The Digital Operational Resilience Act (DORA) was a significant regulatory milestone for financial services firms operating within the EU, strengthening their ability to absorb and adapt to ICT-related incidents in an increasingly digitised landscape. DORA’s prescriptive nature required significant structural and technological changes for in-scope firms1 across the two-year transition period between the passing of the legislation on 16 January 2023 and the implementation date of 17 January 2025.
By GreySpark’s Mark Nsianguana, Manager, Electronic Trading Risk Management practice
Firms faced challenges as they transitioned to being DORA compliant,
with some voicing a mixture of concern and frustration. Even so, in 2025, financial firms must prepare for deeper regulatory oversight while integrating DORA’s principles into their operational frameworks. This article explores the progress toward compliance with DORA, following its implementation date, and looks at upcoming regulatory expectations and how regulators could enforce upcoming regulatory change through audits, reporting and oversight.
Decoding DORA – What You Need to Know
DORA is a comprehensive regulation aimed at enhancing the digital operational resilience of financial firms and third-party providers operating anywhere in the EU by providing them with a unified operational resilience regulatory framework. DORA introduced standards for managing information and communication technology (ICT) risks.
The Act was created for three main reasons:
- Rising Cyber Threats – The financial sector is increasingly being targeted in cyberattacks. As the industry becomes more digitised, effectively the attack surface has increased. Techniques used include ransomware, data breaches and fraud, all of which pose significant risks to business operations and, more broadly, financial stability.
- Regulatory Fragmentation – Before DORA, financial firms in the EU operated under a diverse array of national ICT risk regulations, leading to inconsistencies and gaps in cybersecurity resilience. DORA was introduced to standardise and unify the ICT risk management framework and ensure a single rulebook for all financial firms operating across the EU.
- Growing Dependence on Third-Party ICT Providers – In the search for innovation and efficiency, financial firms are increasingly relying on third-party ICT providers (e.g. cloud service providers and other fintech vendors). However, many of these relationships were established without sufficient regulatory oversight. For instance, financial firms with data or services in the cloud often lacked direct control over how their data and services were secured, making it harder to ensure business continuity. DORA introduced stringent third-party risk management and oversight requirements to ensure that these providers meet sufficiently high security standards.
Specifically, DORA’s requirements can be categorised into five pillars that help financial firms manage risk and improve their digital resilience:
- ICT Risk Management – Establish a solid framework to identify, assess and manage risks related to information technology. Financial firms must develop strategies, guidelines and procedures to ensure that they are equipped to handle potential ICT risks effectively.
- Incident Reporting – Maintain a clear plan for detecting, reporting and managing ICT incidents. This includes everything from minor operational disruptions to major cyberattacks, ensuring fast remediating action that could effectively minimise damage.
- Digital Operational Resilience Testing – Conduct penetration tests and other forms of stress testing, in order to uncover weaknesses in its systems and implement necessary improvements to ensure that the systems withstand various types of threats. Regular testing of digital systems’ resilience is essential.
- ICT Third-Party Risk Management – Assess external third-party suppliers of IT services, ensuring that associated risks are managed throughout the business relationship.
- Information Sharing – Collaborate with other financial firms and relevant authorities to share knowledge about threats and vulnerabilities as well as best practices to enhance collective resilience in the sector.
Beyond the Deadline – Financial Firms’ Alignment with DORA Requirements
Preparing adequately for DORA required significant operational and technological overhauls for in-scope financial firms, as they seek to meet DORA’s more stringent operational resilience standards. Due to the complexity of the regulation, there is not a one-size-fits-all approach to compliance. Indeed, some in-scope firms still working towards full compliance.
Figures suggest that only 19% of in-scope firms are confident that they are fully compliant with current DORA requirements, and nearly 47% cite that they are still in their early to mid-stages and are putting processes in place (see Figure 1).
Figure 1: Degree of Alignment of In-scope Firms to Comply with DORA in Q1 2025
Source: OCEG, GreySpark analysis
(Click image to enlarge)
Not meeting compliance standards on time leaves firms open to regulatory fines and DORA is no exception to this rule. Indeed, financial firms may face penalties of up to 2% of their total annual worldwide turnover for breaches. Critical third-party ICT providers may also face financial penalties, activity restrictions or even suspension until compliance is achieved. In terms of enforcement, regulators are likely to take on a multi-faceted approach, conducting the following:
- Audits and Inspections – Regular assessments and onsite inspections of financial firms and ICT service providers will be conducted to ensure compliance and that adequate governance frameworks, policies and security measures are in place.
- Incident Reporting – Regulators will assess whether firms adhere to mandatory incident reporting timelines (within four hours – initial notification to the regulator, within 24 hours – provide a detailed incident report and within one month – provide a final report outlining root causes and corrective actions).
- Third-Party Risk Management – Regulators will scrutinise contracts with critical ICT service providers to ensure proper risk management and security controls are deployed.
Following the January deadline, some firms remain not fully compliant. However, as well as catching up with that, they must also now prepare for a key, imminent deadline pertaining to their critical ICT providers. By 30 April 2025, under the terms of DORA, the European Supervisory Authorities (ESAs) require National Competent Authorities (NCAs) to submit to them registers of contractual arrangements between financial firms and ICT third-party
service providers.
In fact, according to a study, only around 28% of firms anticipate that they will be ready for the 30 April 2025 deadline (see Figure 2). As highlighted below, firms can implement measures to ensure that they meet the requirements in time and ward off the threat of regulatory censure.
Figure 2: The Anticipated Degree of Readiness of In-scope Firms to Meet Requirements on 30 April 2025
Source: OCEG, GreySpark analysis
(Click image to enlarge)
Ahead of the 30 April 2025 deadline, as shown in Figure 3, financial firms must:
- Create comprehensive registers that include the aforementioned details about ICT services, including data processing locations, subcontracting arrangements, and service level agreements. It should also outline the obligations of ICT providers to assist during incidents and cooperate with authorities, as well as termination rights and notice periods.
- Conduct regular meetings and consultations with NCAs which can help clarify compliance requirements and provide opportunities for feedback on implementation strategies. They should also designate a dedicated liaison or team responsible for managing interactions with NCAs, ensuring consistency and continuity in communication.
- Ensure their registers are ready before 30 April 2025 to allow for any necessary reviews or updates, prior to the NCA’s submission to the ESAs. This includes ensuring that all information is accurate and up-to-date, reflecting any changes in service agreements or provider details.
- Establish a systematic approach to review and update their ICT service registers regularly to reflect any changes which involve setting up a schedule for periodic audits and updates. They should also implement a change management process to capture any modifications in ICT services promptly including new subcontracting arrangements or changes in service level agreements.
Figure 3: Steps Financial Firms Must Take Ahead of 30 April 2025 DORA Deadline
Source: Hyperproof, GreySpark analysis
(Click image to enlarge)
Unpacking DORA’s Impact – Early Effects and Emerging Challenges
Overall, in response to DORA, the sentiment across the financial industry is mixed. Early indications show a combination of apprehension – driven by the fear of fines, and resource strain, as well as optimism and support from those firms seeking to improve their operational efficiency.
One of the key takeaways from GreySpark’s analysis is the stark contrast between the sentiment in larger and smaller organisations. Large firms, with their deep pool of financial and human resources, generally view DORA as a manageable challenge and an opportunity to build on an already robust and mature operational resilience framework.
Small firms and suppliers, however, are finding it harder to adjust to the DORA framework, since they are generally starting from a lower base. Smaller firms typically have less mature operational frameworks and less resources to deal with the changes. In 2025, they are also working toward compliance with several other regulatory requirements (GDPR, ISO20022, NIS2 Directive etc).
In addition, while DORA is prompting a wave of operational efficiency and innovation, as was intended, there are ongoing technological challenges. Revising and implementing internal controls, as well as aligning third-party contracts with the DORA requirements are ongoing processes that require a deep understanding of DORA requirements and their own firm’s processes. Many organisations operate in highly interconnected environments with legacy systems and providers, adding to the complexity of achieving compliance. The transition process may, therefore, take more than the allotted time and efforts to meet the deadline, which could lead to a diversion of attention from other required business process change.
The DORA initiatives have come at a significant cost to firms, with some spending over EUR 1mn on compliance efforts in the last two years. While the positive impact of this change is likely to be felt later this decade, so will the negative. Underinvestment in other business areas, at the expense of DORA compliance, may also become apparent.
That said, it is important to remember that DORA compliance is not just about meeting regulatory demands and avoiding penalties, but that it is also about protecting against the escalating number of cyber threats facing the financial sector. As such, firms should not look at DORA as a cost burden, but rather a protective layer against future disruption caused be peers, suppliers and bad actors, which are becoming increasingly likely in a more digitised financial landscape.
Current Best Practices and Future Regulation
The DORA requirements should be treated as a baseline rather than a checklist, with resilience being embedded into business strategy as a core function rather than an IT requirement. Meeting the terms of DORA is an ongoing process with no final destination. For example, the ongoing monitoring of third-party providers’ business processes, which inevitably change in line with their own objectives.
GreySpark observes several practical steps that firms can take to address DORA’s compliance challenges:
- Strengthen ICT Risk Management Framework – Conduct a gap analysis to assess existing cybersecurity and IT risk management policies against DORA requirements. Define clear roles and responsibilities for ICT risk oversight, implement risk-based controls and ensure business continuity and recovery plans are tested.
- Establish an Incident Reporting Workflow – Automate incident detection and response using tools such as Security Information and Event Management (SIEM) and Extended Detection and Response (XDR). Conduct tabletop exercises and assign clear regulatory reporting responsibilities.
- Enhance Third-Party Risk Management – Identify critical suppliers under DORA requirements, review and update vendor contracts and ensure service level agreements align with compliance standards. GreySpark advises in-scope firms to use industry-recognised assurance frameworks to verify activities for each ICT provider. Leveraging, for example, independent assurance reports such as those provided by the American Institute of CPAs’ SOC 1 and SOC2, the UK’s Cyber Essentials and NIST’s Secure Software Development Framework (SSDF), and cloud-certification schemes that can streamline assessments and save time.
- Implement Resilience Testing – Conduct penetration testing every three years, including red team exercises and real-world automated simulations, as well as testing data backup and recovery procedures.
- Establish Cyber Threat Intelligence Sharing – Join Information Sharing and Analysis Centers (ISACs) and leverage automated threat intelligence feeds for real-time cyber threat monitoring.
Across the board, collaboration and innovation are critical for firms to stay on track with DORA’s requirements. In 2025, leveraging AI-driven risk monitoring tools and fostering strong partnerships within the industry are two key strategies that firms should investigate.
While DORA is currently getting a lot of attention, there is another EU regulation on the horizon: the EU Cyber Resilience Act, which will undergo a phased implementation culminating in full applicability by 2027. Its primary focus is on building robust security and vulnerability management mechanisms into vendors’ development and post-sale support processes for products with digital elements. This will complement DORA by ensuring vendors are also accountable for securing the products which financial institutions consume, and by further instilling a culture of operational resilience among in-scope financial firms.
Final Insights for Financial Institutions and Third-party ICT Providers
DORA seeks to provide a unified operational resilience framework in the EU, breaking new ground when it comes to strengthening the security of ICT providers and systems in the financial sector. With the regulation now in full effect, many in-scope firms are still grappling with the new requirements. There is no one-size-fits-all approach and each firm facing their own set of unique challenges. Nevertheless, firms can find ways to mitigate these challenges by ensuring robust management of critical third-party service providers and their own internal processes, and ultimately, by ensuring they are maintaining a proactive and continuously improving approach towards operational resilience. Firms that embrace DORA as a strategically, rather than as a regulatory obligation, will be better positioned to thrive in an increasingly complex digital landscape.





