Compliance

DORA Compliance: A Practical Guide for Financial Services IT Teams

The Digital Operational Resilience Act took effect in January 2025 and is now in active enforcement. Financial entities need documented ICT risk frameworks, tested resilience, and third-party oversight.

E7
Edge7 Networks Team
Networking & Security Specialists
5 May 2026
9 min read
Share

From deadline to enforcement

The Digital Operational Resilience Act (DORA) applied from 17 January 2025. For much of that first year, the practical question was whether the framework existed on paper. That phase is over. DORA is now in active enforcement, national competent authorities are conducting supervisory reviews, and the initial period of tolerance has ended. The question has shifted from "do we have the controls" to "can we evidence that they work, on demand".

For financial services IT teams, and for the technology providers that serve them, that shift changes what adequate looks like.

Who DORA applies to

DORA covers a broad range of financial entities operating in the EU: banks, insurers, investment firms, payment and e-money institutions, crypto-asset service providers, and more. Critically, it also reaches ICT third-party service providers that serve those entities. A supplier does not have to be a financial firm to feel DORA's effects. serving one is enough to be pulled into its orbit.

The regulation is deliberately about operational resilience rather than security alone. Its concern is the ability of the financial system to withstand, respond to, and recover from ICT disruption, whatever the cause.

The five pillars

DORA is structured around five areas. Understanding them is the fastest way to see what compliance actually requires.

1. ICT risk management

A documented framework for identifying, protecting against, detecting, responding to, and recovering from ICT risks. Governance sits at the centre. management bodies are accountable, not just informed.

2. ICT incident management and reporting

Processes to detect, manage, and classify ICT-related incidents, and to report major incidents to the relevant authority within defined timelines. This demands both the capability to detect incidents and the process to report them promptly.

3. Digital operational resilience testing

Regular testing of ICT systems, from vulnerability assessments through to, for significant entities, threat-led penetration testing. Resilience has to be demonstrated, not assumed.

4. ICT third-party risk management

Oversight of the ICT supply chain, including a register of information on all ICT third-party arrangements, contractual requirements, and management of concentration risk. This has proven the most demanding pillar in practice.

5. Information sharing

Encouragement (not obligation) to share cyber threat information among financial entities, so the sector defends collectively.

Where the pressure is

The Register of Information is the sharp end

Since enforcement began, third-party risk management and the Register of Information have drawn the most supervisory attention, and financial entities consistently report the Register as the single hardest requirement to satisfy. If you are prioritising effort, this is where regulators are looking hardest.

The third-party question

The third-party pillar is where many organisations find the largest gap, because it requires a level of supply-chain visibility that few had before. Building and maintaining a complete register of ICT arrangements, ensuring contracts contain the required provisions, and assessing concentration risk (where too much depends on a single provider) are substantial, ongoing exercises rather than one-off tasks. Supervisors are examining not whether a register exists, but whether it is complete, current, and defensible.

"DORA in 2026 is not asking whether you wrote the policy. It is asking whether the control works, whether it is maintained, and whether you can prove it during an examination. Evidence is the currency."

Edge7 Networks, Compliance Practice

What it means for ICT providers

If you provide technology, connectivity, managed services, or security to in-scope financial entities, DORA reaches you through your customers. You will be asked to meet contractual resilience and security requirements, to support your customers' incident reporting and testing obligations, and to provide the information they need for their register. Providers designated as critical face direct oversight. For most, the practical effect is that financial-services customers now expect a demonstrable resilience posture as a condition of the relationship.

Note the penalties

The consequences are material

Financial entities can face fines of up to 2% of total annual worldwide turnover, or €10 million, whichever is higher. Beyond fines, ICT risk findings now feed into supervisory review processes and can carry wider operational consequences. DORA is not a box-ticking regime.

Where to start

If DORA applies to you and you are not confident in your position, the useful starting point is a gap assessment against the five pillars, with early attention to third-party risk and the register, since that is both the hardest requirement and the one under most scrutiny. From there, effort can be prioritised by where the gaps and the supervisory focus overlap.

Edge7 Networks works with financial services IT teams, and with the providers that serve them, across Ireland and the UK on operational resilience and ICT risk and compliance. Our work also connects to NIS2 and DORA readiness where both regimes apply. If you need to move from policy to demonstrable resilience, a gap assessment is the right first step.


E7
Edge7 Networks Team
Networking & Security Specialists, Ireland & UK

Edge7 Networks is a specialist networking and security provider, founded in 2018. Our team works with IT leaders across Ireland and the UK on enterprise networking, managed security, and compliance. We hold ISO 27001:2022, ISO 9001:2015, and Cyber Essentials certifications.

Working through DORA?

Our team helps financial services IT teams across Ireland and the UK turn DORA requirements into demonstrable resilience. If you would like to talk through your position, we are easy to reach.