Regulation and standard

What does DORA require for ICT security awareness and training?

Short answer

The Digital Operational Resilience Act (DORA, Regulation (EU) 2022/2554) requires EU financial entities to run ICT security awareness programs and digital operational resilience training as compulsory modules for all employees and senior management (Article 13(6)). Members of the management body must keep their ICT risk knowledge current, including through regular specific training (Article 5(4)). DORA has applied since January 17, 2025.

By the Knowledge Foundry editorial team. How we write and check these pages

Published
Updated
Reading time
6 min
Jurisdiction
European Union (Regulation (EU) 2022/2554, directly applicable)
Regulator
National competent authorities for each type of financial entity (in Portugal, the Banco de Portugal, CMVM, and ASF), with the European Supervisory Authorities (EBA, EIOPA, ESMA) coordinating at EU level

Key takeaways

  • Article 13(6): ICT security awareness programs and digital operational resilience training are compulsory modules for all employees and senior management, with complexity matched to each function.
  • Article 5(4): management body members must keep sufficient knowledge and skills to understand and assess ICT risk, including by following specific training on a regular basis.
  • Article 5(2)(g): the management body allocates and periodically reviews the budget for awareness programs, resilience training, and ICT skills for all staff.
  • ICT third-party service providers are brought into training where appropriate, with the conditions set in the contract under Article 30(2)(i).
  • DORA is a regulation, so it applies directly in every Member State from January 17, 2025, without national transposition.

What training does DORA require?

DORA requires compulsory ICT security awareness and digital operational resilience training for every employee and for senior management, plus regular specific training for members of the management body. As at September 2026 these obligations have applied for more than 18 months, since Article 64 of Regulation (EU) 2022/2554 set January 17, 2025 as the application date.

Article 13(6) is the core staff obligation: "Financial entities shall develop ICT security awareness programmes and digital operational resilience training as compulsory modules in their staff training schemes. Those programmes and training shall be applicable to all employees and to senior management staff, and shall have a level of complexity commensurate to the remit of their functions."

The phrase "compulsory modules" means DORA training is mandatory training inside the entity's existing training scheme, not an optional awareness campaign. The phrase "commensurate to the remit of their functions" means one generic course for everyone is unlikely to be enough: a developer, a payments operator, and a board member face different ICT risks.

What must the management body know and do?

The management body bears ultimate responsibility for managing the entity's ICT risk (Article 5(2)(a)), so DORA requires its members to keep their own knowledge current. Article 5(4) states that members "shall actively keep up to date with sufficient knowledge and skills to understand and assess ICT risk and its impact on the operations of the financial entity, including by following specific training on a regular basis, commensurate to the ICT risk being managed."

Article 5(2)(g) adds a resourcing duty: the management body must allocate and periodically review the budget for digital operational resilience, including relevant ICT security awareness programs, digital operational resilience training, and ICT skills for all staff. Article 13(5) requires senior ICT staff to report at least yearly to the management body on lessons from testing and incidents, which gives directors a regular input for their own learning.

Do ICT third-party service providers need DORA training?

Where appropriate, yes. Article 13(6) says financial entities shall also include ICT third-party service providers in their relevant training schemes, and Article 30(2)(i) requires contracts for ICT services to set out the conditions for providers' participation in the entity's awareness programs and resilience training.

The regulatory technical standards in Commission Delegated Regulation (EU) 2024/1774 reinforce this. Article 19 requires the human resources policy to require staff of the financial entity, and of ICT third-party service providers using or accessing its ICT assets, to be informed about and adhere to the entity's ICT security policies, procedures, and protocols, and to be aware of reporting channels for anomalous behavior, including channels established under the EU Whistleblower Directive where applicable.

Why does DORA apply the same way in every EU country?

DORA is an EU regulation, which Article 64 describes as "binding in its entirety and directly applicable in all Member States." A directive, such as NIS2, sets goals that each Member State must write into national law (transposition), so the detail can differ between countries. A regulation needs no transposition, which is why a bank in Lisbon and one in Frankfurt face the same Article 13(6) text.

National rules still matter for supervision and penalties, which are set and enforced by national competent authorities. In Portugal, Article 15 of the cybersecurity regime approved by Decree-Law 125/2025 designates the Banco de Portugal, the Comissão do Mercado de Valores Mobiliários (CMVM), and the Autoridade de Supervisão de Seguros e Fundos de Pensões (ASF) as the special national cybersecurity authorities for digital operational resilience in the financial sector. NIS2 recital 28 treats DORA as the sector specific act for financial entities, so DORA's training rules take precedence over the equivalent NIS2 provisions; see NIS2 management body training.

Do smaller financial entities have lighter training rules?

Entities under the simplified ICT risk management framework in Article 16, such as small and non-interconnected investment firms and certain exempted payment institutions, are not subject to Articles 5 to 15, but they still must develop ICT security awareness programs and resilience training according to their needs and ICT risk profile (Article 16(1)(h)).

Article 28(2)(e) of Delegated Regulation (EU) 2024/1774 adds that the management body of these entities allocates and reviews, at least once a year, the budget for resources including awareness programs, resilience training, and ICT skills for all staff.

How do you show a supervisor that DORA training is adequate?

A supervisor will look for a documented link between each DORA obligation, the population it covers, the training delivered, and evidence that people can apply it. The table below is an illustrative mapping, not a regulatory template.

Illustrative mapping: DORA obligation to learning outcome to assessment evidence
DORA provisionPopulationLearning outcomeAssessment evidence
Article 5(4)Management body membersCan assess ICT risk tolerance, the resilience strategy, and incident impact on operationsIndividual training log, scenario exercise outputs, board minutes showing informed challenge
Article 5(2)(g)Management bodyAllocates budget to awareness, resilience training, and ICT skillsApproved budget and periodic review record
Article 13(6)All employees and senior managementRecognize and report ICT threats and follow ICT security policies relevant to their roleRole based module completion, knowledge check scores, reporting behavior in simulations
Article 13(6) and 30(2)(i)ICT third-party service providersKnow the entity's ICT security requirements and escalation routesContract clause, attendance or equivalent training attestation
RTS Article 19Staff and provider staff accessing ICT assetsKnow ICT security policies and reporting channels for anomalous behaviorPolicy acknowledgement, onboarding records, periodic refresh

Completion data alone rarely shows that training is commensurate to function, which is the distinction explained in completion tracking vs competency verification. Refresh timing can follow the approach in setting mandatory training refresh cycles, triggered also by post incident reviews under Article 13.

How does Knowledge Foundry approach this?

Knowledge Foundry represents DORA provisions, ICT roles, and the competencies each role needs as linked objects with assessment points, so each module traces to Article 5, 13, or 16 and to the population it covers. When the entity's ICT policies or the regulatory technical standards change, the affected modules and learners can be identified from those links.

Frequently asked questions

Does DORA set a training frequency?

No fixed frequency is set for staff training. Article 5(4) requires management body members to follow specific training on a regular basis, and Article 13 ties improvement to lessons from testing and incidents. Most entities set an annual cycle with extra updates after major incidents or policy changes, and document why that cycle fits their risk.

Does DORA apply to financial entities outside the EU?

DORA applies to the financial entities listed in Article 2(1), which are entities authorized or registered under EU financial services law. A group headquartered outside the EU is affected through its EU authorized subsidiaries, and non EU ICT providers are affected through contracts with EU financial entities.

Is phishing simulation required by DORA?

DORA does not name phishing simulation. It requires compulsory awareness programs and resilience training commensurate to each function. Simulations are one common way to evidence that awareness works in practice, alongside knowledge checks and incident reporting data.

Are senior management and the management body treated differently under DORA?

Yes. Senior management staff fall under Article 13(6) with all employees, receiving compulsory awareness and resilience training scaled to their functions. Members of the management body have an additional personal duty under Article 5(4) to keep sufficient knowledge and skills to understand and assess ICT risk, including through regular specific training.

Sources

  1. Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA), Official Journal of the European Union (EUR-Lex)
  2. Commission Delegated Regulation (EU) 2024/1774 (RTS on ICT risk management tools, methods, processes and policies), Official Journal of the European Union (EUR-Lex)
  3. Directive (EU) 2022/2555 (NIS 2 Directive), Official Journal of the European Union (EUR-Lex)
  4. Digital Operational Resilience Act (DORA), European Insurance and Occupational Pensions Authority (EIOPA)
  5. Operational resilience, European Banking Authority (EBA)
  6. Decreto-Lei n.º 125/2025, Diário da República (Portugal)

This page is general information, not legal or compliance advice. Check the primary sources above and obtain advice for your circumstances. See our editorial standards.

Ready to see it?

Bring a subject. Leave with a framework.

A 45-minute working session with our team on a real subject or program you own. You see the system operate on your material, and you keep the framework it produces.

We reply within one business day.