Current view on DORA after first year of applicability (January 2025 — May 2026). Operational reality, gaps, where the regulation sits in EU financial services regulation.
What DORA does well
- Harmonization across financial sector. Previously fragmented ICT requirements (EBA Guidelines on ICT and Security Risk Management, EIOPA equivalents, sector-specific) consolidated.
- Comprehensive scope. All major financial entity types covered.
- Five pillars structure. Coherent operational framework.
- CTPP oversight. Union-level oversight of critical ICT third-party providers addresses concentration risk (AWS, Azure, GCP as critical for financial sector).
- TLPT formalization. TIBER-EU-based threat-led penetration testing institutionalized.
- Detailed RTS/ITS. ESAs published substantial implementing detail.
- Lex specialis clarity. Clear precedence over NIS2 for financial sector.
What DORA does poorly
- Implementation burden. Comprehensive obligations create substantial compliance overhead, particularly for smaller financial entities.
- CTPP designation process complexity. Criteria-based with ESA discretion; predictability for prospective CTPPs imperfect.
- TLPT capacity. Threat-led penetration testing requires specialist providers; capacity constrained as demand ramps.
- Register-of-information burden. Art 28(3) register requirement is data-intensive.
- Cross-border supervisory coordination. Multi-Member-State entities face coordinated supervision; coordination still maturing.
- Smaller entity proportionality. Some implementing acts apply proportionality; smaller entities still face material burden.
- Overlap with NIS2 / sector regulation. Coordination guidance still maturing.
Evidence
- Applicable since 17 January 2025. First year of enforcement.
- CTPP designation process opened 2024; first designations 2025-2026.
- ESA RTS/ITS publications rolled out through 2024-2025; major batch in late 2024.
- Industry compliance work mature in larger institutions; mid-size variable.
- First supervisory actions emerging; major enforcement plausibly 2026-2027.
- CTPP oversight ramping; AWS, Microsoft, Google, IBM cloud divisions among likely CTPP designations.
Personal calibration
- Working assumption for financial-services clients: DORA fluency required; implementation typically driven by client's existing compliance team.
- Working assumption for AI/cloud vendor positioning serving financial customers: DORA TPP obligations flow; expect contract clauses per Art 30.
- Working assumption for SRE work in financial services: TLPT capability commercially valuable; incident-response infrastructure already mature in most institutions.