How this links to the Cyber Security and Resilience Bill
Financial services are not an essential service sector in Schedule 2 of the NIS Regulations, and the Cyber Security and Resilience Bill does not add them. UK banks and insurers are instead covered by PRA and FCA operational resilience rules and the critical third parties regime, the nearest UK counterparts to DORA. The Bill can still reach financial services indirectly.
- A financial firm is not an operator of essential services under the NIS Regulations.
- Cloud and managed service providers serving financial firms can be regulated under the Bill as digital or managed service providers.
- Future Part 3 regulations could in principle cover new essential activities, but none has been proposed for finance.
- Firms with EU operations may face DORA, UK financial rules and, through their suppliers, the Bill.
What does DORA require?
DORA applies to EU banks, insurers, investment firms, payment institutions and other financial entities. It requires an ICT risk management framework, classification and reporting of major ICT-related incidents, resilience testing including threat-led penetration testing for larger firms, and management of ICT third-party risk.
It also creates an EU oversight framework for critical ICT third-party providers, such as major cloud providers, led by the European Supervisory Authorities. For financial entities, DORA takes precedence over the equivalent NIS2 provisions.
What is the UK equivalent of DORA?
The UK has no single equivalent. The PRA and FCA operational resilience rules required in-scope firms to operate important business services within impact tolerances by 31 March 2025. Separately, the critical third parties regime under the Financial Services and Markets Act 2023 lets HM Treasury designate critical suppliers to the sector; the regulators’ rules took effect on 1 January 2025 and apply once a designation is made.
These are financial regulation, not NIS. For the Bill, the practical question for a financial firm is whether its cloud and managed service suppliers are regulated, and what their customer notification duties mean for it.
DORA, UK financial rules and the Bill
| Area | DORA (EU) | UK financial regulation | Cyber Security and Resilience Bill |
|---|---|---|---|
| Who | EU financial entities | PRA and FCA regulated firms | Operators of essential services, digital and managed service providers, data centres |
| Third parties | EU oversight of critical ICT providers | Critical third parties regime (designation by HM Treasury) | Critical supplier designation by regulators |
| Financial firms directly in scope? | Yes | Yes | No, only indirectly through suppliers |
Where it appears in the Bill
- Clause 7Relevant digital service providers, including cloud services that financial firms rely on.
- Clause 9Relevant managed service providers.
- Clause 29Part 3 power to make regulations for essential activities.
References are to HL Bill 32 as brought from the Commons. Read the Bill.
Frequently asked questions
Does DORA apply to UK banks?
Not to their UK activity. DORA is EU law and applies to financial entities authorised in the EU, including EU subsidiaries of UK groups. UK firms are covered by PRA and FCA operational resilience rules and, for their key suppliers, the UK critical third parties regime. Groups operating in both markets need to map the two sets of requirements.
Are financial services in scope of the Cyber Security and Resilience Bill?
Not directly. Banking and financial market infrastructure are not sectors in Schedule 2 of the NIS Regulations, and the Bill does not add them. Financial firms feel the Bill through their suppliers: cloud providers, managed service providers and data centres they rely on can be regulated and may have to notify customers of incidents.
Is the UK critical third parties regime the same as critical supplier designation under the Bill?
No. The critical third parties regime comes from the Financial Services and Markets Act 2023: HM Treasury designates suppliers critical to the financial sector, overseen by the Bank of England, PRA and FCA. Critical supplier designation under the Bill is made by NIS regulators, and cannot start until the first Part 3 activity-critical supply regulations are in force.