Where DORA Stands in 2026
The Digital Operational Resilience Act (DORA) became directly applicable across EU financial services on 17 January 2025, bringing with it mandatory ICT risk management frameworks, third-party oversight requirements, threat-led penetration testing obligations, and a standardised incident reporting regime. Eighteen months in, supervisory authorities in the Netherlands (DNB), Germany (BaFin), Ireland (CBI), and France (ACPR) have moved from the guidance-and-expectation phase to active supervisory engagement.
The picture emerging from those engagements is consistent: most in-scope institutions have the framework documentation in place, but operational implementation — particularly around third-party risk and incident reporting — is incomplete. The gap between paper compliance and operational compliance is where enforcement attention is focusing.
The Four Areas Regulators Are Scrutinising
ICT incident reporting timelines. DORA mandates a three-tier reporting structure for major ICT incidents: initial notification within 4 hours of classification, intermediate report within 72 hours, final report within one month. The 4-hour window in particular is causing operational difficulty. Most organisations lack the detection, triage, and classification capability to consistently identify a major incident within 4 hours of occurrence — let alone notify within that window. Regulators are asking for evidence of classification procedures, not just the procedures themselves.
Third-party ICT risk. DORA requires financial entities to maintain a full register of ICT third-party service providers, with contractual provisions meeting mandatory minimum requirements (set out in the regulatory technical standards). The RTS on ICT third-party risk, finalised in late 2024, specifies what contracts must contain: exit strategies, audit rights, sub-contractor disclosure, data location and portability. Firms with large vendor estates are finding that a significant proportion of existing contracts don’t meet the new standards and require renegotiation — a slow and resource-intensive process.
DORA critical third-party oversight. The European Supervisory Authorities (EBA, ESMA, EIOPA) are in the process of designating Critical ICT Third-Party Providers (CTPPs) — major cloud providers, core banking platform vendors, payment infrastructure providers. Once designated, CTPPs are subject to direct supervisory oversight. For financial entities, this means your critical technology vendors will face their own regulatory scrutiny, and you need to demonstrate that your oversight of them meets DORA standards regardless.
Threat-led penetration testing. DORA requires significant financial institutions to conduct TIBER-EU (or equivalent national framework) threat-led penetration testing at least every three years. This is qualitatively different from standard penetration testing: it uses current threat intelligence specific to the institution’s risk profile, is conducted by certified external testers, and includes the institution’s operational defences (blue team) in scope. Many institutions have not yet conducted their first DORA-compliant TLPT, and the queue for qualified testing providers is long.
What the Supervisory Conversations Are Revealing
CISOs who have been through supervisory engagements in 2026 report a consistent set of questions. Regulators want to see:
Evidence of board-level engagement. DORA places explicit responsibility on the management body — the board — for ICT risk oversight. Supervisors are asking for board meeting minutes that demonstrate substantive ICT risk discussion, not just presentation of dashboard metrics. If the CISO is presenting to the board annually, that is unlikely to satisfy the scrutiny.
Functioning incident classification processes. Not the classification procedure document, but evidence that it is actually used. Regulators are asking to see historical classification decisions and how long they took — including cases where classification was later revised. Speed and accuracy of initial classification are both being assessed.
Tested exit strategies. DORA requires contractual exit strategies for critical ICT third-party providers. But “strategy” is not sufficient — regulators are asking whether the strategy has been operationally tested. Can you actually execute a migration from your core banking provider if required? Have you rehearsed it?
Genuinely implemented resilience testing. Business Continuity testing and Disaster Recovery testing that covers ICT dependencies end-to-end, not just data centre failover. Does your resilience testing include your third-party dependencies? Does it test the decision-making process, not just the technical fallback?
Priority Actions for Institutions Behind on DORA
If your programme is not fully operational across all DORA pillars, sequence remediation as follows:
1. Incident reporting capability — immediate. The 4-hour initial notification window is the highest-enforcement-risk gap. If you cannot reliably identify and classify major ICT incidents within that window, invest in detection and classification procedures first. A classification decision tree that security operations teams can apply under pressure is more valuable than a comprehensive procedure document that takes an hour to navigate.
2. Third-party register completeness — short term. Your supervisory authority can ask for the ICT third-party register at any time. If it is incomplete or inaccurate, this is an immediately visible gap. Complete it — including sub-processors of critical providers — and implement a governance process that keeps it current.
3. Contract remediation — medium term. Begin renegotiating contracts with critical ICT providers that do not meet DORA RTS minimum requirements. Prioritise by risk: cloud providers and core systems first. This process takes 12-18 months for large vendor estates; starting late creates compounding risk.
4. TIBER-EU scheduling — plan now. If you haven’t yet scheduled your first DORA-compliant TLPT, do so now. Lead times for qualified testing providers are 6-12 months, and the TIBER-EU process itself takes 6-9 months to complete. Missing the testing cycle creates a regulatory gap that is visible and difficult to explain.
The UK Position
UK financial institutions are not subject to DORA directly, but the PRA and FCA’s operational resilience framework — which became fully operational in March 2025 — covers similar ground. The FCA’s operational resilience review of 2025 found that a significant proportion of firms still did not meet the impact tolerance requirements for their important business services. UK CISOs should be aware that while the specific obligations differ, the supervisory direction of travel is consistent: demonstrated operational resilience, not documented procedures.