Since 17 January 2025, digital resilience is no longer a best practice: it is a directly applicable obligation, supervised by the ACPR. Here is the framework, the five pillars and the deadlines that structure compliance.
DORA applies to all insurance and reinsurance undertakings, mutual insurers, provident institutions and intermediaries supervised by the ACPR. Size does not remove you from scope: it only modulates the intensity of the obligations, through the proportionality principle set out in Article 4.
The regulation structures compliance around five domains. The first three concern internal organisation; the last two cover the ecosystem — providers and peers.
A documented framework, approved by the management body, which remains accountable. Security policies, asset mapping, continuous detection, tested and updated BCP/DRP.
Management accountabilityDetect, classify then report to the ACPR any major ICT-related incident on a strict timeline — including an outage or failure with no cyber origin.
4h · 72h · 1 monthA programme of regular tests (vulnerability, continuity, performance). Significant entities additionally run a TLPT — threat-led penetration test — at least every 3 years, under the TIBER-EU framework.
TLPT / 3 yrs if significantAn up-to-date register of information, mandatory contractual clauses (Art. 30), due diligence before contracting, exit and reversibility strategies. European oversight of providers deemed critical.
Register + Art. 30 clausesOn a voluntary basis, financial entities may exchange intelligence and indicators on threats and vulnerabilities, to strengthen the sector's collective defence.
VoluntaryBeyond the entry-into-application date, two obligations recur continuously: incident reporting and the annual submission of the register of information.
The ICT risk-management framework, the classification/notification procedures and a tested BCP must be operational. Directly applicable across the whole EU.
Each major incident triggers the 4h / 72h / 1 month sequence with the ACPR, through the dedicated portal. In the event of a personal-data breach, dual notification DORA + GDPR (CNIL, 72h).
Lists all agreements with ICT service providers. Data as of 31 December N-1, submitted via OneGate (Banque de France). A LEI identifier is required.
2025 focused on guidance and first targeted checks; 2026 marks the intensification of compliance audits by the ACPR.
The competent authorities have extensive powers. Beyond the fine, it is the ability to serve members and the reputation that are exposed.
Reported administrative-fine caps for the most serious breaches (the higher amount applies, as a % of annual turnover). A specific sanction regime applies to critical ICT providers.
DORA extends the perimeter well beyond cyber: an unavailable member area, a bug in claims processing or a slow subscription journey are ICT services whose availability must be monitored, tested and evidenced. That is exactly 2Be-FFICIENT's ground — without installing anything in your IT system. Here is how each capability maps to a requirement of the regulation.
Member area, claims, subscription: each journey becomes a probe monitored continuously. Proactive detection feeds the ICT risk-management framework and documents availability.
Acceptance scenarios become robots you can replay on demand or on schedule. Each run produces documented proof — screenshots, response times, checkpoints — reusable from one release to the next.
AI-augmented detection (Argos, Opale) speeds up the identification and pre-diagnosis of an anomaly — precious time before the "major" classification and the 4-hour deadline.
The scenarios built for acceptance testing then turn into production monitoring probes. The testing effort is not lost: it becomes continuous monitoring, with no additional work.
Book a session with our team: a 30-minute personalised demo to see how 2Be-FFICIENT addresses your monitoring challenges.
Our team will get back to you within one business day to agree on a time together.