What Is DORA?
DORA (the Digital Operational Resilience Act, EU 2022/2554) is an EU regulation that establishes uniform requirements for ICT risk management, incident reporting, resilience testing, and third-party risk oversight across the financial sector — including banks, insurers, investment firms, and critical ICT service providers. It applies directly across all EU member states without requiring national transposition, and became fully applicable on January 17, 2025. DORA requires financial entities to maintain a comprehensive register of ICT third-party providers, test their operational resilience regularly, and report major ICT-related incidents to regulators within defined timeframes. Because financial institutions rely heavily on automated systems, APIs, and interconnected service providers, DORA places significant emphasis on understanding and controlling the ICT dependencies — including the credentials and machine identities — that underpin financial services.
Why It Matters
DORA's third-party and ICT-risk requirements put non-human identities directly in scope, because the ICT dependencies regulators care about are largely mediated by service accounts, API keys, and OAuth tokens connecting financial institutions to their vendors and internal systems. A financial entity cannot produce an accurate ICT third-party register, or credibly test operational resilience, without knowing which machine identities exist, what they can reach, and whether they're still needed. This is where the exposure concentrates: non-human identities routinely outnumber human employees 45 to 1, and a mid-sized institution can be running thousands of largely unmonitored service accounts and API keys. OWASP's 2025 NHI Top 10 research found that 80% of identity breaches involve a non-human identity — a statistic that should concern any DORA-regulated entity relying on interconnected APIs and automated trading, settlement, or reporting systems, where a single compromised credential can cascade into a reportable operational incident.
How Cydenti Helps
Cydenti maps the machine identities that sit behind a financial institution's ICT dependencies — service accounts, API keys, and OAuth tokens connecting internal systems to third-party providers — and keeps that map current rather than reconstructed once a year for an audit. That gives risk and compliance teams a working input for their ICT third-party register and a concrete way to demonstrate control over automated access when DORA resilience testing or incident-reporting obligations require it. It's a foundation for showing regulators that operational resilience extends to the credentials, not just the applications.
Explore →Frequently Asked Questions
Who does DORA apply to?
DORA applies to financial entities operating in the EU — banks, insurers, investment firms, payment providers — and to the critical ICT third-party providers that serve them. It became fully applicable on January 17, 2025, and requires these organizations to manage ICT risk, test resilience, and report major incidents within regulated timeframes.
How does DORA relate to non-human identities?
DORA requires financial entities to maintain visibility into their ICT dependencies, including third-party providers and the systems connecting to them. Because those connections are typically made through service accounts, API keys, and OAuth tokens, an accurate DORA risk picture depends on knowing which non-human identities exist and what they can access.
Discover the machine identities you didn't know you had
— in 27 minutes, for free.
NIS2 enforcement begins October 1, 2026. The Audit Flash delivers your complete NHI exposure snapshot — service accounts, orphaned credentials, OAuth grants, AI agents — with a first report in 3 hours. No commitment.
No commitment • No credit card • Data hosted in Europe • Response within 24h