Vendor Sheet
Data Security Compliance with the Digital Operational Resilience Act (DORA)
The Digital Operational Resilience Act (DORA) establishes a unified EU framework to strengthen the cybersecurity of financial institutions and their ICT service providers. Effective January 2025, it mandates ICT risk management, incident reporting, resilience testing, and third-party risk oversight. Thales supports compliance by protecting data at rest, in motion, and in use through encryption, tokenization, and access controls. Solutions like CipherTrust, OneWelcome, and Luna HSM ensure strong authentication, key management, and anomaly detection. Thales also mitigates third-party risk with BYOK and BYOE models, ensuring data sovereignty, compliance, and operational resilience across hybrid environments.