
DORA and Communications: What the Regulation Requires
Complete guide to the DORA Regulation for corporate communications. Requirements, penalties, and how to comply with E2E encryption and archiving.
The DORA Regulation (Digital Operational Resilience Act) has been mandatory since January 17, 2025 for all EU financial entities. This article explains what DORA requires for corporate communications and how Traster Comms helps meet these requirements.
What is DORA and why does it affect communications?
DORA (EU Regulation 2022/2554) establishes a single framework of digital operational resilience for the financial sector. Its goal is to ensure that entities can withstand, respond to and recover from ICT-related incidents.
Corporate communications are a critical point because:
- They are the main channel for transmitting privileged information
- They must be archived and auditable
- They must be protected against unauthorized access
- They must guarantee business continuity
The 4 DORA pillars for communications
1. ICT Risk Management (Articles 5-16)
DORA requires a comprehensive technology risk management framework including:
- Identification of all critical communication assets
- Continuous risk assessment
- Security measures proportional to risk
- Periodic monitoring and review
2. Incident Reporting (Articles 17-23)
Entities must:
- Continuously monitor their communication systems
- Report serious incidents to competent authorities
- Classify and record all incidents
- Establish incident response processes
3. Resilience Testing (Articles 24-27)
Periodic assessments including:
- Vulnerability assessments
- Scenario-based testing
- Penetration testing with specific threats
- Results documentation and follow-up
4. Third-Party ICT Provider Control (Articles 28-44)
Third-party provider risk management:
- Provider assessment before contracting
- Specific contractual agreements
- Continuous performance monitoring
- Exit and contingency plans
Why WhatsApp, Signal and Telegram don't comply with DORA
| DORA Requirement | Signal | Telegram | Traster Comms | |
|---|---|---|---|---|
| Regulatory archiving | No | No | No | Yes |
| E2E key control | No | No | No | Yes |
| Communication audit | No | No | No | Yes |
| On-premise deployment | No | No | No | Yes |
| Centralized access management | Partial | No | No | Yes |
| Business continuity | Partial | No | No | Yes |
How Traster Comms complies with DORA
Traster Comms offers a solution specifically designed for DORA compliance:
- Self-managed encryption keys: The organization controls AES 256 encryption keys
- Complete archiving: All communications are archived and available for audit
- On-premise deployment: Infrastructure at client premises
- No commercial dependency: 100% own network without third-party applications
- Remote destruction: Ability to destroy the network if compromised
Frequently asked questions about DORA and communications
What is DORA and when does it apply?
DORA (EU Regulation 2022/2554) is the Digital Operational Resilience Act. It has been mandatory since January 17, 2025 for all EU financial entities.
Which entities does DORA affect?
Banks, insurance companies, investment firms, fund managers, stock brokerages, crypto-asset providers and their ICT service providers.
Why doesn't WhatsApp comply with DORA?
WhatsApp does not offer regulatory archiving, does not allow organizations to control encryption keys, and shares metadata with Meta. It does not meet DORA audit and resilience requirements.
What are the penalties for DORA non-compliance?
Penalties vary by Member State but can include significant fines and corrective measures. CNMV has already imposed fines totaling €19.46M in 2025 for related non-compliance.


