← All briefings

Industry Research Brief — DORA in Active Supervision: Examination Readiness Across EU Financial Authorities

54aac838-9094-4de5-ac24-993672505cbc

Executive Summary: DORA has moved into active supervision, but not through one uniform EU-wide examination programme. In 2025 the ECB aligned its supervisory methodologies with DORA, collected Registers of Information and continued on-site work on cybersecurity and ICT third-party risk; its 2026–2028 programme includes targeted remediation follow-up, on-site inspection campaigns, TLPT, ICT change-management review and a cloud-provider disruption deep dive. Other competent authorities are integrating DORA through their own risk-based, sector-specific programmes. Financial entities should maintain a common evidence foundation covering management-body oversight, annual ICT-framework review, incident classification and reporting, resilience testing, third-party registers and contracts, concentration and substitutability, exit planning and verified remediation closure—while tailoring the presentation to the authority and sector involved.

Information reviewed through August 4, 2026. Revised after legal-precision verification of Register of Information wording, TLPT frequency, incident-reporting clocks, obligation-versus-artifact labeling, testing requirements, and entity-versus-critical-provider enforcement.

I. Exposure Vector

An in-scope financial entity completed a 2024–2025 DORA implementation programme. Policies exist. The entity created its Register of Information and submitted it where required by its competent authority during the 2025 data-collection exercise. It has not yet demonstrated that the register remains complete, current and reconciled to procurement, contracts and critical-function inventories. Contracts were partially uplifted. Tabletop exercises were scheduled once.

In 2026, the exposure shifts from design completeness to supervisory credibility:

  • Can management demonstrate annual ICT-framework review—and that identified improvements enter controlled remediation—rather than a one-time approval?
  • Are major ICT-related incidents classified and reported on the required clocks (initial notification, 72-hour intermediate report, final report) with retained decision logs?
  • Is resilience testing risk-based, documented, and linked to remediation—including annual testing of systems supporting critical or important functions and annual continuity/recovery testing where required?
  • Where threat-led penetration testing (TLPT) applies, has the competent authority identified the entity, and is the required testing date, scope and three-year (or authority-adjusted) cycle documented?
  • Are ICT third-party arrangements complete as to contractual clauses, register quality, pre-contract assessment, concentration and substitutability, and periodically tested exit or transition plans?
  • When supervisors ask for evidence, can the entity produce operating artifacts—tickets, test reports, board minutes showing challenge, remediation trackers—or only policy PDFs?

DORA (Regulation (EU) 2022/2554) entered into application on 17 January 2025 for in-scope financial entities’ digital operational resilience obligations, including ICT risk management, incident handling and reporting, resilience testing, and ICT third-party risk. [1][2]

Supervision is active, not hypothetical. For significant banks, the ECB reports that DORA reshaped 2025 supervisory activity—updated methodologies, ICT-risk on-site inspections, Register of Information collection, TLPT oversight capacity, and work on cybersecurity and ICT third-party risk—and that its 2026–2028 priorities include targeted remediation follow-up, two on-site inspection campaigns on cybersecurity and third-party risk, TLPT, an ICT change-management review, and a deep dive into preparedness for disruption at a major cloud provider. [3][4]

Other authorities use different methods. Luxembourg’s CSSF, for example, made risk-based monitoring of DORA implementation a 2026 investment-fund supervisory priority, focusing on ICT-risk procedures, reports and major incident notifications. [5]

Critical ICT third-party provider oversight at EU level moved into designation and operational architecture: the ESAs designated the first critical ICT third-party providers on 18 November 2025 (published list of 19 providers), and the ECB’s 2026–2028 priorities state that the operational oversight framework launched in January 2026. That EU-level CTPP oversight is distinct from competent authorities supervising financial entities under DORA Article 46. [6][7][4]

Title discipline: This briefing discusses supervision and examination readiness. It does not assert a formal, EU-wide programme branded “year-two NCA exams.”

Same DORA baseline; different supervisory methods, evidence requests and escalation routes.

II. Quantitative Context

SignalInterpretive use
Application since 17 January 2025Live obligations; second calendar year by August 2026
Register of InformationMaintain and update; report at least annually on new arrangements; provide complete register or requested sections on authority request; 2025 CA collection for ESA CTPP designation was authority-timed [1][8]
TLPT for identified entitiesAt least every three years, or more/less often as the competent authority decides based on risk and circumstances [1]
Major ICT-related incidents reported in 2025ESAs’ first annual report: 3,383 major incidents; about one-third had cross-border effects [11]
Parallel NCA/SSM/sectoral methodsSame regulation; different evidence requests and escalation paths [1][3][4][5]

Do not invent a single fixed EU monetary penalty as “the cost of DORA failure” for financial entities. DORA requires Member States to establish effective, proportionate and dissuasive administrative penalties and remedial measures under national frameworks; competent authorities must have access to documents and data, investigation and on-site inspection powers, and authority to require corrective measures. [1]

A separate EU-level periodic-penalty mechanism applies to designated critical ICT third-party providers that fail to comply with Lead Overseer measures: up to 1% of the provider’s average daily worldwide turnover per day, for no more than six months. That mechanism does not establish a universal penalty for financial entities. [1]

Boards should quantify open remediation items by severity and dependency on critical or important functions—not by aspirational percentage-complete dashboards alone.

III. What Modern GRC Must Enforce

DORA obligations and prudent examination-readiness evidence

DomainBinding requirement (DORA / RTS–ITS)Prudent supporting evidence
ICT risk-management frameworkDocumented framework; reviewed at least annually, after major ICT incidents, and following supervisory instructions or testing/audit conclusions; continuously improved [1]Annual framework review records; changes following incidents, testing, audits or supervisory findings; management approval; improvements entered into controlled remediation
Management-body accountabilityUltimate ICT-risk responsibility on the management body: approve/oversee framework, set ICT-risk tolerance, review continuity and recovery plans, approve ICT audit plans, review budgets, oversee third-party policy, maintain reporting channels on provider arrangements, material changes and major incidents [1]Minutes showing challenge, decisions, resource allocation and escalation of material ICT risk (format not prescribed by DORA)
Incident classification and reportingClassification and reporting under DORA and Commission Delegated Regulation (EU) 2025/301 / Implementing Regulation (EU) 2025/302 [1][10][12]Awareness time; classification analysis; major-incident determination time; initial notification; 72-hour intermediate report; final report; regulator correspondence; documented reason for any delay
Resilience testing programmeRisk-based testing programme; for entities other than microenterprises, appropriate testing at least yearly on ICT systems and applications supporting critical or important functions; ICT business-continuity and response-and-recovery plans for systems supporting all functions tested at least yearly and after substantive changes affecting critical or important functions [1]Risk-based test inventory; evidence of appropriate annual testing for critical/important-function systems; annual continuity and response/recovery test evidence; findings, corrective actions and retest results
TLPT (where identified)Identified entities conduct TLPT at least every three years (authority may adjust frequency); methodology under Commission Delegated Regulation (EU) 2025/1190 [1][13]Designation/identification status; required testing date and scope; cycle or adjusted frequency; scoped scenarios; remediation from findings
ICT third-party registerMaintain and update register of ICT contractual arrangements at entity, sub-consolidated and consolidated levels where applicable; distinguish services supporting critical or important functions; report at least annually on new arrangements; provide register or sections on request [1]Complete, current register reconciled to procurement, contracts and critical-function inventories
Contracts and subcontractingRequired contractual clauses; additional provisions for critical or important functions; subcontracting rules under Commission Delegated Regulation (EU) 2025/532 and contractual-policy requirements under Commission Delegated Regulation (EU) 2024/1773 [1][14][15]Clause gap analysis vs DORA contractual expectations; uplift tracker; monitoring and audit-rights evidence
Concentration, substitutability and exitPre-contract risk assessment; concentration and substitutability assessment; documented and periodically tested exit plans; alternative solutions and transition plans [1]Dependency maps; substitutability assessments; tested exit or transition options (ECB 2025 register analysis noted heavy reliance on few providers, low substitutability and difficulty bringing services back in-house) [3]
Remediation trackingFormal follow-up and remediation for critical audit findings; continuous improvement of the framework [1]Aged findings with owners, due dates, residual-risk acceptance and verified closure
Operating effectivenessFramework implemented, reviewed, audited, tested and improved—not merely documented [1]Samples showing policies used in incidents, changes, procurements and board packs

Major ICT-related incident clocks (operative technical standard)

Under Commission Delegated Regulation (EU) 2025/301, the reporting sequence after classification as a major incident includes: [10]

  • an initial notification within four hours after classification as a major incident and no later than 24 hours after awareness;
  • an intermediate report within 72 hours after the initial notification; and
  • a final report no later than one month after the intermediate report—or the latest updated intermediate report.

Label supervisory differences

Authority contextPractical implication
ECB / SSM (significant institutions)Integrated banking supervision with DORA-aligned methodologies, OSI campaigns, TLPT and cloud-disruption deep dives [3][4]
National competent authoritiesLocal priorities, templates and enforcement ladders (e.g. CSSF fund-sector DORA monitoring) [5]
Insurance / securities / other sectoral supervisorsSame DORA baseline under Article 46 allocation; different portfolio risk focus and information requests [1]
Critical ICT third-party oversight (EU level)Joint Examination Teams examine designated CTPPs; distinct from entity-level exams under Article 46; still affects concentration and contractual leverage [6][7]

Control-system requirements

Failure modeRequirement
“DORA project closed” in 2025Continuous evidence production and remediation ownership
Register quality treated as a one-off filingReconcile register to contracts and critical functions on an ongoing basis
Testing without remediation closureLink findings to tracked corrective actions and retests
Identical playbook assumed for all NCAsMaintain a core evidence library; adapt packs to the asking authority
Confusing CTPP oversight with entity examsTrack entity obligations separately from Lead Overseer measures on designated providers

IV. Verification Protocol

  1. Confirm DORA application date of 17 January 2025 from Regulation (EU) 2022/2554. [1]
  2. Do not claim a single harmonised “year-two NCA examination cycle” across the Union unless a specific authority’s published programme is cited. [3][4][5]
  3. Separate entity supervision (Article 46) from EU-level critical ICT third-party oversight (Articles 31–44). [1][6][7]
  4. State incident clocks from Commission Delegated Regulation (EU) 2025/301—not paraphrased “required timelines.” [10]
  5. State TLPT as at-least-every-three-years for identified entities, adjustable by the competent authority—not a vague “later in the decade” completion expectation. [1][13]
  6. Keep CPS 230 (Australia), the AI Act, CSRD, and SEC cyber disclosure out of this briefing’s lead claims.
  7. For any country-specific assertion, cite that NCA’s guidance or public supervisory communication.

Key Takeaways

  • By August 2026, DORA work is supervisory evidence work under authority-specific programmes.
  • Prepare a common evidence foundation; expect different asking styles across ECB/SSM, NCAs and sectoral supervisors.
  • Registers, contracts, testing, incident clocks, concentration/exit and remediation closure are where policies meet examination.
  • CTPP designation and Lead Overseer measures are real—and separate from entity-level exams.

V. Sources & Citations