Digital Operational Resilience Act (DORA) and Alohi

The Digital Operational Resilience Act (DORA), Regulation (EU) 2022/2554, is an EU regulation that came into force on 16 January 2023 and became fully applicable on 17 January 2025. It sets out a legally binding framework for ICT risk management, incident reporting, resilience testing and third-party oversight across the EU financial sector.

DORA was introduced to harmonise ICT risk standards across all EU member states, so that the digital operational resilience of financial entities, and of the ICT providers they depend on, meets a single, consistent standard.

Who DORA applies to: DORA applies directly to around 20 types of EU financial entities, including banks, payment and e-money institutions, investment firms, asset managers, insurers and insurance intermediaries. These entities must also manage the risks arising from the ICT third-party service providers they rely on. A small number of ICT providers designated as "critical" by the European Supervisory Authorities are also directly overseen under DORA.

The five pillars of DORA

1. ICT risk management

Financial entities must maintain a comprehensive ICT risk management framework covering identification, protection, detection, response and recovery. Financial entities must assess whether their ICT providers apply appropriate information security standards.

2. ICT-related incident management and reporting

Major ICT-related incidents must be classified, managed and reported to regulators in a standardised way. Service providers are expected to support their financial clients in meeting mandatory reporting timelines.

3. Digital operational resilience testing

ICT systems must be tested regularly, from vulnerability assessments to advanced threat-led penetration testing (TLPT) for significant entities. Providers supporting critical functions may be asked to take part in client-led testing.

4. ICT third-party risk management

Financial entities must actively manage their ICT supply chain, including contractual requirements, exit strategies and ongoing oversight of their technology providers. Providers are expected to be transparent and auditable.

5. Information and intelligence sharing

Financial entities and their trusted service providers are encouraged to share cyber threat intelligence voluntarily, to strengthen resilience across the ecosystem.

How DORA applies to Alohi

Alohi SA is not a financial entity and has not been designated as a critical ICT third-party service provider under DORA's oversight framework, so DORA does not apply to Alohi directly. However, many of our customers are banks, insurers and financial services firms that fall within DORA's scope, and they use Sign.Plus and Fax.Plus as part of their day-to-day workflows.

For these customers, Alohi acts as an ICT third-party service provider. Under DORA, our financial-sector customers must make sure their ICT providers maintain appropriate resilience, governance and transparency. Alohi supports this by providing the information and documentation our customers need for their due diligence and contractual requirements.

Requesting documentation for due diligence

If your organisation is subject to DORA and you need information about Alohi as part of your vendor assessment, please contact our support team and include:

  • Your organisation's name and the account email address
  • The product(s) you use (Sign.Plus, Fax.Plus)
  • The documentation or questionnaire you need completed

You can also find an overview of our security and compliance practices on the Alohi Trust Center.

This article is for general information only and does not constitute legal advice. Please consult your own legal or compliance advisers about your obligations under DORA.

Was this article helpful?
0 out of 0 found this helpful
More articles in this section