From deadline to enforcement
The Digital Operational Resilience Act (DORA) applied from 17 January 2025. For much of that first year, the practical question was whether the framework existed on paper. That phase is over. DORA is now in active enforcement, national competent authorities are conducting supervisory reviews, and the initial period of tolerance has ended. The question has shifted from "do we have the controls" to "can we evidence that they work, on demand".
For financial services IT teams, and for the technology providers that serve them, that shift changes what adequate looks like.
Who DORA applies to
DORA covers a broad range of financial entities operating in the EU: banks, insurers, investment firms, payment and e-money institutions, crypto-asset service providers, and more. Critically, it also reaches ICT third-party service providers that serve those entities. A supplier does not have to be a financial firm to feel DORA's effects. serving one is enough to be pulled into its orbit.
The regulation is deliberately about operational resilience rather than security alone. Its concern is the ability of the financial system to withstand, respond to, and recover from ICT disruption, whatever the cause.
The five pillars
DORA is structured around five areas. Understanding them is the fastest way to see what compliance actually requires.
1. ICT risk management
A documented framework for identifying, protecting against, detecting, responding to, and recovering from ICT risks. Governance sits at the centre. management bodies are accountable, not just informed.
2. ICT incident management and reporting
Processes to detect, manage, and classify ICT-related incidents, and to report major incidents to the relevant authority within defined timelines. This demands both the capability to detect incidents and the process to report them promptly.
3. Digital operational resilience testing
Regular testing of ICT systems, from vulnerability assessments through to, for significant entities, threat-led penetration testing. Resilience has to be demonstrated, not assumed.
4. ICT third-party risk management
Oversight of the ICT supply chain, including a register of information on all ICT third-party arrangements, contractual requirements, and management of concentration risk. This has proven the most demanding pillar in practice.
5. Information sharing
Encouragement (not obligation) to share cyber threat information among financial entities, so the sector defends collectively.
The Register of Information is the sharp end
Since enforcement began, third-party risk management and the Register of Information have drawn the most supervisory attention, and financial entities consistently report the Register as the single hardest requirement to satisfy. If you are prioritising effort, this is where regulators are looking hardest.
The third-party question
The third-party pillar is where many organisations find the largest gap, because it requires a level of supply-chain visibility that few had before. Building and maintaining a complete register of ICT arrangements, ensuring contracts contain the required provisions, and assessing concentration risk (where too much depends on a single provider) are substantial, ongoing exercises rather than one-off tasks. Supervisors are examining not whether a register exists, but whether it is complete, current, and defensible.
"DORA in 2026 is not asking whether you wrote the policy. It is asking whether the control works, whether it is maintained, and whether you can prove it during an examination. Evidence is the currency."
Edge7 Networks, Compliance PracticeWhat it means for ICT providers
If you provide technology, connectivity, managed services, or security to in-scope financial entities, DORA reaches you through your customers. You will be asked to meet contractual resilience and security requirements, to support your customers' incident reporting and testing obligations, and to provide the information they need for their register. Providers designated as critical face direct oversight. For most, the practical effect is that financial-services customers now expect a demonstrable resilience posture as a condition of the relationship.
The consequences are material
Financial entities can face fines of up to 2% of total annual worldwide turnover, or €10 million, whichever is higher. Beyond fines, ICT risk findings now feed into supervisory review processes and can carry wider operational consequences. DORA is not a box-ticking regime.
Where to start
If DORA applies to you and you are not confident in your position, the useful starting point is a gap assessment against the five pillars, with early attention to third-party risk and the register, since that is both the hardest requirement and the one under most scrutiny. From there, effort can be prioritised by where the gaps and the supervisory focus overlap.
Edge7 Networks works with financial services IT teams, and with the providers that serve them, across Ireland and the UK on operational resilience and ICT risk and compliance. Our work also connects to NIS2 and DORA readiness where both regimes apply. If you need to move from policy to demonstrable resilience, a gap assessment is the right first step.