- Docs
- Compliance
- Compliance Frameworks
- Digital Operational Resilience Act (DORA)
Digital Operational Resilience Act (DORA)
The Digital Operational Resilience Act (DORA) is a European Union regulation focused on strengthening the digital resilience of financial entities. It establishes uniform requirements to ensure that firms in the financial sector can withstand, respond to, and recover from all types of Information and Communication Technology (ICT) related disruptions and threats.
DORA came into effect in January 2023 and became fully applicable on January 17, 2025. It applies to a wide range of financial entities including banks, insurance companies, investment firms, and ICT third-party service providers—particularly cloud providers like Files.com that support financial-sector operations.
Files.com and DORA
Files.com is committed to supporting its customers in meeting their DORA compliance obligations by offering:
- Secure Infrastructure: Encryption in transit and at rest, detailed audit logs, access controls, and regional storage options.
- Business Continuity & Incident Response: Redundant systems, high availability architecture, and incident management processes ensure service continuity and rapid recovery from disruptions.
- Operational and Security Monitoring: Real-time monitoring tools, automated alerting, and SIEM integration support.
- Independent Security Validation: Files.com undergoes an annual SOC 2 Type II audit, conducted by an independent third-party firm, to validate the effectiveness of our security, availability, and confidentiality controls.
Shared Responsibility Model
As with other compliance frameworks, DORA compliance using Files.com operates under a Shared Responsibility Model:
- Files.com is responsible for the infrastructure, platform, and security controls we provide.
- Customers are responsible for configuring their usage, conducting their own resilience testing, managing risk assessments, and fulfilling regulatory reporting duties.
You must carefully configure your Files.com environment to ensure DORA compliance. We provide the tools—you are responsible for using them properly.
Final Note: You Own the Configuration
As with any compliance framework, DORA compliance with Files.com is achievable, but only if your environment is configured correctly. We provide the platform, security features, and operational tools. You are responsible for implementing and using them in a manner that aligns with DORA and other applicable regulatory requirements.
This article is not legal advice. Organizations subject to DORA are solely responsible for ensuring that their use of Files.com complies with all provisions of the regulation, including ICT risk management, incident handling, and third-party oversight.
We strongly recommend working with your legal and compliance teams to determine your specific obligations under DORA and to validate that your implementation of Files.com supports your operational resilience goals.