DORA does not set a maximum fine for financial entities. Article 50(3) of Regulation (EU) 2022/2554 leaves it to each Member State to "lay down rules establishing appropriate administrative penalties and remedial measures", which "shall be effective, proportionate and dissuasive". What the Regulation does fix is a floor of powers every regulator must have, the option to sanction members of the management body, the factors that set the amount, and a duty to publish final decisions. The only percentage in the whole text is the periodic penalty payment in Article 35(8): up to 1% of average daily worldwide turnover, per day, for up to six months. It applies to designated critical ICT third-party service providers, not to the banks, insurers and payment firms that use them. So the real figure for your firm is in your own country's law, and it is already being used: in July 2026 the Austrian FMA fined a credit institution EUR 42,000 for late incident reports.
This guide sets out what the Regulation says, what two national laws added, and what the common figures on other pages get wrong. The obligations those penalties enforce are in DORA requirements explained.
| Question | Answer | Where it says so |
|---|---|---|
| Who sets fines for financial entities? | Each Member State, in national law | Article 50(3) |
| Is there an EU wide ceiling for financial entities? | No | Article 50 contains no amount |
| Can managers be sanctioned personally? | Yes, where national law provides for it | Article 50(5) |
| What decides the size of a penalty? | Intent or negligence, gravity, duration, financial strength, profits, losses, cooperation, previous breaches | Article 51(2) |
| Are penalties published? | Yes, final decisions, with names unless that would be disproportionate, for up to five years | Article 54 |
| Who can get 1% of daily turnover? | Critical ICT third-party service providers only, for up to six months | Article 35(6) to (8) |
Does DORA set a maximum fine?
Not for financial entities. Article 50(1) gives competent authorities "all supervisory, investigatory and sanctioning powers necessary to fulfil their duties", and Article 50(3) hands the content of the penalties to the Member States. Article 52 adds that a Member State may choose criminal penalties instead, and need not lay down administrative ones for breaches its criminal law already covers. Under Article 53 each Member State had to notify its implementing rules to the Commission and the three ESAs by 17 January 2025, the date DORA started to apply.
That is a different design from the neighbouring EU laws, which write ceilings into the text. NIS2 Article 34(4) sets a maximum of at least EUR 10 million or 2% of worldwide turnover for essential entities, the GDPR Article 83(5) up to EUR 20 million or 4%, and the Cyber Resilience Act Article 64(2) up to EUR 15 million or 2.5%. For a financial entity that NIS2 would otherwise catch, DORA Article 1(2) makes DORA the sector specific act, so the NIS2 figures are not the ones to plan around.
What penalties must every regulator be able to impose?
Article 50 sets a floor that every national law has to reach. Under Article 50(2) the competent authority can access any document or data it considers relevant and take a copy, carry out on site inspections and investigations, summon representatives for oral or written explanations, and "require corrective and remedial measures for breaches". Article 50(4) then lists at least five penalties or measures the authority must be able to apply:
| Point | What the authority can do |
|---|---|
| 50(4)(a) | Order the person to cease the conduct in breach and not repeat it |
| 50(4)(b) | Require the temporary or permanent cessation of a practice it considers contrary to the Regulation |
| 50(4)(c) | Adopt any type of measure, including of pecuniary nature, to keep the financial entity compliant |
| 50(4)(d) | Require existing data traffic records held by a telecommunication operator, where national law permits and a breach is reasonably suspected |
| 50(4)(e) | Issue public notices, including statements naming the person and the nature of the breach |
Point (c) is where money enters the text, and it carries no figure. Article 50(6) requires every decision under Article 50(2)(c) to be "properly reasoned" and open to appeal.
Can managers be fined personally under DORA?
Yes, if national law provides for it. Article 50(5) says that where the penalties apply to legal persons, Member States shall give competent authorities the power to apply them, "subject to the conditions provided for in national law, to members of the management body, and to other individuals who under national law are responsible for the breach". DORA sets no amount for individuals. Austria shows what that looks like in practice: section 7 of its DORA enforcement act makes the responsible person liable to a fine of up to EUR 150,000. Article 5 already puts the management body in charge of ICT risk, so this is the paragraph that gives that duty a personal edge; the governance side is covered in the ICT risk management framework guide.
What do national DORA laws set?
This is where the euro figures are. Two examples from the primary texts:
| Country and law | Who | Maximum |
|---|---|---|
| Austria, DORA Vollzugsgesetz, section 7 | The responsible natural person, for breaches of the listed DORA articles | EUR 150,000 |
| Austria, DORA Vollzugsgesetz, section 8(3) | The legal person | EUR 500,000 or 1% of annual total net turnover, whichever is higher |
| Germany, KWG section 56(5e) with (6) no. 1 | Late or incomplete major incident reports under Article 19(4); TLPT not carried out under Article 26(1) | EUR 5 million |
| Germany, KWG section 56(5e) with (6) no. 2 | Breach of an enforceable order under, among others, Articles 6(5), 28(3) and 42(6); outsourcing reports and notifications under Article 28(3); Article 45(3) notifications | EUR 500,000 |
Read these as examples, not as a European scale. The German figures come from the Banking Act, which covers credit institutions; other German sector laws carry their own provisions. Other Member States chose other amounts and other routes, including criminal law under Article 52. The Austrian act and section 56 of the KWG are linked in the sources below; for any other country, find the act that implements DORA for your sector and read its penalty section.
Has anyone been fined under DORA yet?
Yes. On 14 July 2026 the Austrian Financial Market Authority announced a fine of EUR 42,000 on Western Union International Bank GmbH as a legal person, for "repeated breaches of the reporting obligations pursuant to Article 19 (4)" of DORA in conjunction with Article 5(1) of Delegated Regulation (EU) 2025/301. The bank had made several delayed initial and intermediate reports on major ICT related incidents. The penal order was issued in accelerated proceedings and is legally final.
Two things stand out. The breach was lateness, not the incidents themselves, and the evidence was the bank's own timestamps. That makes the reporting clocks the cheapest exposure to close; they are set out in DORA major incident classification.
How do regulators decide the amount?
Article 51(2) tells the competent authority to take into account "the extent to which the breach is intentional or results from negligence" and, where appropriate, seven circumstances: the materiality, gravity and duration of the breach; the degree of responsibility; the financial strength of the person responsible; profits gained or losses avoided; losses caused to third parties; the level of cooperation with the authority; and previous breaches. Most of those are things a firm controls after the fact. A breach found, reported and fixed with a clear record reads very differently from one an inspection uncovers.
Are DORA penalties made public?
Yes. Article 54(1) requires competent authorities to publish on their websites, without undue delay, any decision imposing an administrative penalty that can no longer be appealed. The publication covers "the type and nature of the breach, the identity of the persons responsible and the penalties imposed". Where naming would be disproportionate, endanger financial stability or an ongoing criminal investigation, the authority must defer publication, publish anonymously, or in narrow cases not publish at all. Pending appeals and their outcomes are added. Under Article 54(6) a publication stays online only as long as necessary and never more than five years. Separately, Article 50(4)(e) lets the authority issue a public notice naming the person as a measure in its own right.
What penalties apply to critical ICT third-party providers?
A separate regime. On 18 November 2025 the ESAs published the first list of 19 designated critical ICT third-party providers, including the large cloud providers. Each has a Lead Overseer with the Article 35(1) powers to request information, investigate, inspect and issue recommendations. If a provider fails to comply with a request, investigation, inspection or report demand under Article 35(1) points (a) to (c), and at least 30 calendar days have passed since it was notified, the Lead Overseer must impose a periodic penalty payment. It runs daily until compliance, for no more than six months, at up to 1% of the provider's average daily worldwide turnover in the preceding business year. The payments are administrative, enforceable, go to the EU budget, and are disclosed to the public unless that would seriously jeopardise the financial markets or cause disproportionate damage. The provider must be heard first.
Financial entities feel this through Article 42. Where a provider's risks are not addressed, a competent authority may, "as a measure of last resort", require a financial entity to suspend use of the service in part or completely and, where necessary, to terminate the contract. That is why the exit plans in the DORA vendor register guide are not paperwork. Payment firms often see the 1% figure applied to them; DORA for payment institutions explains why it does not.
What do other pages on DORA fines get wrong?
Most of page one repeats the same set of figures, and none of them is in the Regulation. The first is a fine of "up to 2% of total annual worldwide turnover" for financial entities; DORA contains no such cap. The second is "1% of average daily turnover" presented as a penalty on banks; it is the Article 35(8) periodic penalty and applies only to critical ICT providers. The third is EUR 1 million for individual managers, and the fourth EUR 5 million for critical providers; DORA sets no amount for either, and the only euro amounts anywhere in the Regulation are size thresholds in the Article 3 definitions. Several of those pages also cite "Article 97" for supervisory powers. DORA ends at Article 64.
The opposite error is to conclude that no fixed EU figure means low exposure. The national amounts above are real, the Austrian fine shows they are applied, and publication under Article 54 means a customer can read about it.

Check your own exposure
Fill in the middle column. Most firms can answer the first row in ten minutes and have never written it down.
| Question | Your answer | Why it matters |
|---|---|---|
| Which national act implements DORA penalties for your sector? | That act, not DORA, holds the euro amounts. | |
| What is its maximum for the firm, and for an individual? | Article 50(5) reaches managers only on national law's terms. | |
| Were all major incident reports this year filed inside the clocks? | The first published DORA fine was for late initial and intermediate reports. | |
| Is every open supervisory finding on a dated remediation plan? | Cooperation and duration both count under Article 51(2). | |
| Do your ICT contracts with critical providers allow suspension and exit? | Article 42(6) can require either as a last resort. | |
| Who would see a published decision about you? | Article 54 decisions stay online for up to five years. |
DORA in Venvera runs the incident clocks, the register of information and the supervisory findings as records with owners and dates, so the evidence behind Article 51(2) exists before anyone asks. What a supervisory review looks like is in DORA audit: what to expect, and the free compliance check gives a starting position.

Frequently asked questions
What is the maximum fine under DORA?
DORA sets none for financial entities. Each Member State sets its own under Article 50(3). The only figure in the Regulation is the periodic penalty of up to 1% of average daily worldwide turnover for critical ICT third-party providers.
Does the 1% of daily turnover penalty apply to banks?
No. Article 35(8) applies to critical ICT third-party service providers designated by the ESAs, and only for failing to comply with the Lead Overseer's measures.
Can board members be fined under DORA?
Yes, where national law provides for it. Article 50(5) requires Member States to let authorities apply penalties to members of the management body and other responsible individuals, on national law's conditions.
When did DORA penalties start?
DORA has applied since 17 January 2025, and Member States had to notify their penalty rules by the same date under Article 53.
Are DORA fines published?
Final decisions are published under Article 54, normally with the identity of the person responsible, and kept online for no more than five years.
Primary sources
Articles 1(2), 35, 42, 50 to 54 and 64 are quoted from Regulation (EU) 2022/2554 as published in OJ L 333 of 27 December 2022. The designated providers are from the ESAs' press release of 18 November 2025 and the list itself. National amounts are from the Austrian DORA Vollzugsgesetz, sections 7 and 8, and section 56 of the German Kreditwesengesetz. The fine is from the FMA announcement of 14 July 2026. NIS2, GDPR and Cyber Resilience Act figures are from Article 34(4) of Directive (EU) 2022/2555, Article 83(5) of Regulation (EU) 2016/679 and Article 64(2) of Regulation (EU) 2024/2847. National laws change; check the current text for your sector before relying on an amount.




