Why 2026 is the year DORA gets serious
For a while financial firms could treat DORA, the EU’s Digital Operational Resilience Act, as an upcoming requirement to prepare for. That time is over. The regulation has applied since January 2025, and 2026 is the year it enters a maturity phase in which supervisors move from guiding to reviewing and enforcing. The informal tolerance period has ended, and national competent authorities now act alongside the European Supervisory Authorities in active reviews.
For banks, insurers, investment firms, payment institutions and a long list of other financial actors, this means the issue has shifted from project planning to ongoing responsibility. DORA harmonises the requirements for how the financial sector must withstand, manage and recover from disruptions to its IT and information systems, whether caused by cyberattacks or technical failures. This article explains what the five core requirements mean, where firms most often fall short and how you stand strong when the reviewer gets in touch.
What DORA requires: the five building blocks
DORA rests on five connected pillars, and weakness in one often undermines the others.
Risk management and governance
At the core is a framework for managing ICT risk that is owned and overseen at management level. The board and senior management carry an explicit responsibility for digital resilience that cannot be fully delegated away to a technical function. The framework must identify critical systems, protect them and ensure continuity.
Incident management and reporting
Firms must detect, classify and report major ICT-related incidents within the timeframes the regulation sets out. That requires processes that work under pressure, not just a policy in a binder, because the tight deadlines leave little room for improvisation when something actually happens.
Resilience testing and third-party risk
The regulation requires regular testing of operational resilience as well as structured management of the risks of outsourced IT services. Because so much of the financial infrastructure rests on external cloud and system providers, firms must keep a register of their ICT third-party arrangements and ensure the contracts meet DORA’s requirements. The fifth pillar, sharing information on cyber threats, ties the sector together so that lessons spread faster than the threats.
Why even non-financial providers are affected
One of DORA’s most underestimated effects is its reach into the supply chain. Third-party providers that supply financial firms with IT systems and services, including cloud and data analytics, are drawn into the framework, and critical providers can come under direct oversight. That means even companies outside the EU that supply services to European financial actors need to address the requirements. For a financial firm it means its own compliance cannot be built without also reviewing and contractually governing the supply chain.
A practical example: the investment firm that trusted the cloud
Imagine a mid-sized investment firm that has outsourced most of its IT operations to a large cloud provider. The firm has a modern technical environment and feels secure, because the provider is a well-known player with its own certifications.
When the supervisor asks for the firm’s register of ICT third-party arrangements, its plan for what happens if the provider suffers a prolonged outage and its contractual rights to audit and information, it turns out the contracts were never adapted to DORA. The firm relied on the provider’s general reassurance without securing the specific rights and processes the regulation requires. It is not the technology that fails, but the governance and documentation around it. A review of the supplier contracts and an updated continuity plan would have made the same setup defensible.
Common mistakes companies make
The first mistake is to treat DORA as an IT project rather than a leadership and governance issue. Responsibility sits explicitly at management level, and a reviewer expects to see that reflected in how the firm is run.
The second mistake is to overlook the supply chain. Many firms have their own systems in good order but lack registers, contractual rights and contingency plans for the external providers they are in practice wholly dependent on.
The third mistake is to have policies on paper but not processes that work in a real situation. The deadlines for incident reporting quickly reveal whether preparedness is genuine or merely documented.
Legal risks
DORA is backed by a sanctions regime, and in the maturity phase supervisors have both the ability and the will to use it. Penalties for financial firms are largely set by national law and can be significant, while critical third-party providers can face dedicated oversight measures. Equally important is the allocation of responsibility: because it sits at management level, the board and senior management are personally exposed to governance failures.
Beyond the sanctions there is an operational and reputational risk. A firm that cannot demonstrate resilience risks not only regulatory measures but also the confidence of customers and counterparties, and in the financial sector trust is a precondition for doing business.
Recommended actions
Start by establishing that responsibility for digital resilience is anchored at management level and documented. Then map your critical systems and your ICT third-party arrangements, and create or update the register the regulation requires.
Review the supplier contracts and ensure they give you the rights DORA assumes, including to information, audit and exit management. Test your incident process against the regulation’s deadlines so it works under pressure, and keep the plans alive through regular testing. Because supervision is now active, it is wise to be able to show not only that the requirements are met, but how, with documentation that withstands a review.
Frequently asked questions about DORA
Does DORA apply to our company?
DORA covers a broad span of financial actors, including banks, insurers, investment firms and payment institutions, as well as critical IT providers to the sector. If you are a financial actor in the EU, the starting point is that the regulation applies to you.
We have outsourced our IT operations. Is it then the provider’s responsibility?
No. You can outsource the operations but not the responsibility. DORA requires you to keep a register of your providers, secure the right contractual terms and have a plan for outages, regardless of how large and well-known the provider is.
What does it mean that 2026 is a maturity phase?
The regulation has applied since January 2025, and the initial tolerance is over. During 2026 supervision shifts to active review and enforcement rather than guidance alone.
How quickly must we report a major incident?
DORA sets tight timeframes for classifying and reporting major ICT-related incidents. The exact deadlines mean the process must be rehearsed in advance, because there is no time to build it once the incident has already occurred.
Does DORA also affect our providers outside the EU?
Yes, indirectly and in some cases directly. Providers supplying IT services to European financial actors need to address the requirements, and critical providers can come under oversight wherever they are based.
Summary
DORA has left the rollout phase and entered a period of active supervision, and 2026 is the year financial firms are tested against the requirements in practice. Those who pass the review best are not necessarily the ones with the most modern technology, but the ones that have anchored responsibility at management level, brought order to their supply chain and can show that their processes work when it really matters. In the financial sector, digital resilience is no longer a technical detail but a precondition for trust.
Lawgent helps financial firms translate DORA’s requirements into concrete governance, review and update their supplier contracts and build resilience that withstands supervision. We combine experienced business-law advice with AI-driven efficiency, so you get clear, practical guidance faster and more cost-effectively than at a traditional firm. Want to know how your firm measures up against DORA’s requirements? Contact Lawgent for a review of your digital resilience.
