How Does DORA Impact Insurance Companies? Explained in Detail

An insurance company can have enough capital to absorb a major loss, but what happens when it cannot access the systems needed to process claims, communicate with customers, or manage policies? That question captures a less obvious side of digital risk in insurance. The threat is not always a cyberattack or data breach. A failed cloud service, unavailable third-party platform, technology outage, compromised account, or malfunctioning system can disrupt critical insurance operations just as quickly. As insurers become increasingly dependent on interconnected digital services, operational resilience is becoming inseparable from business resilience.
The Digital Operational Resilience Act (DORA) shifts technology risk from a narrow IT concern to a core governance and risk-management responsibility. For European insurers, the focus is no longer just on securing systems, but on ensuring critical services remain resilient when systems, providers, or processes come under stress.
DORA has applied since 17 January 2025 and introduces a common framework for managing ICT risk, reporting major ICT-related incidents, testing digital resilience, and managing risks arising from ICT third-party providers. For insurance and reinsurance undertakings within its scope, these requirements can affect governance, business continuity, incident response, testing, vendor oversight, and the way technology risks are incorporated into enterprise risk management.
So, how does DORA impact insurance companies in practice? The answer goes beyond adding another set of compliance requirements. It changes how insurers are expected to understand, govern, test, and respond to the digital dependencies behind their business.
What Is DORA and Why Does It Matter to Insurers?
DORA is an EU regulation designed to ensure that financial entities can withstand, respond to, and recover from ICT-related disruptions. For insurance companies, this means looking beyond cybersecurity alone. DORA addresses the wider ability of an organization to maintain important operations when technology fails, is disrupted, or becomes unavailable. The regulation requires financial entities within its scope to maintain a sound and documented ICT risk management framework, identify ICT-supported business functions and dependencies, monitor ICT risks, test resilience, manage ICT incidents, and address risks arising from third-party ICT providers.
The importance of this broader approach is becoming clearer. In its first annual report on major ICT-related incidents under DORA, published in June 2026, the European Supervisory Authorities reported 3,383 major ICT-related incidents during 2025. Around one-third had a cross-border impact, while system failures and external events were the main drivers. Only 10% were related to cybersecurity. This demonstrates an important point about the DORA impact on insurance companies: digital operational resilience is much broader than preventing cyberattacks.
Connect with INTERCERT for independent DORA assessment and assurance services tailored to your organization’s regulatory requirements.
How Does DORA Affect Insurance Companies?
The DORA impact on insurance companies extends well beyond cybersecurity. It reaches into governance, ICT risk management, incident response, resilience testing, business continuity, and relationships with technology providers. For insurers, the bigger shift is that digital resilience is no longer treated as a concern limited to the IT function. It becomes part of how the organization manages operational risk and protects the continuity of critical insurance services.
ICT Risk Management Becomes a Formal Business Responsibility
One of the most significant changes under DORA is the formalization of ICT risk management as part of an insurer’s broader risk management framework. Insurance companies within DORA’s scope must maintain a comprehensive and documented ICT risk management framework and identify the technology assets, information assets, business functions, dependencies, vulnerabilities, and risks that could affect their operations. These assessments must also be reviewed regularly and when significant changes occur.
For an insurer, this can involve mapping the technology supporting policy administration, claims processing, underwriting, customer-facing applications, payment systems, data platforms, cloud infrastructure, and critical third-party services. The practical shift is important: insurers are expected to look beyond whether an individual system is secure and understand how its failure could affect a critical business function. A disruption to a claims platform, for example, becomes a business resilience issue when it prevents claims from being processed. This business-impact perspective is central to the DORA requirements for insurance companies.
Senior Management Has Greater Accountability
DORA places clear responsibility for ICT risk at the management level. The management body of a financial entity is ultimately responsible for ICT risk management and must approve and oversee the relevant framework, determine ICT risk tolerance, oversee the digital operational resilience strategy, and maintain sufficient knowledge to understand the risks facing the organization.
For insurers, this means DORA for insurance companies cannot be treated as an IT-only initiative. Senior management needs visibility into which insurance services depend on critical technology, which third parties are involved, how long important operations could continue during an outage, and whether recovery arrangements are effective. Questions around technology dependencies, resilience testing, recovery capabilities, and unresolved weaknesses therefore become part of management-level risk oversight rather than remaining solely within the technology function.
Major ICT Incidents Need Structured Management and Reporting
DORA introduces a harmonized framework for identifying, managing, classifying, and reporting major ICT-related incidents. Insurance companies need processes to detect and record incidents, assess their significance, assign responsibilities, escalate serious events, respond to disruption, and capture lessons that can improve future resilience. Major ICT-related incidents must also be reported to the relevant authorities within the timelines established by the DORA reporting framework.
In practice, this creates a more structured incident lifecycle: detect → classify → escalate → report → respond → recover → learn. The objective is not simply to restore a service. Insurers also need to understand the nature and impact of an incident and use that information to improve their ICT risk management. The first DORA-wide report reinforces why this matters: 3,383 major ICT-related incidents were reported across the EU financial sector in 2025, with system failures and external events among the main drivers and around one-third having a cross-border impact.
Digital Resilience Must Be Tested
Having policies and recovery plans does not demonstrate that an insurer can withstand a serious technology disruption. DORA therefore places significant emphasis on testing digital operational resilience. Depending on the entity and applicable requirements, testing can include vulnerability assessments, scenario-based testing, penetration testing, network security assessments, performance testing, and other forms of resilience testing. ICT systems and applications supporting critical or important functions are subject to recurring testing requirements.
Certain financial entities identified under DORA must also conduct advanced threat-led penetration testing at least every three years. Not every insurance company is automatically subject to the same TLPT obligations; the requirement depends on the criteria established under DORA and the characteristics of the individual entity. For insurers, the purpose of testing is to determine whether critical services can continue, recover, and operate effectively when realistic disruption scenarios occur. It can expose weaknesses that may remain invisible in policies, procedures, or standard recovery exercises.
Third-Party ICT Risk Becomes a Major Focus
Modern insurers operate through an increasingly interconnected technology ecosystem. Cloud platforms, SaaS applications, managed service providers, cybersecurity vendors, data providers, and other ICT suppliers can become deeply embedded in everyday insurance operations. DORA treats ICT third-party risk as an integral part of ICT risk management, requiring financial entities to understand their ICT dependencies and manage the risks associated with services provided by third parties.
The issue becomes particularly important when one provider supports multiple business-critical services. An insurer could, for example, depend on the same cloud environment for claims applications, customer portals, data storage, and analytics, meaning one disruption could affect several functions simultaneously. DORA therefore makes third-party dependency a resilience question rather than simply a procurement or outsourcing issue. The first DORA incident report also highlighted the importance of third-party risk management and oversight of outsourced services, particularly as system failures and external events emerged as significant incident drivers.
Business Continuity and Recovery Become More Closely Linked to ICT Risk
Insurance companies already understand the importance of business continuity and disaster recovery. DORA brings these areas into closer alignment with ICT risk management by requiring financial entities to maintain measures that support the continuity of critical or important functions, including appropriate response and recovery arrangements, backup and restoration capabilities, and regular testing.
For an insurer, this means looking at the complete chain behind an important service. If claims processing depends on a particular application, database, cloud environment, network connection, external service, and internal team, recovery planning needs to account for those dependencies rather than focusing on the application alone. The key question becomes: If a critical technology service fails, can the insurance business continue operating? DORA therefore shifts the focus from simply having a disaster recovery document to demonstrating that recovery arrangements can maintain or restore important services during a significant technology disruption.
Legacy Systems Also Come Under Greater Attention
Legacy technology presents a particular challenge for insurers because systems that have been in place for many years can remain deeply connected to important business processes. Replacing them may introduce significant operational complexity, while continuing to rely on them without adequate risk visibility can create additional ICT risk. DORA requires financial entities other than microenterprises to conduct regular ICT risk assessments of legacy systems and consider the risks associated with major technology changes.
For insurers, this means digital resilience cannot focus only on newer cloud platforms, applications, and emerging technologies. Older policy administration, claims, and data systems can be equally important when they continue to support critical or important functions. Understanding where these systems fit within the wider technology environment, what they depend on, and what risks they introduce becomes part of the insurer’s broader ICT risk assessment.
AI and Digitalization Make DORA Even More Relevant
The DORA impact on insurance companies is becoming relevant as insurers adopt artificial intelligence and other digital technologies. EIOPA’s 2026 survey of 347 insurance undertakings across 25 countries found that nearly two-thirds were already actively using generative AI. The survey also identified hallucinations, cybersecurity, and data protection among key concerns, while highlighting significant reliance on third-party providers and pretrained or off-the-shelf AI models.
For insurers, this creates another layer of digital dependency. An AI-enabled underwriting, customer service, claims, or analytics capability may rely on external models, cloud infrastructure, APIs, data services, and other technology providers. As these technologies become embedded in insurance operations, organizations need to consider where they are hosted, what systems and data they depend on, how changes are managed, and what happens if the service becomes unavailable. DORA does not create a separate compliance category for every AI application; instead, its existing requirements around ICT risk, third-party dependencies, resilience, continuity, incident management, and testing become increasingly relevant as AI becomes part of everyday insurance operations.
What Are the Biggest DORA Challenges for Insurance Companies?
For insurers, DORA compliance is not simply about introducing new policies or completing a checklist. The more difficult task is building a clear picture of how technology supports critical insurance activities and being able to demonstrate that those activities can continue when systems, providers, or digital services fail. This becomes particularly challenging for insurers with complex technology environments, long-standing legacy platforms, and extensive reliance on external ICT providers. Some of the biggest challenges include:
Mapping Complex ICT Dependencies
Insurance operations often depend on interconnected systems for policy administration, claims processing, underwriting, payments, customer services, and data management. These systems may also rely on cloud platforms, software providers, infrastructure vendors, and other external services. Creating and maintaining an accurate view of these dependencies can be difficult, particularly when a single technology provider supports several business functions.
DORA requires insurers to identify and document their ICT-supported business functions, information assets, ICT assets, and dependencies. The challenge is keeping this information accurate as systems change, new services are introduced, and third-party relationships evolve. For insurers, resilience depends on understanding not only individual systems but also what could happen when a critical dependency becomes unavailable.
Managing Legacy Systems
Legacy technology can create a particular challenge for insurers because older policy administration, claims, and data systems may remain critical to day-to-day operations even when newer platforms are introduced. These systems may be difficult to replace, integrate, test, or monitor, while still carrying important business processes and data.
DORA does not limit ICT risk management to newer technology. Non-microentities are expected to regularly assess the ICT risks associated with legacy systems and consider risks arising from major changes to their ICT environment. This means insurers need visibility into the resilience of older technology rather than assuming that modernization alone addresses their operational risk.
Maintaining Accurate Third-Party ICT Information
Insurers increasingly depend on external ICT providers for cloud infrastructure, software, data services, managed technology, and other critical capabilities. Keeping an accurate record of these relationships can become challenging when contracts, services, subcontractors, and dependencies change over time.
DORA places third-party ICT risk within the broader ICT risk management framework. Insurers therefore need to understand which providers support critical or important functions, what services they provide, and where dependencies or concentration risks exist. This requires more than maintaining a vendor list; the information needs to remain sufficiently current to support risk assessments, continuity planning, and management decisions.
Assessing Cloud Concentration Risk
Cloud adoption can improve scalability and operational efficiency, but it can also create concentration risk when multiple insurers or multiple critical functions depend on the same provider. A disruption affecting a major cloud service can therefore have consequences beyond an individual application or business unit.
For insurers, assessing this risk requires looking beyond whether an individual provider meets security or contractual requirements. The bigger question is whether excessive dependence on a particular provider could affect the continuity of critical services. DORA brings this type of third-party dependency into a broader digital resilience discussion, making concentration and substitutability important considerations.
Establishing Effective Incident Classification and Reporting
A technology disruption does not automatically fit neatly into a predefined incident category. Insurers need processes that allow ICT incidents to be detected, assessed, classified, escalated, and reported consistently. This can be challenging when an incident initially appears minor but its operational impact becomes clearer over time.
DORA establishes a harmonized approach to ICT incident management and reporting. For major ICT-related incidents, insurers must meet defined reporting requirements and timelines, making accurate classification particularly important. The challenge is therefore not simply reporting an incident; it is ensuring that the organization has the information, responsibilities, escalation mechanisms, and decision-making processes needed to determine the appropriate response.
Testing Whether Recovery Arrangements Actually Work
Having a business continuity plan or disaster recovery procedure does not necessarily demonstrate operational resilience. Insurers need to know whether critical services can actually be restored within the required timeframe and whether dependencies on applications, infrastructure, data, and third-party providers have been properly considered.
DORA requires digital operational resilience testing across ICT systems and applications supporting critical or important functions, with specific testing obligations applying according to the type and circumstances of the financial entity. For insurers, effective testing can expose weaknesses that may not be visible during normal operations, including recovery dependencies, communication gaps, inadequate backup arrangements, or unexpected technology interactions.
Aligning Contracts With DORA Expectations
Existing contracts with ICT providers may not contain all the information, rights, or provisions needed to meet DORA expectations. Reviewing these agreements can become especially difficult where insurers have large numbers of providers, long-term contracts, complex service arrangements, or multiple layers of subcontracting.
DORA introduces specific expectations around contractual arrangements with ICT third-party service providers, including provisions relevant to access, audit, termination, security, continuity, and cooperation. The challenge for insurers is determining where existing contracts fall short and maintaining appropriate contractual visibility as relationships and services change.
Demonstrating Meaningful Management Oversight
DORA places responsibility for ICT risk at the management-body level. This creates a challenge for insurers where digital resilience has traditionally been viewed primarily as an IT or cybersecurity matter. Senior management needs enough visibility to understand material ICT risks, critical dependencies, resilience capabilities, and areas requiring attention.
This also means that management oversight needs to be demonstrable. Decisions, reviews, risk tolerance, testing outcomes, incidents, and remediation activities need to form part of an ongoing governance process rather than being addressed only when an audit or regulatory review takes place.
Maintaining Evidence Over Time
One of the less visible challenges of DORA is maintaining evidence that demonstrates ongoing compliance. Insurers may need to retain evidence relating to risk assessments, testing, incident management, business continuity, third-party oversight, management reviews, and remediation activities.
DORA requires the ICT risk management framework for entities other than microenterprises to be reviewed at least annually, as well as following major incidents and relevant audit or testing conclusions. The framework is also expected to be continuously improved based on lessons learned. This makes DORA compliance an ongoing operating discipline rather than a one-time regulatory project. For insurers, the real challenge is maintaining the visibility, governance, testing, and evidence needed to demonstrate that digital resilience continues to work as the business and its technology environment change.
Ensure your organization is prepared to meet DORA requirements for ICT risk management, incident reporting, operational resilience, and third-party ICT risk.
The Future of Insurance Resilience Starts with DORA
For insurance companies, DORA is ultimately less about adding another regulatory requirement and more about changing how digital resilience is viewed across the business. A claims platform going offline, a cloud provider becoming unavailable, or a critical technology dependency failing can quickly become an insurance operations problem. DORA brings these scenarios into the broader risk and governance conversation by requiring insurers to understand their dependencies, test their resilience, manage ICT incidents, oversee third-party risks, and demonstrate that critical services can withstand disruption.
That makes DORA an ongoing discipline rather than a compliance milestone that can simply be completed and closed. As insurance operations become more dependent on cloud services, interconnected platforms, external providers, and emerging technologies such as AI, the ability to demonstrate digital resilience will become increasingly important. For insurers, the question is no longer only whether their technology is protected. It is whether the business knows what it depends on, understands where disruption could occur, and can demonstrate that it is prepared to maintain or restore critical operations when technology fails.
As a third-party independent certification body, INTERCERT brings an independent perspective to management-system and certification engagements, with experienced auditors and internationally recognized certification services across a wide range of business sectors. For organizations addressing DORA-related governance and resilience
