DORA vs EN 1090
DORA
EU regulation for digital operational resilience in financial sector
EN 1090
EU harmonized standard for steel and aluminium structural execution.
Quick Verdict
DORA mandates ICT resilience for EU finance against cyber threats, while EN 1090 requires certified FPC for CE-marking steel/aluminium structures. Finance adopts DORA for regulatory compliance; manufacturers use EN 1090 for EU market access.
DORA
Regulation (EU) 2022/2554, Digital Operational Resilience Act
Key Features
- Mandates comprehensive ICT risk management frameworks overseen by management body
- Requires incident reporting within 4 hours for major disruptions
- Enforces risk-based resilience testing including triennial TLPT
- Imposes direct ESAs oversight on critical third-party providers
- Harmonizes rules across 20 EU financial entity types proportionally
EN 1090
EN 1090 Execution of steel and aluminium structures
Key Features
- Factory Production Control (FPC) certification
- Execution Classes (EXC1-EXC4) risk scaling
- CE marking under CPR for market access
- Welding quality via ISO 3834 alignment
- Material traceability and NDT inspection regimes
Detailed Analysis
A comprehensive look at the specific requirements, scope, and impact of each standard.
DORA Details
What It Is
The Digital Operational Resilience Act (DORA), formally Regulation (EU) 2022/2554, is a transformative EU regulation enhancing digital operational resilience for the financial sector against ICT disruptions like cyberattacks and third-party failures. Enacted in 2022 and applied from January 17, 2025, it covers 20 financial entity types and critical ICT third-party providers (CTPPs), using a risk-based, proportional approach to harmonize rules across member states.
Key Components
DORA's pillars include ICT risk management frameworks with vulnerability controls and continuity plans; incident reporting with 4/72-hour timelines; resilience testing via annual scans and triennial TLPT; and third-party oversight with due diligence and ESAs supervision. It mandates management oversight, annual reviews, and penalties up to 2% of global turnover.
Why Organizations Use It
Financial firms adopt DORA for legal compliance amid rising threats (74% ransomware hit rate), to mitigate systemic risks shown in CrowdStrike outage, improve resilience, foster information sharing, and gain trust from regulators/stakeholders in a tech-dependent ecosystem.
Implementation Overview
Entities conduct gap analyses against RTS/ITS, develop frameworks, implement testing/monitoring tools, and assess vendors. Proportional to size/complexity, it targets EU finance; compliance via authority audits, with enforcement active since the 2025 deadline. (178 words)
EN 1090 Details
What It Is
EN 1090 is the harmonized European standard family (EN 1090-1, -2, -3) for execution and conformity assessment of structural steel and aluminium components. It implements the EU Construction Products Regulation (CPR), enabling CE marking via a risk-based approach through Execution Classes (EXC1–EXC4).
Key Components
- **EN 1090-1Conformity assessment, Factory Production Control (FPC) certification by Notified Bodies.
- **EN 1090-2/-3Technical rules for steel/aluminium (welding, tolerances, corrosion protection, inspection/NDT).
- Core principles: Material traceability, ISO 3834 welding quality, risk-scaled controls.
- AVCP systems with ongoing surveillance.
Why Organizations Use It
- Mandatory for EU market access with CE marking.
- Reduces liability, rework; builds trust via certified quality.
- Strategic: Enables high-risk projects (EXC3/4), competitive bidding.
Implementation Overview
Phased: Gap analysis, FPC build, welding quals, NB certification (3–12 months). Applies to fabricators in construction; requires audits, training for all sizes.
Key Differences
| Aspect | DORA | EN 1090 |
|---|---|---|
| Scope | Digital operational resilience in finance | Execution of steel/aluminium structural components |
| Industry | EU financial sector only | EU construction/manufacturing |
| Nature | Mandatory EU regulation | Harmonized standard for CE marking |
| Testing | Annual basic + triennial TLPT | FPC certification + surveillance audits |
| Penalties | Up to 2% global turnover fines | Market exclusion, no CE marking |
Scope
Industry
Nature
Testing
Penalties
Frequently Asked Questions
Common questions about DORA and EN 1090
DORA FAQ
EN 1090 FAQ
You Might also be Interested in These Articles...

Decoding Tomorrow's Regulations: How Advanced Compliance Tools Predict and Prepare for Future Shifts
Advanced compliance tools use AI, analytics & real-time monitoring to predict regulatory shifts, cut non-compliance costs 3x, and ensure audit readiness. Stay p

Why the SEC Stepped In: The Investor-Driven Push for Cybersecurity Transparency
Discover why the SEC's 2023 cybersecurity rules treat cyber risks as material financial threats. Explore the 'stick and carrot' approach for standardized disclo

HITRUST CSF MyCSF Platform Mastery: Infograph of Evidence Tagging Workflows and Top 5 Maturity Tier Acceleration Takeaways
Master MyCSF platform with infographics on evidence tagging for 1,400+ HITRUST controls across 19 domains. Cut documentation by 30%, boost Measured/Managed tier
Run Maturity Assessments with GRADUM
Transform your compliance journey with our AI-powered assessment platform
Assess your organization's maturity across multiple standards and regulations including ISO 27001, DORA, NIS2, NIST, GDPR, and hundreds more. Get actionable insights and track your progress with collaborative, AI-powered evaluations.
Explore More Comparisons
See how DORA and EN 1090 compare against other standards