---
title: "EU DORA penalties and fines: enforcement powers and limits"
canonical_url: "https://www.sorena.io/artifacts/eu/digital-operational-resilience-act/penalties-and-fines"
source_url: "https://www.sorena.io/artifacts/eu/digital-operational-resilience-act/penalties-and-fines"
author: "Sorena AI"
description: "Official source guide to DORA enforcement: competent-authority powers, administrative penalties, remedial measures, publication rules, and Lead Overseer penalty payments for critical ICT third-party providers."
published_at: "2026-05-09"
updated_at: "2026-05-09"
keywords:
  - "EU DORA penalties"
  - "DORA fines"
  - "DORA enforcement"
  - "administrative penalties"
  - "remedial measures"
  - "critical ICT third-party provider"
  - "Lead Overseer"
  - "EU DORA"
  - "critical ICT third-party providers"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# EU DORA penalties and fines: enforcement powers and limits

Official source guide to DORA enforcement: competent-authority powers, administrative penalties, remedial measures, publication rules, and Lead Overseer penalty payments for critical ICT third-party providers.

*Artifact Guide* *EU*

## EU DORA penalties and fines

DORA enforcement is not a single EU fine schedule for every breach. The regulation gives competent authorities supervisory, investigatory, sanctioning, and remedial powers, while Member States set national administrative penalty rules.

This page helps separate financial-entity enforcement exposure from the distinct Lead Overseer penalty-payment regime for critical ICT third-party service providers.

This DORA penalties and fines page focuses on what the regulation itself supports: competent-authority powers, administrative penalties and remedial measures, criteria for setting sanctions, publication safeguards, and the separate periodic penalty payments available to a Lead Overseer when a critical ICT third-party service provider does not comply with oversight measures. It does not list unsupported Member State fine amounts.

## What DORA actually says about fines

DORA requires Member States to establish appropriate administrative penalties and remedial measures for breaches of the regulation, and to ensure effective implementation. The regulation does not provide one uniform EU-wide maximum fine for every financial entity breach in the way some other EU regimes do.

For a visitor assessing exposure, the first distinction is therefore between EU-level DORA powers and national penalty rules. DORA supplies the minimum enforcement toolkit and sanctioning factors; Member State law supplies the detailed national administrative penalty framework unless the Member State uses criminal penalties for the same breaches.

- Do not treat DORA as a single pan-EU fine table for financial entities.
- Map the breach to the competent authority responsible for the financial entity and the national law implementing DORA enforcement.
- Separate monetary penalties from remedial measures such as cease-and-desist orders, corrective measures, temporary or permanent cessation of practices, and public notices.
- Record whether the matter is handled through administrative penalties, remedial measures, or criminal penalties under national law.

Sources for this answer:

- [Regulation (EU) 2022/2554 (DORA)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554&ref=sorena.io) - Articles 50 to 54 ground DORA administrative penalties, remedial measures, criminal-penalty option, notification duties, and publication rules.

## Competent-authority powers for financial-entity breaches

DORA requires competent authorities to have the supervisory, investigatory, and sanctioning powers needed to perform their duties. Those powers include access to relevant documents and data, on-site inspections or investigations, and the ability to require corrective and remedial measures for breaches.

The minimum remedial and sanctioning toolkit is broad. Competent authorities must be able to order a person to stop breaching conduct, require temporary or permanent cessation of practices that conflict with DORA, adopt measures of a pecuniary nature to ensure continued compliance, require certain data traffic records where national law permits and a breach is reasonably suspected, and issue public statements identifying the person and nature of the breach.

- Prepare for evidence requests: keep ICT risk management, incident reporting, testing, third-party risk, and register records retrievable by legal entity and supervisory perimeter.
- Keep management-body accountability records because DORA allows national law to extend penalties or remedial measures to management-body members and other responsible individuals.
- Treat remediation orders as enforcement outcomes, not only financial fines.
- Keep a written appeal and response path because DORA requires reasoned decisions and a right of appeal for relevant administrative penalty or remedial-measure decisions.

Sources for this answer:

- [Regulation (EU) 2022/2554 (DORA)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554&ref=sorena.io) - Article 50 defines the minimum competent-authority powers and administrative penalties or remedial measures for DORA breaches.

## How authorities set the type and level of a DORA sanction

DORA tells competent authorities to exercise penalty and remedial powers through their national legal frameworks. When determining the type and level of an administrative penalty or remedial measure, authorities must consider whether the breach was intentional or negligent and assess the circumstances of the breach.

The regulation lists sanctioning factors that are practical risk indicators for compliance teams: materiality, gravity, duration, responsibility, financial strength, profits gained or losses avoided, third-party losses, cooperation with the authority, and previous breaches.

- Build the enforcement file around facts that match the DORA sanctioning factors: timeline, affected functions, affected customers or counterparties, root cause, duration, loss impact, and remediation status.
- Document cooperation with the competent authority without using cooperation as a substitute for remediation.
- Preserve evidence of avoided recurrence: corrected controls, owner sign-off, retesting, updated contracts, incident process changes, or register corrections.
- Avoid unsupported fine estimates unless they come from the relevant Member State rule or supervisory decision.

Sources for this answer:

- [Regulation (EU) 2022/2554 (DORA)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554&ref=sorena.io) - Article 51 lists the factors competent authorities consider when setting administrative penalties or remedial measures.

## Publication, appeal, and criminal-penalty limits

DORA includes safeguards around enforcement publication. Competent authorities must publish final administrative penalty decisions on their official websites without undue delay after the addressee has been notified, but publication can be deferred, anonymised, or withheld in specified circumstances such as disproportionate damage, personal-data concerns, market-stability risk, or an ongoing criminal investigation.

Published penalty information must remain online only for the period necessary to meet the DORA publication rule and cannot exceed five years. If a published decision is appealed, the competent authority must add appeal information and later outcome information, including any judicial annulment.

- Track whether the enforcement matter is final, appealed, anonymised, deferred, or not published.
- Prepare public-statement facts carefully because public notices can identify the natural or legal person and the nature of the breach.
- Check whether the Member State has chosen criminal penalties for the same breach category, because DORA allows Member States not to create administrative penalties or remedial measures where criminal penalties apply.
- Do not assume non-public handling; DORA publication is the baseline for final administrative penalty decisions, subject to the listed safeguards.

Sources for this answer:

- [Regulation (EU) 2022/2554 (DORA)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554&ref=sorena.io) - Articles 52 and 54 cover the criminal-penalty option and publication of administrative penalties.

## Critical ICT third-party provider penalty payments

DORA has a separate EU-level oversight regime for critical ICT third-party service providers. A Lead Overseer can request information, conduct investigations and inspections, request reports on actions or remedies, and issue recommendations. Critical providers must cooperate in good faith.

If a critical ICT third-party service provider wholly or partly fails to comply with required oversight measures after at least 30 calendar days from notification, the Lead Overseer must adopt a decision imposing a periodic penalty payment to compel compliance. The payment is imposed daily until compliance, for no more than six months, and may be up to 1% of the provider's average daily worldwide turnover in the preceding business year.

- This periodic penalty payment is for critical ICT third-party service providers, not a general fine cap for all DORA financial-entity breaches.
- The Lead Overseer considers gravity, duration, intent or negligence, and cooperation when setting the penalty-payment amount.
- Before imposing the payment, the provider must have an opportunity to be heard and access to the file, subject to confidentiality and business-secret limits.
- The Lead Overseer must disclose imposed periodic penalty payments unless disclosure would seriously jeopardise financial markets or cause disproportionate damage.

Sources for this answer:

- [Regulation (EU) 2022/2554 (DORA)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554&ref=sorena.io) - Article 35 grounds the Lead Overseer powers and periodic penalty-payment regime for critical ICT third-party service providers.
- [ESMA news: ESAs designate critical ICT third-party providers under DORA](https://www.esma.europa.eu/press-news/esma-news/european-supervisory-authorities-designate-critical-ict-third-party-providers?ref=sorena.io) - Grounds the practical existence of the DORA critical ICT third-party provider oversight framework and ESA designation process.

## Oversight fees are not the same as enforcement fines

Critical ICT third-party service providers can also owe oversight fees under DORA's oversight framework. Those fees fund the Lead Overseer's oversight work and are calculated under a delegated regulation; they should not be described as penalties or fines.

For penalty analysis, keep three buckets separate: national administrative penalties and remedial measures for DORA breaches, criminal penalties where Member State law uses them, and EU-level periodic penalty payments used by the Lead Overseer to compel critical ICT third-party provider compliance with oversight measures.

- Do not mix annual oversight fees with breach penalties in public copy, risk registers, or board reporting.
- For critical providers, keep audited turnover evidence because it is relevant to oversight-fee calculation and can also be relevant to the Article 35 periodic penalty-payment ceiling.
- For financial entities, focus enforcement readiness on DORA obligations, competent-authority requests, remediation evidence, and the applicable Member State penalty framework.
- Escalate any country-specific fine amount only when the national legal source or supervisory decision is available.

**Does DORA set one EU-wide maximum fine for financial entities?**

No. DORA requires Member States to establish appropriate administrative penalties and remedial measures and gives competent authorities a minimum enforcement toolkit, but it does not provide one uniform EU-wide fine cap for all financial-entity breaches.

**Can DORA penalties apply to management-body members?**

Yes, where national law allows it. DORA requires Member States to give competent authorities power to apply relevant administrative penalties and remedial measures to management-body members and other individuals who are responsible for a breach under national law.

**What is the DORA penalty-payment cap for critical ICT third-party providers?**

For non-compliance with specified Lead Overseer measures, the periodic penalty payment can be imposed daily until compliance for no more than six months and can be up to 1% of the critical provider's average daily worldwide turnover in the preceding business year.

Sources for this answer:

- [Delegated Regulation (EU) 2024/1505 on DORA oversight fees](https://eur-lex.europa.eu/eli/reg_del/2024/1505/oj?ref=sorena.io) - Grounds the distinction between DORA oversight fees for critical ICT third-party service providers and enforcement fines or penalty payments.
- [Regulation (EU) 2022/2554 (DORA)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554&ref=sorena.io) - Articles 35 and 50 to 54 distinguish Lead Overseer periodic penalty payments, national administrative penalties, remedial measures, criminal penalties, and publication rules.

*Recommended next step*

*Placement: before sources*

## Turn DORA enforcement rules into an evidence file

Sorena can help separate national penalty exposure, remedial-measure risk, and critical-provider oversight issues into cited facts, owners, and evidence requests.

- [Open Research Copilot for EU DORA](/solutions/research-copilot.md): Ask questions tied to cited sources about DORA enforcement powers, competent-authority measures, and critical-provider oversight penalties.
- [Talk through implementation](/contact.md): Review your DORA enforcement-readiness file, source gaps, and evidence plan with Sorena.

## Primary sources

- [Regulation (EU) 2022/2554 (DORA)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554&ref=sorena.io) - Primary DORA source for competent-authority enforcement powers, administrative penalties, remedial measures, sanctioning factors, publication rules, and Lead Overseer periodic penalty payments.
  - Quote: "Administrative penalties and remedial measures"
- [Delegated Regulation (EU) 2024/1505 on DORA oversight fees](https://eur-lex.europa.eu/eli/reg_del/2024/1505/oj?ref=sorena.io) - Grounds the oversight-fee bucket for critical ICT third-party providers so it is not confused with breach penalties or fines.
  - Quote: "oversight fees"
- [ESMA news: ESAs designate critical ICT third-party providers under DORA](https://www.esma.europa.eu/press-news/esma-news/european-supervisory-authorities-designate-critical-ict-third-party-providers?ref=sorena.io) - Grounds the DORA oversight framework for designated critical ICT third-party providers.
  - Quote: "DORA oversight framework"

## Related Topic Guides

- [DORA Critical or Important Functions: mapping ICT dependencies and evidence](/artifacts/eu/digital-operational-resilience-act/critical-and-important-functions.md): How DORA critical or important functions affect ICT service mapping, third-party contracts, register-of-information records, incidents, testing, and evidence.
- [DORA deadlines and compliance calendar for financial entities](/artifacts/eu/digital-operational-resilience-act/deadlines-and-compliance-calendar.md): Calendar the official source DORA dates and recurring evidence: 17 January 2025 application, incident reporting clocks, register updates, annual reporting, TLPT cadence, and CTPP oversight milestones.
- [DORA ICT Third-Party Contract Remediation Workflow](/artifacts/eu/digital-operational-resilience-act/contract-remediation-workflow.md): A DORA workflow for remediating ICT third-party contracts covering critical or important functions, subcontracting, audit rights, exits, register updates, and evidence.
- [DORA ICT Third-Party Contracts FAQ](/artifacts/eu/digital-operational-resilience-act/faq/ict-third-party-contracts.md): What DORA requires in ICT third-party contracts, including critical or important functions, audit and access rights, termination, exit, subcontracting, register updates, and evidence.
- [DORA ICT third-party risk and contract clauses guide](/artifacts/eu/digital-operational-resilience-act/third-party-risk-and-contract-clauses.md): Official source DORA guide for financial entities in scope, ICT third-party risk, contract clauses, subcontracting controls, register evidence, audit rights, exit planning, and oversight.
- [DORA incident classification forms: criteria, fields, and reporting clocks](/artifacts/eu/digital-operational-resilience-act/incident-classification-forms.md): Official source guide to DORA ICT incident classification forms: major-incident criteria, significant cyber-threat notifications, report fields, time limits, evidence, and reclassification records.
- [DORA incident clock workflow: classification, reports, deadlines, and evidence](/artifacts/eu/digital-operational-resilience-act/incident-clock-workflow.md): Official source DORA workflow for starting the major-incident reporting clock, classifying ICT incidents, submitting initial, intermediate, and final reports, and preserving authority evidence.
- [DORA major ICT incident reporting: classification, reports, and timing](/artifacts/eu/digital-operational-resilience-act/major-incident-reporting.md): Official source DORA guide to major ICT-related incident classification, initial notifications, intermediate and final reports, competent authority routing, and significant cyber threat notifications.
- [DORA major ICT incident thresholds: what triggers reporting?](/artifacts/eu/digital-operational-resilience-act/faq/major-incident-thresholds.md): FAQ on DORA major ICT-related incident classification thresholds, recurring incidents, reporting triggers, and evidence inputs based on EU DORA RTS and ITS texts.
- [DORA Register of Information FAQ: ICT Third-Party Arrangements](/artifacts/eu/digital-operational-resilience-act/faq/register-of-information.md): FAQ on the DORA register of information: who maintains it, which ICT third-party arrangements it covers, template fields, critical functions, reporting, data quality, and evidence.
- [DORA Register of Information Import and Build Workflow](/artifacts/eu/digital-operational-resilience-act/roi-import-and-build-workflow.md): Build a DORA register of information from procurement, vendor, contract, service, function, and subcontractor data using the official register templates and validation checks.
- [DORA Register of Information Template: ICT Provider Fields and Evidence](/artifacts/eu/digital-operational-resilience-act/dora-register-of-information-template.md): An official source DORA register of information template for ICT third-party contracts, provider hierarchy, critical functions, dates, statuses, reporting, and evidence.
- [DORA TLPT selection: who can be required to test?](/artifacts/eu/digital-operational-resilience-act/faq/tlpt-selection.md): FAQ on DORA threat-led penetration testing selection: who identifies financial entities, what criteria are used, what the TLPT authority validates, and what evidence to keep.
- [DORA vs EBA outsourcing guidelines: ICT third-party risk comparison](/artifacts/eu/digital-operational-resilience-act/dora-vs-eba-outsourcing-guidelines.md): Compare binding DORA ICT third-party risk duties with the EBA/ESA outsourcing baseline for registers, critical functions, contracts, subcontracting, exit, incident reporting, and evidence.
- [DORA vs ISO 22301: ICT resilience and business continuity compared](/artifacts/eu/digital-operational-resilience-act/dora-vs-iso-22301.md): Compare DORA's binding ICT operational resilience duties for financial entities with ISO 22301's business continuity management system requirements.
- [DORA vs ISO/IEC 27001: legal ICT resilience obligations and ISMS controls](/artifacts/eu/digital-operational-resilience-act/dora-vs-iso-27001.md): Compare EU DORA and ISO/IEC 27001 across scope, governance, incident reporting, testing, ICT third-party risk, certification, evidence, overlap, and gaps.
- [DORA vs NIS2: financial-sector obligations, overlap, and evidence](/artifacts/eu/digital-operational-resilience-act/dora-vs-nis2.md): Compare DORA and NIS2 for financial entities, ICT providers, incident reporting, management accountability, third-party risk, supervisory routes, and reusable evidence.
- [DORA vs PSD2 incident reporting: major ICT and payment incidents](/artifacts/eu/digital-operational-resilience-act/dora-vs-psd2-incident-reporting.md): Compare DORA major ICT-related incident reporting with PSD2 major operational or security payment incident reporting, including scope, triggers, report stages, recipients, and evidence.
- [EU DORA Applicability Test for Financial Entities and ICT Providers](/artifacts/eu/digital-operational-resilience-act/applicability-test.md): An official source DORA applicability test for financial-entity scope, ICT third-party services, critical or important functions, exclusions, proportionality, and evidence.
- [EU DORA Compliance Checklist for Financial Entities](/artifacts/eu/digital-operational-resilience-act/checklist.md): An official source DORA checklist covering ICT risk governance, major incident reporting, resilience testing, TLPT, ICT third-party contracts, register-of-information records, and audit evidence.
- [EU DORA Compliance Obligations and Evidence Guide](/artifacts/eu/digital-operational-resilience-act/compliance.md): An official source DORA compliance guide covering ICT risk management, incident reporting, resilience testing, TLPT, ICT third-party risk, registers, governance, oversight, and evidence.
- [EU DORA FAQ: scope, incidents, ICT contracts, testing, and evidence](/artifacts/eu/digital-operational-resilience-act/faq.md): Concise DORA FAQ covering who is in scope, proportionality, ICT third-party contracts, register-of-information records, major ICT incident thresholds and reporting, TLPT, testing, enforcement, and evidence.
- [EU DORA ICT risk management control baseline](/artifacts/eu/digital-operational-resilience-act/ict-risk-management-control-baseline.md): An official source DORA control baseline for ICT risk governance, asset and dependency mapping, protection, detection, response, recovery, testing, third-party risk, and evidence.
- [EU DORA ICT subcontracting chain controls for critical functions](/artifacts/eu/digital-operational-resilience-act/subcontracting-chain-controls.md): DORA guide to ICT subcontracting chains for critical or important functions: prior assessment, contract conditions, register fields, monitoring, exit rights, and evidence.
- [EU DORA Register of Information Data Model: templates, fields, and evidence](/artifacts/eu/digital-operational-resilience-act/register-of-information-data-model.md): Field-level guide to the EU DORA register of information data model: templates B_01 to B_07, provider identifiers, contract links, subcontracting chains, critical-function assessments, dates, and export evidence.
- [EU DORA Requirements Overview: ICT risk, incidents, testing, and third-party risk](/artifacts/eu/digital-operational-resilience-act/requirements.md): An official source overview of the main EU DORA requirements for financial entities: governance, ICT risk management, incident reporting, resilience testing, TLPT, ICT third-party risk, register of information, oversight, proportionality, and evidence.
- [EU DORA Scope and Covered Entities: financial entities and ICT providers](/artifacts/eu/digital-operational-resilience-act/scope-and-covered-entities.md): Classify whether DORA applies to a financial entity, ICT third-party provider, group arrangement, branch, or critical ICT service dependency.
- [EU DORA Scope and Proportionality Workflow](/artifacts/eu/digital-operational-resilience-act/scope-and-proportionality-workflow.md): Classify DORA covered entities, simplified-framework status, critical or important functions, ICT dependencies, evidence records, and governance approvals.
- [EU DORA testing and TLPT readiness guide](/artifacts/eu/digital-operational-resilience-act/testing-and-tlpt-readiness.md): An official source DORA guide for resilience testing, TLPT eligibility, authority interaction, test evidence, remediation plans, and avoiding unsupported testing cadence.
- [EU DORA TLPT eligibility workflow for financial entities](/artifacts/eu/digital-operational-resilience-act/tlpt-eligibility-workflow.md): Check how DORA TLPT authorities identify financial entities for threat-led penetration testing and what evidence supports scope, readiness, providers, and governance.
- [EU DORA TLPT Runbook: scope, providers, reports, and remediation](/artifacts/eu/digital-operational-resilience-act/tlpt-runbook.md): Build a DORA threat-led penetration testing runbook around authority coordination, scope validation, provider controls, active testing, closure reports, remediation, and attestation.
- [How does proportionality work under EU DORA?](/artifacts/eu/digital-operational-resilience-act/faq/proportionality.md): An official source FAQ on DORA proportionality: what can be scaled, who may use the simplified ICT risk framework, what evidence supports the decision, and which duties cannot be waived.
- [How to build a DORA register of information](/artifacts/eu/digital-operational-resilience-act/register-of-information-how-to-build.md): Build a DORA register of information from contracts, ICT services, providers, functions, subcontractors, risk assessments, audit evidence, exit plans, and export checks.


---

[Privacy Policy](https://www.sorena.io/privacy) | [Terms of Use](https://www.sorena.io/terms-of-use) | [DMCA](https://www.sorena.io/dmca) | [About Us](https://www.sorena.io/about-us)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/eu/digital-operational-resilience-act/penalties-and-fines
