management and reporting (DORA Art. 17–23 + FINMA reporting duties)

The management and reporting of ICT-related incidents form a central field of duties under both regimes. DORA establishes detailed, EU-wide harmonised reporting duties; FINMA requires in parallel the reporting of serious cyber incidents to the supervisor.

**DORA, ICT incident management process (Art. 17 DORA).** A defined process for the detection, management, classification and escalation of ICT-related incidents. Responsibilities, escalation paths, documentation duties and lessons learned are binding.

**Classification (Art. 18 DORA).** Incidents are classified according to criteria refined in an RTS Delegated Regulation: impact on customers, data integrity, duration and service operation, geographical reach, economic impact and reputational damage.

**Reporting of major incidents (Art. 19 DORA).** For "major ICT-related incidents" three reports must be submitted to the competent authority: an initial notification, an intermediate report and a final report. The exact deadlines are refined by RTS / ITS and are bindingly set out in the Delegated Regulations of the ESAs.

**Voluntary reporting of significant cyber threats (Art. 19(2) DORA).** Financial entities may report significant cyber threats voluntarily, an element of preventive information sharing.

**Notification of customers (Art. 19(3) DORA).** Where customers are affected by an incident, they must be informed without undue delay, as soon as this is feasible, without jeopardising the response.

**FINMA reporting duties.** Under FINMA Circular 2013/03 as well as Supervisory Notice 05/2020 and subsequent adjustments, FINMA requires the reporting of successful serious cyber attacks within a short deadline. Supervised entities report directly to FINMA through the prescribed reporting channel; the detailed content (initial notification with a follow-up report) follows a FINMA specification. For banks, sector-specific reporting duties of the SNB apply in addition.

**Swiss BACS reporting duty.** Independently of this, since 1 April 2025 the Information Security Act (ISA) imposes on operators of critical infrastructures a duty to report cyber attacks to the Federal Office for Cyber Security (BACS) within 24 hours of becoming aware.

An entity subject to both regimes complies in each case with the strictest deadline and uses a consolidated incident-reporting workflow.

## Digital operational resilience testing (Art. 24–27 DORA)

Articles 24 to 27 DORA require financial entities to maintain a documented, risk-based testing programme for digital operational resilience. The testing programme is mandatory for all entities within scope; threat-led penetration testing, as the most demanding tier, applies additionally to a narrower group.

**Testing programme (Art. 24 DORA).** All ICT systems and applications that support critical or important functions must be appropriately tested at least annually. The programme is anchored in the ICT risk management framework and must be approved by the management body.

**Minimum scope (Art. 25 DORA).** Depending on the risk profile, the testing programme comprises: vulnerability scans, open-source analyses, network security assessments, gap analyses, physical security reviews, questionnaires and scan-based software solutions, source-code reviews, scenario-based tests, compatibility tests, performance tests, end-to-end tests and penetration tests. The distinction between a vulnerability scan and a penetration test is explained in the comparison [Pentest vs vulnerability scan](https://www.sidd.swiss/einblicke/pentest-vs-scan/).

**Independence of testers (Art. 24(4) DORA).** Testers must have the necessary independence from the function being tested. Internal tests are permitted provided conflicts of interest are excluded and the management body approves this in a documented manner.

**Remediation (Art. 24(5) DORA).** Identified vulnerabilities are prioritised on a risk basis and remediated within a defined timeframe. The remediation status forms part of the ongoing reporting to senior management.

**Interlock with ISO 27001 A.8.8.** Vulnerability management under Annex A.8.8 ISO/IEC 27001:2022 forms the operational basis. DORA additionally requires the explicitly documented and auditable testing cycle with approval by the management body.

## Threat-led penetration testing (TLPT), Art. 26–27 DORA and TIBER-EU

Articles 26 and 27 DORA introduce threat-led penetration testing (TLPT) as a binding, advanced testing method. TLPT simulates real attackers in live production environments of critical functions, methodologically aligned closely with the TIBER-EU framework of the European Central Bank (TIBER = Threat Intelligence-based Ethical Red Teaming).

**Scope (Art. 26(8) DORA).** Mandatory for a group of financial entities selected by the competent authority that are significant for financial stability. The exact criteria are refined in an RTS Delegated Regulation and cover size, systemic relevance, risk profile and maturity. Small and non-interconnected investment firms are explicitly excluded.

**Frequency (Art. 26(1) DORA).** At least every three years, more frequently depending on the risk profile. The competent authority may adjust the cycle in light of particular circumstances.

**Methodological requirements (Art. 26(2) DORA).** The TLPT scope covers critical or important functions including relevant ICT third-party services. Tests are carried out on production systems. Threat intelligence drives the attacker scenarios (TTPs, tactics, techniques, procedures).

**Tester requirements (Art. 27 DORA).** External, or combined internal/external, testers must demonstrate technical and organisational suitability: the highest reputation, formal certifications, recognised methodology, professional indemnity insurance, an ethical code of conduct. Purely internal tests are permitted under strict conditions and require approval by the competent authority.

**Relationship to TIBER-EU.** TIBER-EU has been, since 2018, the harmonised ECB framework for threat-led red-team tests in the European financial sector. DORA TLPT tests carried out under the TIBER-EU methodology are recognised in supervisory practice as DORA-compliant. Swiss institutions with EU subsidiaries benefit from TIBER-CH experience that the SNB has piloted in Switzerland.

**Distinction from the classic pentest.** TLPT is not a usual application pentest and not a vulnerability scan. It is a red-team exercise with threat intelligence, several weeks of preparation, "white team" steering and a defined escalation matrix. Classic pentests remain necessary for individual applications; they are no substitute for TLPT.

## Third-party risk management (DORA Art. 28–44 + FINMA Outsourcing Circular 2018/03)

The management of ICT third-party risks (ICT Third-Party Risk Management, TPRM) is among the most intensively regulated areas of DORA and complements the national Swiss outsourcing regime of FINMA. Both regimes require contractual minimum contents, risk analyses before contract conclusion, exit strategies and a documented register.

**DORA, general principles (Art. 28 DORA).** Financial entities bear full responsibility for ICT risks arising from third-party relationships, irrespective of the provider's seat. TPRM is part of the ICT risk management framework and must be approved by the management body.

**Strategy and policy (Art. 28(2) DORA).** A written strategy on ICT third-party risks with concentration-risk analysis, defined risk-appetite limits and escalation criteria.

**Pre-contractual phase (Art. 28(4) DORA).** Before any award: due diligence, risk assessment, suitability review. For the outsourcing of critical or important functions, heightened requirements apply.

**Contractual minimum contents (Art. 30 DORA).** A detailed catalogue for all contracts, with heightened duties for critical functions: description of services, locations of data processing, information and audit rights, service level agreements, reporting and notification duties, security standards, cooperation duties in supervisory actions, termination and exit provisions.

**Register (Art. 28(3) DORA).** A duty to maintain a complete register of all ICT third-party contracts at group and individual-institution level. The register is made available to the competent authority; format and content are standardised by ITS.

**Oversight of critical ICT third-party service providers (Art. 31–44 DORA).** The ESAs designate certain providers as "critical" and conduct direct oversight through a lead ESA with powers of information, investigation and sanction (daily periodic penalty payments of up to 1 percent of the average worldwide daily turnover).

**FINMA Circular 2018/03 "Outsourcing, banks and insurers".** The Swiss counterpart requires, for the outsourcing of significant functions, among other things: selection of a suitable service provider, a written agreement, ensuring FINMA's ability to audit, observance of bank-client confidentiality (Art. 47 BankA), reporting to FINMA and periodic review.

**Practice.** Swiss institutions with an EU establishment maintain the register and the contracts in consolidated form to the DORA maximum standard. The FINMA requirements are covered in the same contract and the same register. Duplicate contracts are avoided.

## Business continuity management (BCM) and ICT contingency planning

Business continuity management (BCM) and ICT contingency planning are the operational backbone of digital resilience. Both regimes, FINMA Circular 2023/01 and DORA Art. 11 et seq., require a closed cycle of analysis, plans, tests and improvement. ISO 22301 (Business Continuity Management Systems) and Annex A.5.29 / A.5.30 ISO/IEC 27001:2022 (Information Security During Disruption / ICT Readiness for Business Continuity) provide the recognised implementation methodology.

**Business impact analysis (BIA).** Identification of critical business processes, quantification of the maximum tolerable period of disruption (MTPD), definition of the Recovery Time Objective (RTO) and Recovery Point Objective (RPO) for each critical function.

**Business continuity plan (BCP).** Documented plans per critical function with responsibilities, escalation paths, resource requirements, alternative work locations and communication patterns.

**ICT contingency plan (ICT disaster recovery plan).** A technical recovery plan for ICT systems with documented recovery procedures, failover architectures, tape/object-storage backups and cyber-recovery capabilities.

**Cyber resilience.** Beyond classic BCM, FINMA Circular 2023/01 and DORA explicitly require the consideration of cyber scenarios including ransomware with simultaneous compromise of production and backup environments. Immutable backups, air-gapped copies and cyber-recovery sites are increasingly expected in supervisory practice.

**Tests.** Regular tabletop exercises (at least annually), functional tests of individual recovery components and at least periodic end-to-end recovery tests. Test results are documented; identified gaps are tracked in an improvement plan.

**Crisis communication.** Defined messaging, stakeholder lists (supervisors, customers, employees, the media, suppliers), redundant communication channels. For Swiss banks, coordination with the crisis team and, where applicable, with the SNB.

## Swiss ICT minimum standard (BWL), what it is and to whom it applies

The Swiss ICT minimum standard was issued by the Federal Office for National Economic Supply (BWL) as a cross-sectoral recommendation for the security of critical information and communication technologies. It bundles minimum requirements for operators of critical infrastructures and is closely aligned with the NIST Cybersecurity Framework.

**Character.** The ICT minimum standard is primarily a recommendation, not a directly legally binding norm. It acquires de facto binding force, however, through sectoral regulation, procurement conditions and insurance requirements. For certain sectors (electricity, water, transport, health, finance) it is invoked as a reference in supervisory and procurement practice.

**Structure.** The standard follows the five NIST-CSF functions Identify, Protect, Detect, Respond, Recover, with around 100 measures in total, defined across three maturity levels (Basic, Standard, High).

**Relationship to ISO 27001.** The ICT minimum standard and ISO/IEC 27001:2022 are complementary. ISO 27001 provides the management system; the minimum standard adds sector-specific minimum measures. In practice the two are frequently combined.

**Relationship to FINMA and DORA.** For FINMA-supervised entities the ICT minimum standard is not a directly applicable body of rules; FINMA Circular 2023/01 and the relevant sectoral circulars are decisive. The same applies to DORA, which refers to its own RTS. The minimum standard may, however, be invoked as an additional reference for the maturity of ICT security management.

**eCH-0199.** In the public sector (federal government, cantons, municipalities) the eCH-0199 standard "ICT Security Standard" is becoming established alongside as a best-practice reference for authorities and quasi-governmental organisations.

## Mapping FINMA × DORA × ISO/IEC 27001, where the synergies lie

Swiss financial institutions with an EU nexus face the task of consolidating FINMA Circular 2023/01, DORA and ideally ISO/IEC 27001:2022 in a single management system. A cleanly mapped architecture reduces duplication of effort, avoids contradictory policies and provides both FINMA and the competent EU authority with consistent evidence.

**Governance.** ISO 27001 Chapter 5 (Leadership) largely covers the requirements of FINMA Circular 2023/01 section III ("Responsibilities of senior management") and Art. 5 DORA (management body). The personal responsibility of senior management must additionally be set out explicitly in the information security policy.

**Risk management.** ISO 27001 Chapter 6.1 (risk assessment and treatment) provides the methodology. Building on this, FINMA Circular 2023/01 and Art. 6 et seq. DORA require a specific ICT risk inventory with classification of critical functions.

**Asset inventory.** ISO 27001 A.5.9 (Inventory of Information and other Associated Assets) is extended by the DORA duty to maintain ICT third-party contracts separately in the register under Art. 28(3) DORA.

**Incident management.** ISO 27001 A.5.24–A.5.28 covers the basic duties. Both the DORA classification and reporting and the FINMA cyber reporting duty and the BACS 24-hour deadline build on this process.

**BCM.** ISO 27001 A.5.29 and A.5.30, supplemented by ISO 22301, largely satisfy the BCM requirements of both regimes. DORA additionally requires documented tests and lessons-learned cycles.

**Third-party management.** ISO 27001 A.5.19–A.5.23 (Supplier Relationships, Cloud Services) forms the basis. For DORA contracts the minimum contents under Art. 30 DORA are mandatory; FINMA Circular 2018/03 supplements the Swiss outsourcing regime.

**Vulnerability management and tests.** ISO 27001 A.8.8 (Management of Technical Vulnerabilities), A.8.25 (Secure Development Life Cycle) and A.8.29 (Security Testing in Development and Acceptance) provide the routine tests. Building on this, DORA Art. 24–25 requires a formal test plan with approval by the management body; TLPT (Art. 26–27) applies only to selected institutions.

**Data protection.** In parallel with FINMA and DORA, Art. 8 Swiss DSG (FADP) (Switzerland) and Art. 32 GDPR (EU) continue to apply. The TOM requirements are maintained in the same ISMS repository, detail in the [GDPR guide](https://www.sidd.swiss/einblicke/dsgvo-leitfaden/).

In practice, a shared controls repository is advisable, in which each control anchor is linked to the FINMA, DORA and ISO references.

## Sanctions and supervisory measures

The sanction and enforcement logic differs fundamentally between FINMA and DORA. FINMA works primarily with supervisory measures; DORA and the competent EU authorities have a broad spectrum of administrative sanctions.

**FINMA, supervisory measures.** FINMA typically does not impose direct fines on supervised entities for ICT or resilience breaches. Rather, it resorts to supervisory measures under Art. 31–37 FINMASA: restoration of compliance, professional bans, activity bans, confiscation of unlawfully obtained profit, withdrawal of the licence, publication of the ruling ("naming and shaming"). Monetary sanctions are largely reserved to criminal law (Art. 44 et seq. FINMASA, administrative criminal law) and tied to narrow offences. Amount and applicability depend on the individual case and supervisory category.

**DORA, administrative sanctions (Art. 50 DORA).** Member States regulate sanctions and measures for breaches of DORA in their national law and ensure that these are effective, proportionate and dissuasive. The competent authorities may, among other things, issue public warnings, impose temporary activity bans or withdraw the licence. The specific fine levels vary by Member State, depending on the individual case.

**DORA, sanctions against critical ICT third-party service providers (Art. 35 DORA).** The lead ESA may impose daily periodic penalty payments to ensure compliance with orders. The amount is capped at up to 1 percent of the provider's average worldwide daily turnover in the preceding financial year, for a maximum duration of six months.

**Reputational risk.** In practice the economically most relevant dimension of sanction is often the reputational damage from public rulings or media coverage, as well as the loss of trust among customers and investors. A single inadequately managed cyber incident with delayed reporting can have higher economic consequences than any administrative fine.

**Criminal liability.** At the Swiss DSG (FADP) level, criminal fines against responsible natural persons of up to CHF 250,000 under Art. 60 et seq. DSG remain in place, where a security breach with a data protection nexus is engaged.

## FINMA/DORA compliance checklist for regulated institutions (10 steps)

The following checklist summarises the steps with which a FINMA-supervised institution with DORA exposure builds its integrated resilience framework. It does not replace institution-specific advice but structures the approach.

1. **Clarify the scopes.** FINMA status (banks, insurers, FinTech, CISA, portfolio managers; supervisory category); DORA applicability (direct via EU establishment or indirect via supply relationship); where applicable, consider NIS2, the Swiss BACS/ISA and the ICT minimum standard in parallel.
2. **Anchor governance.** Document the responsibility of senior management, set the risk appetite for ICT risks, adopt the digital resilience strategy, approve the ICT risk management framework.
3. **Build the ICT risk inventory.** Asset and service inventory, classification of critical / important functions, identification of critical data, a dependency map, concentration-risk analysis.
4. **Consolidate the control framework.** ISO/IEC 27001:2022 as the methodology, supplemented by FINMA Circular 2023/01 and DORA specifics. A shared controls repository with a mapping of all three regimes.
5. **Build incident management.** Classification scheme under DORA Art. 18, escalation and reporting path to FINMA, to the competent EU authority, to the BACS, to customers, to the FDPIC (in the case of data breaches). A consolidated workflow, with parallel notifications automated.
6. **Test BCM and cyber recovery.** BIA, BCP, ICT contingency plans, cyber-recovery plan; at least an annual tabletop exercise, a periodic end-to-end recovery test with a documented result.
7. **Sharpen the third-party register and contracts.** A DORA-compliant register under Art. 28(3) DORA, contracts with DORA minimum contents under Art. 30 DORA, FINMA outsourcing duties under Circular 2018/03, exit strategies for critical providers.
8. **Establish the testing programme.** Vulnerability scans, penetration tests, source-code reviews, end-to-end tests in accordance with DORA Art. 24–25, comparison [Pentest vs vulnerability scan](https://www.sidd.swiss/einblicke/pentest-vs-scan/). For TLPT-obligated institutions, additionally a threat-led penetration test under the TIBER-EU methodology at least every three years.
9. **Awareness and training.** A binding training programme for senior management, IT and the business units; role-specific deepening; documented participation; effectiveness measurement.
10. **Secure audit readiness.** Internal audit annually, management review semi-annually, preparation for FINMA supervisory reviews and for reviews by the EU supervisors; where applicable, ISO/IEC 27001 certification via CIS Cert (Quality Austria Group) as third-party evidence.

## Frequently asked questions on FINMA and DORA (FAQ)

**When did DORA enter into force?** DORA, Regulation (EU) 2022/2554, was adopted on 16 January 2023 and has applied directly in all EEA Member States since 17 January 2025. The supplementary RTS and ITS of the ESAs have in part also been in force since the date of application, with further ones adopted in stages. Swiss financial entities with an EU establishment have been directly covered since that date.

**Does DORA apply to Swiss institutions without an EU establishment?** Not directly. DORA is an EU regulation and attaches to the seat in the EU/EEA. Swiss institutions without an EU establishment are, however, indirectly affected as soon as they serve EU-regulated financial entities as customers and supply ICT services: they are bound contractually to the DORA minimum contents under Art. 30 DORA, depending on the individual case with information and audit rights for the EU supervisors.

**What exactly does FINMA Circular 2023/01 require?** Circular 2023/01 "Operational risks and resilience, banks" has been in force since 1 January 2024 and bundles an integrated framework for operational risks, a dedicated ICT and cyber risk management, a management of critical data, a BCM with cyber resilience, and the steering of critical functions from the perspective of operational resilience. The requirements are staggered proportionally by supervisory category.

**Who must carry out a threat-led penetration test (TLPT) under DORA?** Only a group of financial entities selected by the competent authority that are significant for financial stability. The criteria (size, systemic relevance, risk profile, maturity) are refined in an RTS Delegated Regulation. Small and non-interconnected investment firms are excluded. Frequency: at least every three years, methodology aligned with TIBER-EU.

**How are the FINMA Outsourcing Circular 2018/03 and DORA Art. 28 et seq. related?** Both regimes govern third-party management but apply cumulatively. FINMA Circular 2018/03 is Swiss supervisory law and requires contractual minimum contents, FINMA's ability to audit and observance of bank-client confidentiality. DORA Art. 28 et seq. requires EU-wide standardised contract contents, a consolidated register and concentration-risk analyses. In practice both regimes are covered in a consolidated contract and a shared register.

**Which reporting duties arise in the event of a cyber incident?** Several in parallel: DORA Art. 19 (initial, intermediate, final report to the competent EU authority within the RTS deadlines), the FINMA cyber reporting duty (initial notification and follow-up report directly to FINMA), the BACS under the Information Security Act (24 hours, for critical infrastructures), the FDPIC under Art. 24 DSG (in the case of data breaches, "as soon as possible") and, where applicable, the EU supervisors under Art. 33 GDPR (72 hours). A consolidated workflow is mandatory.

**Does ISO/IEC 27001:2022 replace the FINMA and DORA duties?** No. ISO 27001 provides the recognised management-system framework and covers most controls. It does not, however, replace the specific FINMA and DORA duties, such as the register of critical ICT third parties (Art. 28 DORA), the DORA contractual minimum contents (Art. 30 DORA), the specific reporting duties or the requirements on threat-led penetration testing. ISO 27001 is the foundation; FINMA and DORA build on it.

**What costs are associated with DORA implementation?** Strongly dependent on maturity, size and complexity. A mid-sized Swiss institution with existing ISMS substance typically anticipates a project lasting several months for the gap analysis, the contract adjustments with all ICT third parties, the extension of the register and additional tests. The ongoing costs, TLPT every three years, annual end-to-end tests, continuous TPRM, are permanent and not one-off.

## How SIDD supports you on FINMA and DORA compliance

SIDD is the data protection and InfoSec brand of Priverion GmbH (Baar/ZG), founded in 2017. We support Swiss financial institutions in building an integrated resilience framework that maps FINMA Circular 2023/01, DORA and ISO/IEC 27001:2022 in a consolidated management system. In a mandate as [external ISMS officer / CISO/ISO function](https://www.sidd.swiss/en/services/vciso/) we take on the ongoing steering; the ISMS build-out and certification preparation we handle in the [ISMS mandate ISO 27001](https://www.sidd.swiss/en/services/iso-27001-isms/) with CIS Cert (Quality Austria Group) as certification partner. For the testing programme under DORA Art. 24–25 we provide [penetration tests](https://www.sidd.swiss/en/services/penetration-test/) and [vulnerability scans](https://www.sidd.swiss/en/services/vulnerability-scan/); for the methodological classification of TLPT versus the classic pentest see the [comparison Pentest vs vulnerability scan](https://www.sidd.swiss/einblicke/pentest-vs-scan/). Deeper methodology in the [ISO 27001 guide](https://www.sidd.swiss/einblicke/iso-27001-leitfaden/). We keep advisory and audit strictly separate.

## Cited legislation and sources

- Regulation (EU) 2022/2554 (DORA)
- Art. 2 DORA
- Art. 5 DORA
- Art. 6 DORA
- Art. 8 DORA
- Art. 9 DORA
- Art. 10 DORA
- Art. 11 DORA
- Art. 12 DORA
- Art. 14 DORA
- Art. 17 DORA
- Art. 18 DORA
- Art. 19 DORA
- Art. 24 DORA
- Art. 25 DORA
- Art. 26 DORA
- Art. 27 DORA
- Art. 28 DORA
- Art. 30 DORA
- Art. 31 DORA
- Art. 35 DORA
- Art. 50 DORA
- Delegated Regulations (RTS / ITS) on DORA by the ESAs (EBA, ESMA, EIOPA)
- FINMA Circular 2023/01 "Operational risks and resilience, banks"
- FINMA Circular 2018/03 "Outsourcing, banks and insurers"
- FINMA Circular 2017/02 "Corporate governance, insurers"
- FINMA Circular 2013/03 "Auditing"
- Financial Market Supervision Act (FINMASA)
- Art. 3 FINMASA
- Art. 31 FINMASA
- Art. 44 FINMASA
- Banking Act (BankA)
- Art. 1b BankA
- Art. 47 BankA
- Insurance Supervision Act (ISA)
- Financial Institutions Act (FinIA)
- Collective Investment Schemes Act (CISA)
- Financial Market Infrastructure Act (FinMIA)
- Information Security Act (ISA)
- Art. 8 DSG
- Art. 24 DSG
- Art. 60 DSG
- Art. 32 GDPR
- Art. 33 GDPR
- ISO/IEC 27001:2022
- ISO/IEC 27002:2022
- ISO/IEC 27005:2022
- ISO 22301:2019
- NIST Cybersecurity Framework
- TIBER-EU Framework (ECB)
- Swiss ICT minimum standard (BWL)
- eCH-0199 ICT Security Standard

---

This document is the Markdown rendition of the page linked above. Please cite the HTML URL.
