DORA entered enforcement in January 2026. Six months into the first supervisory cycle, the picture is becoming clear: regulators are not uniformly enforcing everything at once, but they have prioritised two areas where deficiencies are most observable and most consequential. Financial sector CISOs need to understand where enforcement attention is concentrating — and what exposure exists for entities that have not yet closed the gaps.
What the First Supervisory Cycle Looks Like
The European Supervisory Authorities (ESAs) — the European Banking Authority, EIOPA, and ESMA — have supervisory frameworks that operate with a degree of national variation, since DORA is enforced through national competent authorities in most cases (with direct ESA oversight reserved for critical ICT third-party service providers under DORA’s Oversight Framework).
In the first six months of enforcement:
- Supervisory reviews have begun, with national competent authorities sending formal information requests and conducting preliminary assessments of DORA program maturity
- Incident reporting mechanisms are under active scrutiny — whether firms have the detection and reporting infrastructure to meet the 4-hour initial report and 24-hour intermediate report timeframes for major incidents
- The Register of Information — DORA’s required inventory of all ICT third-party service arrangements — has become a primary audit focus because it is concrete, verifiable, and reveals the quality of a firm’s third-party risk management program immediately
The Register of Information Gap
The Register of Information requirement under Article 28 of DORA is straightforward in principle: a comprehensive, maintained inventory of every ICT third-party arrangement, categorised by criticality, with contractual details, sub-contractor mapping, and concentration risk analysis.
In practice, most firms underestimated what full compliance requires. A Register that covers direct ICT suppliers but omits fourth-party dependencies, cloud sub-processors, or legacy technology arrangements is deficient in ways that supervisors will identify quickly.
The specific gaps supervisors have flagged in preliminary reviews:
- Incomplete sub-contractor chains — knowing who your critical ICT providers use, not just who you use directly
- Missing concentration risk analysis — DORA requires explicit assessment of systemic risk when multiple critical functions depend on the same provider or cloud region
- Outdated entries — a Register that was populated for the January 2026 deadline but hasn’t been maintained through vendor changes and contract renewals
What good looks like: The Register is a living document, maintained quarterly minimum, with contractual terms from Article 30 (mandatory contractual clauses including audit rights, security testing participation, and sub-contractor change notification) verified for every critical arrangement.
Incident Reporting: The 4-Hour Test
DORA’s major incident reporting timeline is aggressive by design:
- 4 hours from classification as a major incident for the initial report to the national competent authority
- 24 hours for an intermediate report with assessed cause and impact
- 72 hours for a final report with root cause analysis
The classification criteria for “major incident” are defined by the ESAs: incidents affecting availability, integrity, continuity, authenticity, or confidentiality of ICT services above defined thresholds.
The critical process gap supervisors are finding: many firms have the reporting templates and know the regulatory timelines, but haven’t tested the detection-to-classification-to-report chain end-to-end. The question supervisors are asking isn’t “do you have an incident response process?” It’s “how long did it take you to classify your last significant incident, and do your detection tools generate the telemetry required to complete the initial report in 4 hours?”
Action for CISOs: Run a tabletop specifically for DORA incident reporting. Take a realistic scenario (ransomware hitting an ICT service provider that you depend on, for example), and walk through: when does the ICO detection occur, when does classification happen, who drafts the initial report, who approves it, and how does it reach the competent authority within 4 hours of classification? The gaps will surface.
Third-Party ICT Risk: The Article 30 Contract Audit
DORA Article 30 specifies mandatory contractual clauses for arrangements with critical ICT third-party service providers. Many firms signed contracts before DORA entered force and have not yet renegotiated them to include required provisions.
Key clauses that are frequently missing in pre-DORA contracts:
- Full audit and inspection rights — not just security questionnaire responses
- Right to participate in ICT security testing — including TLPT (threat-led penetration testing) conducted on the third party’s systems
- Sub-contractor change notification — requirement that the provider notifies you before making material changes to sub-contractors that support critical services
- Business continuity requirements — explicit contractual obligations for recovery time and recovery point objectives
- Data and systems portability — exit provisions that allow migration without operational disruption
Supervisors reviewing Register of Information submissions are cross-checking contractual terms for critical arrangements. Contracts that pre-date DORA without renegotiation are a documented compliance deficiency.
The Digital Operational Resilience Testing Obligation
DORA requires annual ICT systems and process testing, with critical infrastructure firms conducting Threat-Led Penetration Testing (TLPT) at least every three years. The TLPT requirement is the highest-maturity obligation — it requires coordinated, intelligence-driven penetration tests conducted by accredited testers with regulatory involvement.
For most financial entities, the near-term focus should be on the baseline testing obligation (annual ICT systems tests) and demonstrating that results feed into a remediation cycle with documented timelines. TLPT typically involves advance coordination with the national competent authority; begin that coordination process now if you are classified as a significant firm likely to be in scope for the first TLPT cycle.
What Enforcement Action Looks Like
Early enforcement in the DORA cycle has taken the form of formal supervisory notices — requests for remediation plans with defined timelines — rather than financial penalties. This is characteristic of first-cycle enforcement: regulators are establishing a baseline understanding of industry maturity and creating a documented record that enables penalty escalation for entities that receive a notice and fail to remediate.
The shift from “improve your Register” to “pay a penalty for not improving your Register” is one supervisory cycle away for entities currently receiving notices.
For CISOs, the practical message is direct: the three areas requiring immediate board-level attention are Register of Information completeness, incident detection and reporting capability, and Article 30 contract coverage. These are the areas where enforcement is actively focused and where gaps have near-term regulatory consequence.
The Board Report
CISOs briefing boards on DORA in H2 2026 should cover:
- Current maturity status against the three enforcement priorities (Register, incident reporting, contracts)
- Outstanding remediation items and committed timelines
- Whether the firm has received any supervisory information requests and their status
- Budget required to close remaining gaps before the next supervisory review cycle
DORA is not in the “wait and see” phase. Enforcement is active, the priorities are visible, and the trajectory from supervisory notice to penalty is short for entities that don’t respond to first-cycle findings.