Compliance & GRC

DORA Is Not Just a European Problem

Aug 8, 20265 min read

DORA has been in force since January 2025. If you work in financial services in the European Union, you knew that. If you work at a technology company that provides software, infrastructure, or managed services to EU banks, asset managers, or insurance firms, there is a reasonable chance you are in scope and have not fully come to terms with that yet.

Eighteen months in, the first regulatory examinations are producing findings. The gap between what firms documented in their compliance programs and what they can demonstrate operationally is becoming visible.

What DORA Actually Covers

The Digital Operational Resilience Act applies to EU-regulated financial entities and their critical ICT third-party providers. The covered entity list is broad: banks, investment firms, payment institutions, insurance companies, crypto-asset service providers, and others. If you provide ICT services to any of these entities and that service is considered critical, DORA's third-party provisions reach you regardless of where you are incorporated.

The regulation organizes its requirements into five areas: ICT risk management, incident classification and reporting, digital operational resilience testing, third-party risk management, and information sharing arrangements. Each area has specific requirements. Testing and incident reporting are where most organizations are discovering they have more work to do than they expected.

The Incident Reporting Timeline

DORA specifies reporting timelines for major ICT incidents that differ substantially from what most organizations have built into their incident response programs. The structure is: an initial notification to the competent authority within four hours of classification as major, an intermediate report within 72 hours, and a final report within one month.

The four-hour initial notification is the part that catches programs off guard. Most incident response playbooks are designed around internal escalation first, external notification when the situation is understood. Under DORA, the clock on regulator notification starts at classification, not at containment or root cause identification.

Classification itself requires defined criteria. DORA specifies thresholds involving number of affected clients, criticality of impacted services, duration, geographic scope, and economic impact. Organizations that built their IR classification on subjective severity language are finding they need to rebuild that portion of the process with quantitative thresholds that match DORA's definitions.

The Testing Requirement

DORA requires annual basic digital resilience testing for all in-scope financial entities, and mandates Threat-Led Penetration Testing (TLPT) every three years for significant entities. The TLPT framework is derived from TIBER-EU and involves specific roles for external Red Team providers and Threat Intelligence providers, with regulator involvement in scoping.

TLPT is substantively different from a standard penetration test. It is driven by threat intelligence about realistic adversaries targeting the firm's specific profile. The regulator participates in approving scope. The Red Team and Threat Intelligence providers are subject to qualification requirements. The output includes a remediation plan that goes back to the supervisor. Firms cannot use their existing pentest vendor, run a standard test, and satisfy this requirement.

The lead time problem is underappreciated. Identifying and engaging a qualifying Red Team provider, completing the scope definition process with your competent authority, conducting the exercise, and delivering a remediation report takes longer than most security program timelines assume. Firms treating TLPT as a problem to solve twelve months before the deadline may find themselves short of runway.

Third-Party Risk at Scale

DORA's third-party risk requirements are more prescriptive than most frameworks. Financial entities must maintain a register of all ICT third-party providers and ensure that contracts with critical providers include specific provisions: termination rights, audit access rights, data portability, incident notification obligations, and service level guarantees structured around resilience.

The concentration risk provisions are where the larger policy concern surfaces. Regulators can designate cloud providers, major SaaS platforms, and payment infrastructure operators as Critical Third-Party Providers (CTPPs), subjecting them to direct EU oversight. Financial entities that depend heavily on a single designated provider face additional scrutiny and must demonstrate documented exit strategies and substitutability assessments. Exit strategies that describe switching cloud providers in a paragraph are not going to hold up.

Where US Companies Get Caught

DORA's reach extends beyond the EU through the third-party provisions. A US technology company that provides critical ICT services to EU financial entities may need to comply with contractual requirements its EU clients are now obligated to impose. Whether existing contracts meet those requirements is a question many US firms are working through, often after an EU client has sent revised contract language.

The practical consequence is contract renegotiation. EU financial entities are adding DORA-required provisions to vendor agreements. Technology providers without a clear DORA compliance position are being asked to negotiate audit rights, notification timelines, and portability requirements they have never encountered before.

Where Things Stand

Every significant compliance regulation follows the same sequence: announcement, grace period, initial documentation, examination, discovery of gaps, remediation pressure. DORA is in the examination phase.

Organizations that treated DORA as a documentation exercise are discovering what the first examination cycle finds. The firms that mapped their incident response to the four-hour notification requirement, structured their testing calendar around TLPT lead times, and audited their third-party contracts for DORA-required provisions are in a materially different position. The deadline has passed. The question now is which category your program is in.