DORA Controversies

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

Contested points and known concerns about DORA after first year of applicability.

Implementation burden

DORA's five pillars combined produce substantial compliance work:

  • Smaller financial entities (savings banks, regional insurers, smaller asset managers) face disproportionate burden.
  • RTS / ITS volume is significant.
  • Register of information is data-intensive.
  • TLPT capability adds material cost for in-scope entities.

Proportionality provisions help but don't eliminate burden for smaller entities.

CTPP designation predictability

ESA designation criteria are clear in principle, less clear in application:

  • Prospective CTPPs face uncertainty before designation.
  • Commercial impact of designation significant.
  • Some major cloud / SaaS providers may attempt to structure around designation.
  • Designation process opacity criticized.

TLPT capacity bottleneck

Threat-led penetration testing requires specialist providers:

  • Accredited TLPT providers limited globally.
  • Demand from significant entities ramping faster than supply.
  • Pricing pressure upward.
  • Capacity for AI-feature testing especially constrained.

Overlap with adjacent regulation

DORA + NIS2 + GDPR + AI Act + sector-specific regulations create overlapping obligations:

  • Same incident may trigger multiple reporting regimes.
  • Same control may satisfy multiple regulators with different evidence formats.
  • Same vendor may be subject to multiple oversight mechanisms.
  • Authority coordination guidance still developing.

Cross-border supervisory coordination

Multi-Member-State financial entities face coordination across competent authorities:

  • Cross-border colleges existing for some sectors.
  • Newer mechanisms for DORA-specific cross-border coordination still maturing.
  • Inconsistencies emerging.

CTPP non-EU jurisdictions

CTPPs primarily based outside EU (US cloud providers) face EU oversight:

  • Extraterritorial reach.
  • Enforcement against non-EU entities procedurally complex.
  • Diplomatic / commercial tensions.

CTPP cooperation has been substantial in early state; longer-term sustainability unclear.

Register-of-information burden

Article 28(3) register has been criticized as data-intensive:

  • Continuous updating burden.
  • ITS-standardized format produces significant fields.
  • Smaller entities particularly burdened.

Industry has pushed for simplification; ITS includes some proportionality.

AI-specific provisions limited

DORA pre-dates the AI maturity wave. AI features integrated into ICT systems are subject to general DORA obligations but no AI-specific provisions:

  • AI risk treated as generic ICT risk.
  • AI Act co-applies but coordination guidance limited.
  • TLPT methodology for AI features evolving practitioner-side.

Counterpoint: what DORA still does well

  • Comprehensive harmonization across fragmented predecessor framework.
  • CTPP oversight addresses real concentration risk.
  • TLPT institutionalization elevates testing maturity.
  • Management body accountability.
  • Detailed RTS / ITS provide implementation clarity.

See also