- Key Takeaways
- What Does Dora Require Around Cryptographic Key Protection?
- Who Does DORA Apply to?
- What Happens if a Financial Entity Fails to Meet Dora's Cryptography Requirements?
- How Should a Financial Entity Approach Dora's Cryptography Requirements Practically?
- How Encryption Consulting Helps
- Frequently Asked Questions
- Close Your DORA Cryptographic Compliance Gaps
The Digital Operational Resilience Act (DORA) is an EU regulation, applicable since January 17, 2025, that requires financial entities to protect cryptographic keys throughout their lifecycle and implement strong authentication mechanisms as part of a broader ICT risk management framework.
DORA (Regulation (EU) 2022/2554) requires EU financial entities to manage ICT risk, including cryptography, under a unified framework. Article 9.4(d) requires strong authentication and cryptographic key protection, and Article 7.2-7.3 requires controls protecting keys through their entire lifecycle against loss, unauthorized access, disclosure, and modification.
Key Takeaways
- DORA entered into force January 16, 2023, and has applied to EU financial entities since January 17, 2025.
- Article 9.4(d) specifically requires implementing strong authentication mechanisms and protecting cryptographic keys, tying key management directly into DORA’s ICT risk requirements.
- Articles 7.2 and 7.3 require financial entities to protect cryptographic keys through their whole lifecycle, covering loss, unauthorized access, disclosure, and modification.
- DORA applies to a broad range of financial entities, including banks, insurers, investment firms, and the ICT third-party providers that support them.
- Non-compliance penalties can reach up to 2% of global annual turnover for financial entities, and up to €5 million for critical ICT third-party providers.
What Does Dora Require Around Cryptographic Key Protection?
| Article | Requirement |
|---|---|
| Article 9.4(d) | Implement strong authentication mechanisms and protect cryptographic keys as part of ICT security policy |
| Article 7.2 | Identify and implement controls protecting cryptographic keys throughout their entire lifecycle |
| Article 7.3 | Protect keys against loss, unauthorized access, disclosure, and modification specifically |
These provisions sit within DORA’s broader ICT risk management framework, meaning cryptographic key protection is not an isolated technical requirement but part of the governance, testing, and incident reporting obligations DORA applies across a financial entity’s entire ICT estate.
Who Does DORA Apply to?
DORA applies to a wide range of EU financial entities, including credit institutions, payment institutions, investment firms, and insurance companies, along with the critical ICT third-party providers that support them. Financial entities must also identify their critical ICT service providers and submit contractual information about those relationships to regulators, extending DORA’s reach into the broader technology supply chain, not just regulated financial institutions themselves.
What Happens if a Financial Entity Fails to Meet Dora’s Cryptography Requirements?
Regulators can impose inspections, require remedial actions, and levy financial penalties: up to 2% of global annual turnover for financial entities and up to €5 million for critical ICT third-party providers found non-compliant. Regulators can also suspend or terminate contracts between financial entities and non-compliant ICT providers, making cryptographic key protection a contractual as well as a regulatory risk.
How Should a Financial Entity Approach Dora’s Cryptography Requirements Practically?
- Inventory every cryptographic key in use across ICT systems, including keys held by third-party providers.
- Map current key lifecycle controls (generation, storage, rotation, destruction) against DORA’s Article 7.2-7.3 requirements.
- Identify gaps, particularly around keys stored outside a Hardware Security Module or without documented lifecycle controls.
- Remediate gaps using centralized key management and HSM-backed storage, prioritizing systems tied to critical ICT service providers.
- Document controls and testing evidence to support DORA’s broader ICT risk management and resilience testing obligations.
How Encryption Consulting Helps
How Encryption Consulting HelpsCompliance Advisory Services map your cryptographic key management practices against DORA’s Article 7 and Article 9 requirements, while HSM-as-a-Service closes gaps in key lifecycle protection identified during that assessment. Backed by ISO/IEC 27001:2022 and SOC 2 certified practices.
Frequently Asked Questions
When did DORA come into effect?
DORA, Regulation (EU) 2022/2554, entered into force on January 16, 2023, and has applied to EU financial entities since January 17, 2025, following a two-year period for organizations to prepare.
What specific DORA articles cover cryptography?
Article 9.4(d) requires strong authentication and cryptographic key protection as part of ICT security policy. Articles 7.2 and 7.3 require protecting cryptographic keys through their entire lifecycle against loss, unauthorized access, disclosure, and modification.
Does DORA apply to companies outside the EU?
DORA applies directly to EU financial entities, but non-EU ICT third-party providers supporting EU financial entities can fall within its scope as critical service providers, subject to oversight and contractual requirements even without an EU headquarters.
What are the penalties for DORA non-compliance?
Penalties can reach up to 2% of global annual turnover for financial entities and up to €5 million for critical ICT third-party providers, alongside potential contract suspension or termination and mandated remedial action by regulators.
Close Your DORA Cryptographic Compliance Gaps
Take the next stepCompliance Advisory Services map your key management practices against DORA’s requirements, and HSM-as-a-Service closes the gaps. Simplify your DORA compliance path with Encryption Consulting.
- Key Takeaways
- What Does Dora Require Around Cryptographic Key Protection?
- Who Does DORA Apply to?
- What Happens if a Financial Entity Fails to Meet Dora's Cryptography Requirements?
- How Should a Financial Entity Approach Dora's Cryptography Requirements Practically?
- How Encryption Consulting Helps
- Frequently Asked Questions
- Close Your DORA Cryptographic Compliance Gaps
