DORA

DORA takes effect on January 17, 2025 and Swiss companies must act now to ensure compliance and mitigate digital operational risks.

January 17, 2025, is approaching quickly, bringing with it the enforcement of the Digital Operational Resilience Act (DORA). This EU regulation aims to strengthen digital operational resilience within the financial sector.

For affected Swiss companies, this means finalizing the implementation of DORA requirements in the coming weeks and critically reviewing the adjustments made.

Below, we outline the relevant DORA framework and highlight some of the key challenges companies may face during implementation.

DORA is an EU-wide regulation that establishes a uniform framework for managing risks related to information and communication technology (ICT) in the financial sector. It was designed to make financial institutions more resilient to IT-related risks such as system failures and cyberattacks.

Key aspects of the regulation include:

  • Strict ICT risk management requirements

  • Standardized incident and cyberattack reporting procedures

  • Regular resilience testing of digital systems

  • Monitoring and control of external ICT service providers

Even though DORA is an EU regulation that applies directly to EU financial institutions, it can also impact Swiss companies.

A key factor in determining whether an ICT provider is "critical" is whether a failure of that provider would have serious consequences for operational continuity, customer data protection, or financial stability.

  1. Companies subject to DORA

The upcoming enforcement of DORA presents significant challenges for companies, primarily due to uncertainties in the regulation and its interpretation:

These requirements mean that organizations must align not only their third-party providers but also their own IT systems and processes with DORA standards.

  • Regulatory Uncertainty Until After January 2025:

Swiss companies must navigate the complex interplay between Swiss and EU regulations, requiring a deep understanding of both legal frameworks.

Key areas that require immediate attention:

See what else we are doing with

Source

Related Articles