Contested points and known concerns about DORA after first year of applicability.
Implementation burden
DORA's five pillars combined produce substantial compliance work:
- Smaller financial entities (savings banks, regional insurers, smaller asset managers) face disproportionate burden.
- RTS / ITS volume is significant.
- Register of information is data-intensive.
- TLPT capability adds material cost for in-scope entities.
Proportionality provisions help but don't eliminate burden for smaller entities.
CTPP designation predictability
ESA designation criteria are clear in principle, less clear in application:
- Prospective CTPPs face uncertainty before designation.
- Commercial impact of designation significant.
- Some major cloud / SaaS providers may attempt to structure around designation.
- Designation process opacity criticized.
TLPT capacity bottleneck
Threat-led penetration testing requires specialist providers:
- Accredited TLPT providers limited globally.
- Demand from significant entities ramping faster than supply.
- Pricing pressure upward.
- Capacity for AI-feature testing especially constrained.
Overlap with adjacent regulation
DORA + NIS2 + GDPR + AI Act + sector-specific regulations create overlapping obligations:
- Same incident may trigger multiple reporting regimes.
- Same control may satisfy multiple regulators with different evidence formats.
- Same vendor may be subject to multiple oversight mechanisms.
- Authority coordination guidance still developing.
Cross-border supervisory coordination
Multi-Member-State financial entities face coordination across competent authorities:
- Cross-border colleges existing for some sectors.
- Newer mechanisms for DORA-specific cross-border coordination still maturing.
- Inconsistencies emerging.
CTPP non-EU jurisdictions
CTPPs primarily based outside EU (US cloud providers) face EU oversight:
- Extraterritorial reach.
- Enforcement against non-EU entities procedurally complex.
- Diplomatic / commercial tensions.
CTPP cooperation has been substantial in early state; longer-term sustainability unclear.
Register-of-information burden
Article 28(3) register has been criticized as data-intensive:
- Continuous updating burden.
- ITS-standardized format produces significant fields.
- Smaller entities particularly burdened.
Industry has pushed for simplification; ITS includes some proportionality.
AI-specific provisions limited
DORA pre-dates the AI maturity wave. AI features integrated into ICT systems are subject to general DORA obligations but no AI-specific provisions:
- AI risk treated as generic ICT risk.
- AI Act co-applies but coordination guidance limited.
- TLPT methodology for AI features evolving practitioner-side.
Counterpoint: what DORA still does well
- Comprehensive harmonization across fragmented predecessor framework.
- CTPP oversight addresses real concentration risk.
- TLPT institutionalization elevates testing maturity.
- Management body accountability.
- Detailed RTS / ITS provide implementation clarity.