Industry Research Brief — DORA in Active Supervision: Examination Readiness Across EU Financial Authorities
54aac838-9094-4de5-ac24-993672505cbc
Executive Summary: DORA has moved into active supervision, but not through one uniform EU-wide examination programme. In 2025 the ECB aligned its supervisory methodologies with DORA, collected Registers of Information and continued on-site work on cybersecurity and ICT third-party risk; its 2026–2028 programme includes targeted remediation follow-up, on-site inspection campaigns, TLPT, ICT change-management review and a cloud-provider disruption deep dive. Other competent authorities are integrating DORA through their own risk-based, sector-specific programmes. Financial entities should maintain a common evidence foundation covering management-body oversight, annual ICT-framework review, incident classification and reporting, resilience testing, third-party registers and contracts, concentration and substitutability, exit planning and verified remediation closure—while tailoring the presentation to the authority and sector involved.
Information reviewed through August 4, 2026. Revised after legal-precision verification of Register of Information wording, TLPT frequency, incident-reporting clocks, obligation-versus-artifact labeling, testing requirements, and entity-versus-critical-provider enforcement.
I. Exposure Vector
An in-scope financial entity completed a 2024–2025 DORA implementation programme. Policies exist. The entity created its Register of Information and submitted it where required by its competent authority during the 2025 data-collection exercise. It has not yet demonstrated that the register remains complete, current and reconciled to procurement, contracts and critical-function inventories. Contracts were partially uplifted. Tabletop exercises were scheduled once.
In 2026, the exposure shifts from design completeness to supervisory credibility:
- Can management demonstrate annual ICT-framework review—and that identified improvements enter controlled remediation—rather than a one-time approval?
- Are major ICT-related incidents classified and reported on the required clocks (initial notification, 72-hour intermediate report, final report) with retained decision logs?
- Is resilience testing risk-based, documented, and linked to remediation—including annual testing of systems supporting critical or important functions and annual continuity/recovery testing where required?
- Where threat-led penetration testing (TLPT) applies, has the competent authority identified the entity, and is the required testing date, scope and three-year (or authority-adjusted) cycle documented?
- Are ICT third-party arrangements complete as to contractual clauses, register quality, pre-contract assessment, concentration and substitutability, and periodically tested exit or transition plans?
- When supervisors ask for evidence, can the entity produce operating artifacts—tickets, test reports, board minutes showing challenge, remediation trackers—or only policy PDFs?
DORA (Regulation (EU) 2022/2554) entered into application on 17 January 2025 for in-scope financial entities’ digital operational resilience obligations, including ICT risk management, incident handling and reporting, resilience testing, and ICT third-party risk. [1][2]
Supervision is active, not hypothetical. For significant banks, the ECB reports that DORA reshaped 2025 supervisory activity—updated methodologies, ICT-risk on-site inspections, Register of Information collection, TLPT oversight capacity, and work on cybersecurity and ICT third-party risk—and that its 2026–2028 priorities include targeted remediation follow-up, two on-site inspection campaigns on cybersecurity and third-party risk, TLPT, an ICT change-management review, and a deep dive into preparedness for disruption at a major cloud provider. [3][4]
Other authorities use different methods. Luxembourg’s CSSF, for example, made risk-based monitoring of DORA implementation a 2026 investment-fund supervisory priority, focusing on ICT-risk procedures, reports and major incident notifications. [5]
Critical ICT third-party provider oversight at EU level moved into designation and operational architecture: the ESAs designated the first critical ICT third-party providers on 18 November 2025 (published list of 19 providers), and the ECB’s 2026–2028 priorities state that the operational oversight framework launched in January 2026. That EU-level CTPP oversight is distinct from competent authorities supervising financial entities under DORA Article 46. [6][7][4]
Title discipline: This briefing discusses supervision and examination readiness. It does not assert a formal, EU-wide programme branded “year-two NCA exams.”
Same DORA baseline; different supervisory methods, evidence requests and escalation routes.
II. Quantitative Context
| Signal | Interpretive use |
|---|---|
| Application since 17 January 2025 | Live obligations; second calendar year by August 2026 |
| Register of Information | Maintain and update; report at least annually on new arrangements; provide complete register or requested sections on authority request; 2025 CA collection for ESA CTPP designation was authority-timed [1][8] |
| TLPT for identified entities | At least every three years, or more/less often as the competent authority decides based on risk and circumstances [1] |
| Major ICT-related incidents reported in 2025 | ESAs’ first annual report: 3,383 major incidents; about one-third had cross-border effects [11] |
| Parallel NCA/SSM/sectoral methods | Same regulation; different evidence requests and escalation paths [1][3][4][5] |
Do not invent a single fixed EU monetary penalty as “the cost of DORA failure” for financial entities. DORA requires Member States to establish effective, proportionate and dissuasive administrative penalties and remedial measures under national frameworks; competent authorities must have access to documents and data, investigation and on-site inspection powers, and authority to require corrective measures. [1]
A separate EU-level periodic-penalty mechanism applies to designated critical ICT third-party providers that fail to comply with Lead Overseer measures: up to 1% of the provider’s average daily worldwide turnover per day, for no more than six months. That mechanism does not establish a universal penalty for financial entities. [1]
Boards should quantify open remediation items by severity and dependency on critical or important functions—not by aspirational percentage-complete dashboards alone.
III. What Modern GRC Must Enforce
DORA obligations and prudent examination-readiness evidence
| Domain | Binding requirement (DORA / RTS–ITS) | Prudent supporting evidence |
|---|---|---|
| ICT risk-management framework | Documented framework; reviewed at least annually, after major ICT incidents, and following supervisory instructions or testing/audit conclusions; continuously improved [1] | Annual framework review records; changes following incidents, testing, audits or supervisory findings; management approval; improvements entered into controlled remediation |
| Management-body accountability | Ultimate ICT-risk responsibility on the management body: approve/oversee framework, set ICT-risk tolerance, review continuity and recovery plans, approve ICT audit plans, review budgets, oversee third-party policy, maintain reporting channels on provider arrangements, material changes and major incidents [1] | Minutes showing challenge, decisions, resource allocation and escalation of material ICT risk (format not prescribed by DORA) |
| Incident classification and reporting | Classification and reporting under DORA and Commission Delegated Regulation (EU) 2025/301 / Implementing Regulation (EU) 2025/302 [1][10][12] | Awareness time; classification analysis; major-incident determination time; initial notification; 72-hour intermediate report; final report; regulator correspondence; documented reason for any delay |
| Resilience testing programme | Risk-based testing programme; for entities other than microenterprises, appropriate testing at least yearly on ICT systems and applications supporting critical or important functions; ICT business-continuity and response-and-recovery plans for systems supporting all functions tested at least yearly and after substantive changes affecting critical or important functions [1] | Risk-based test inventory; evidence of appropriate annual testing for critical/important-function systems; annual continuity and response/recovery test evidence; findings, corrective actions and retest results |
| TLPT (where identified) | Identified entities conduct TLPT at least every three years (authority may adjust frequency); methodology under Commission Delegated Regulation (EU) 2025/1190 [1][13] | Designation/identification status; required testing date and scope; cycle or adjusted frequency; scoped scenarios; remediation from findings |
| ICT third-party register | Maintain and update register of ICT contractual arrangements at entity, sub-consolidated and consolidated levels where applicable; distinguish services supporting critical or important functions; report at least annually on new arrangements; provide register or sections on request [1] | Complete, current register reconciled to procurement, contracts and critical-function inventories |
| Contracts and subcontracting | Required contractual clauses; additional provisions for critical or important functions; subcontracting rules under Commission Delegated Regulation (EU) 2025/532 and contractual-policy requirements under Commission Delegated Regulation (EU) 2024/1773 [1][14][15] | Clause gap analysis vs DORA contractual expectations; uplift tracker; monitoring and audit-rights evidence |
| Concentration, substitutability and exit | Pre-contract risk assessment; concentration and substitutability assessment; documented and periodically tested exit plans; alternative solutions and transition plans [1] | Dependency maps; substitutability assessments; tested exit or transition options (ECB 2025 register analysis noted heavy reliance on few providers, low substitutability and difficulty bringing services back in-house) [3] |
| Remediation tracking | Formal follow-up and remediation for critical audit findings; continuous improvement of the framework [1] | Aged findings with owners, due dates, residual-risk acceptance and verified closure |
| Operating effectiveness | Framework implemented, reviewed, audited, tested and improved—not merely documented [1] | Samples showing policies used in incidents, changes, procurements and board packs |
Major ICT-related incident clocks (operative technical standard)
Under Commission Delegated Regulation (EU) 2025/301, the reporting sequence after classification as a major incident includes: [10]
- an initial notification within four hours after classification as a major incident and no later than 24 hours after awareness;
- an intermediate report within 72 hours after the initial notification; and
- a final report no later than one month after the intermediate report—or the latest updated intermediate report.
Label supervisory differences
| Authority context | Practical implication |
|---|---|
| ECB / SSM (significant institutions) | Integrated banking supervision with DORA-aligned methodologies, OSI campaigns, TLPT and cloud-disruption deep dives [3][4] |
| National competent authorities | Local priorities, templates and enforcement ladders (e.g. CSSF fund-sector DORA monitoring) [5] |
| Insurance / securities / other sectoral supervisors | Same DORA baseline under Article 46 allocation; different portfolio risk focus and information requests [1] |
| Critical ICT third-party oversight (EU level) | Joint Examination Teams examine designated CTPPs; distinct from entity-level exams under Article 46; still affects concentration and contractual leverage [6][7] |
Control-system requirements
| Failure mode | Requirement |
|---|---|
| “DORA project closed” in 2025 | Continuous evidence production and remediation ownership |
| Register quality treated as a one-off filing | Reconcile register to contracts and critical functions on an ongoing basis |
| Testing without remediation closure | Link findings to tracked corrective actions and retests |
| Identical playbook assumed for all NCAs | Maintain a core evidence library; adapt packs to the asking authority |
| Confusing CTPP oversight with entity exams | Track entity obligations separately from Lead Overseer measures on designated providers |
IV. Verification Protocol
- Confirm DORA application date of 17 January 2025 from Regulation (EU) 2022/2554. [1]
- Do not claim a single harmonised “year-two NCA examination cycle” across the Union unless a specific authority’s published programme is cited. [3][4][5]
- Separate entity supervision (Article 46) from EU-level critical ICT third-party oversight (Articles 31–44). [1][6][7]
- State incident clocks from Commission Delegated Regulation (EU) 2025/301—not paraphrased “required timelines.” [10]
- State TLPT as at-least-every-three-years for identified entities, adjustable by the competent authority—not a vague “later in the decade” completion expectation. [1][13]
- Keep CPS 230 (Australia), the AI Act, CSRD, and SEC cyber disclosure out of this briefing’s lead claims.
- For any country-specific assertion, cite that NCA’s guidance or public supervisory communication.
Key Takeaways
- By August 2026, DORA work is supervisory evidence work under authority-specific programmes.
- Prepare a common evidence foundation; expect different asking styles across ECB/SSM, NCAs and sectoral supervisors.
- Registers, contracts, testing, incident clocks, concentration/exit and remediation closure are where policies meet examination.
- CTPP designation and Lead Overseer measures are real—and separate from entity-level exams.
V. Sources & Citations
-
[1] Regulation (EU) 2022/2554 (Digital Operational Resilience Act)
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022R2554
Operative provisions relied upon include Articles 5–16 (governance and ICT-risk management), 17–23 (incidents), 24–27 (testing and TLPT), 28–30 (third-party risk and contracts), 31–44 (critical-provider oversight), and 46–52 (competent authorities and enforcement). Retrieved / re-verified 2026-08-04. -
[2] European Insurance and Occupational Pensions Authority — Digital Operational Resilience Act overview
https://www.eiopa.europa.eu/digital-operational-resilience-act-dora_en
Concise official secondary summary that DORA entered into application on 17 January 2025. Does not replace the operative regulation or technical standards. Retrieved / re-verified 2026-08-04. -
[3] European Central Bank Banking Supervision — Annual Report on supervisory activities 2025
https://www.bankingsupervision.europa.eu/press/other-publications/annual-report/html/ssm.ar2025~6ee989dc7e.en.html
Describes DORA’s effect on 2025 supervisory activity, including methodology updates, ICT on-site work, Register of Information collection, TLPT capacity and ICT third-party / cybersecurity examination themes; also notes concentration and low substitutability findings from register analysis. Retrieved 2026-08-04. -
[4] European Central Bank Banking Supervision — Supervisory priorities 2026–2028
https://www.bankingsupervision.europa.eu/framework/priorities/html/ssm.supervisory_priorities202511.en.html
States DORA-related priorities including targeted remediation follow-up, two OSI campaigns on cybersecurity and third-party risk, TLPT, ICT change-management review, cloud-provider disruption deep dive, and launch of CTPP oversight in January 2026. Retrieved 2026-08-04. -
[5] Commission de Surveillance du Secteur Financier — 2026 priorities for supervising the investment fund sector
https://www.cssf.lu/en/2026/03/the-cssfs-2026-priorities-for-supervising-the-investment-fund-sector/
Identifies risk-based monitoring of DORA implementation—including ICT-risk procedures, reports and major incident notifications—as a 2026 fund-sector priority. Published 31 March 2026. Retrieved 2026-08-04. -
[6] European Supervisory Authorities — designation of critical ICT third-party providers (18 November 2025)
https://www.eba.europa.eu/publications-and-media/press-releases/european-supervisory-authorities-designate-critical-ict-third-party-providers-under-digital
Publishes the first CTPP list under DORA and describes designation methodology based on Registers of Information and criticality assessment with competent authorities. Published list comprises 19 designated providers. Retrieved 2026-08-04. -
[7] European Supervisory Authorities — Guide on DORA Oversight activities
https://www.eiopa.europa.eu/esas-publish-guide-dora-oversight-activities-2025-07-15_en
Explains Joint Examination Team oversight of critical providers as distinct from competent-authority supervision of financial entities. Retrieved 2026-08-04. -
[8] European Supervisory Authorities — timeline to collect information for designation of critical ICT third-party service providers
https://www.eba.europa.eu/publications-and-media/press-releases/esas-announce-timeline-collect-information-designation-critical-ict-third-party-service-providers
Describes competent-authority collection of register information for ESA designation work; deadlines and processes are authority-specific. Retrieved 2026-08-04. -
[9] European Central Bank — Governing Council decisions (reference for TLPT identification of supervised entities in 2025 supervisory programme)
https://www.ecb.europa.eu/press/govcdec/otherdec/2025/html/ecb.gc250725~7913f7a897.en.html
Supporting context for ECB TLPT identification activity; use together with [4] for 2026 TLPT supervisory work. Retrieved 2026-08-04. -
[10] Commission Delegated Regulation (EU) 2025/301
https://eur-lex.europa.eu/eli/reg_del/2025/301/oj/eng
Incident-reporting content and timelines (initial / intermediate / final clocks). Retrieved 2026-08-04. -
[11] European Supervisory Authorities — first report on DORA major ICT-related incidents (3 June 2026)
https://www.eiopa.europa.eu/esas-publish-first-report-dora-major-ict-related-incidents-2026-06-03_en
Reports 3,383 major ICT-related incidents in 2025, with approximately one-third having cross-border impact. Retrieved 2026-08-04. -
[12] Commission Implementing Regulation (EU) 2025/302
https://eur-lex.europa.eu/eli/reg_impl/2025/302/oj/eng
Reporting templates and procedures for major ICT-related incidents. Retrieved 2026-08-04. -
[13] Commission Delegated Regulation (EU) 2025/1190
https://eur-lex.europa.eu/eli/reg_del/2025/1190/oj/eng
TLPT selection, methodology, closure and remediation. Retrieved 2026-08-04. -
[14] Commission Delegated Regulation (EU) 2025/532
https://eur-lex.europa.eu/eli/reg_del/2025/532/oj/eng
Subcontracting supporting critical or important functions. Retrieved 2026-08-04. -
[15] Commission Delegated Regulation (EU) 2024/1773
https://eur-lex.europa.eu/eli/reg_del/2024/1773/oj/eng
Contractual-policy requirements for ICT services supporting critical or important functions. Retrieved 2026-08-04.