Compliance
DORA in 2026: ICT Resilience Is No Longer Optional for Financial Entities
Regulation (EU) 2022/2554 has applied across the EU since 17 January 2025. Supervisors are now moving from guidance to inspection. Here is what DORA actually requires, and where financial entities remain exposed.
Regulation (EU) 2022/2554, known as DORA, the Digital Operational Resilience Act, entered into force on 16 January 2023 and has applied across the European Union since 17 January 2025. It harmonises ICT risk management rules for 21 categories of financial entities, from banks and insurers to investment firms, payment institutions and crypto-asset service providers.
DORA does not sit beside existing financial regulation. It replaces a patchwork of national and sector-specific ICT rules with a single framework, and it extends direct oversight, for the first time, to the technology providers financial entities depend on.
Five requirements, one accountable body
The regulation rests on five pillars: a documented ICT risk management framework, incident classification and reporting, regular digital resilience testing, oversight of ICT third-party risk, and voluntary information sharing on cyber threats. All five sit under one accountability rule: the management body defines, approves and remains responsible for the ICT risk framework. It cannot be delegated to a CIO or an external provider.
- ICT risk management framework: a documented strategy, policies, procedures and tools to identify, protect, detect, respond to and recover from ICT-related incidents, reviewed at least once a year.
- Incident classification and reporting: major ICT-related incidents must be reported to the competent national authority, through an initial notification, an intermediate report and a final report, on a fixed timeline set by regulatory technical standards.
- Digital operational resilience testing: a basic testing programme every year for most entities, and threat-led penetration testing (TLPT) every three years for entities identified as critical to the financial system.
- ICT third-party risk management: a full register of information on all ICT third-party arrangements, contractual clauses covering exit strategies and audit rights, and direct EU oversight of providers designated as critical.
- Information sharing: voluntary arrangements between financial entities to exchange cyber threat intelligence, encouraged but not mandatory.
The exposure most entities underestimate
Two areas generate most of the supervisory findings so far. The first is the register of ICT third-party providers: many entities can list their main cloud and software vendors, but struggle to map subcontracted providers several layers down, which the regulation still requires. The second is contractual coverage: exit clauses, audit rights and service-level commitments negotiated years ago rarely meet DORA's specific requirements, and renegotiating them with large providers takes time most entities did not budget for.
21
categories of financial entities directly in scope
17 janv. 2025
date DORA became applicable across the EU
3 ans
frequency of threat-led penetration testing for critical entities
1
single accountable body, the management body, for the entire ICT risk framework
Why this matters beyond the financial sector
DORA reaches further than balance sheets. Cloud providers, core banking software vendors and payment infrastructure companies serving financial clients are increasingly asked to demonstrate DORA alignment as a condition of the contract, whether or not they are themselves a financial entity. A fintech or software vendor that cannot answer a DORA due diligence questionnaire loses deals, not because it is out of scope, but because its client is not.
“A documented ICT risk framework is not a policy exercise. It is what a financial counterparty, an auditor or a regulator expects to see within days, not weeks.”
— Aegryn
Aegryn Advisory helps financial entities and their technology providers document ICT risk management, structure third-party registers and prepare resilience testing evidence, certified under the CIFSO Security & Sovereignty dimension, ahead of the moment a supervisor, investor or enterprise client asks for proof.
This article was written with the assistance of artificial intelligence and reviewed under Aegryn editorial responsibility. In accordance with Article 50 of the EU AI Act, we assume editorial responsibility for this content.
Insights Aegryn
Recevez chaque semaine les analyses Aegryn — M&A, valorisation, tech, CIFSO.
Ready to submit your asset or access the catalogue?
