DORA position

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

Current view on DORA after first year of applicability (January 2025 — May 2026). Operational reality, gaps, where the regulation sits in EU financial services regulation.

What DORA does well

  • Harmonization across financial sector. Previously fragmented ICT requirements (EBA Guidelines on ICT and Security Risk Management, EIOPA equivalents, sector-specific) consolidated.
  • Comprehensive scope. All major financial entity types covered.
  • Five pillars structure. Coherent operational framework.
  • CTPP oversight. Union-level oversight of critical ICT third-party providers addresses concentration risk (AWS, Azure, GCP as critical for financial sector).
  • TLPT formalization. TIBER-EU-based threat-led penetration testing institutionalized.
  • Detailed RTS/ITS. ESAs published substantial implementing detail.
  • Lex specialis clarity. Clear precedence over NIS2 for financial sector.

What DORA does poorly

  • Implementation burden. Comprehensive obligations create substantial compliance overhead, particularly for smaller financial entities.
  • CTPP designation process complexity. Criteria-based with ESA discretion; predictability for prospective CTPPs imperfect.
  • TLPT capacity. Threat-led penetration testing requires specialist providers; capacity constrained as demand ramps.
  • Register-of-information burden. Art 28(3) register requirement is data-intensive.
  • Cross-border supervisory coordination. Multi-Member-State entities face coordinated supervision; coordination still maturing.
  • Smaller entity proportionality. Some implementing acts apply proportionality; smaller entities still face material burden.
  • Overlap with NIS2 / sector regulation. Coordination guidance still maturing.

Evidence

  • Applicable since 17 January 2025. First year of enforcement.
  • CTPP designation process opened 2024; first designations 2025-2026.
  • ESA RTS/ITS publications rolled out through 2024-2025; major batch in late 2024.
  • Industry compliance work mature in larger institutions; mid-size variable.
  • First supervisory actions emerging; major enforcement plausibly 2026-2027.
  • CTPP oversight ramping; AWS, Microsoft, Google, IBM cloud divisions among likely CTPP designations.

Personal calibration

  • Working assumption for financial-services clients: DORA fluency required; implementation typically driven by client's existing compliance team.
  • Working assumption for AI/cloud vendor positioning serving financial customers: DORA TPP obligations flow; expect contract clauses per Art 30.
  • Working assumption for SRE work in financial services: TLPT capability commercially valuable; incident-response infrastructure already mature in most institutions.

See also