Montro
DORA & Financial Services10 min read

DORA Enforcement: What's Next After The 17 January 2025 Go-Live

DORA Enforcement: What's Next After The 17 January 2025 Go-Live
AuthorNamita Razdan
Published on24 Jun 2026

Year one of DORA was about achieving documented compliance. Year two is about defending it under scrutiny, and most firms underestimated how different those two jobs are.


A year ago, everyone in financial services was preparing for DORA. Now they are operating under it.

The DORA compliance work the CISO who carried DORA through 17 January 2025 has a different problem in 2026. The documentation is in place. The frameworks are signed off. The processes were tested in the run-up. None of that is the issue. The issue is that the supervisors have moved from "is the framework in place" to "is what you said you would do, what you are actually doing", and the answer at most firms is partly.


This piece is the post-go-live perspective. What the European Supervisory Authorities have done in year one, where supervisor attention is concentrating, and what the year-two work looks like for a CISO at a mid-market in-scope financial entity.


What The ESAs Have Done In Year One


Year one of DORA regulation was largely about supervisory engagement, not direct enforcement. The pattern of activity:


Regulatory technical standards. The substantive Commission Delegated Regulations supplementing DORA have been published through 2024 and into 2025. The criteria for designating critical ICT third-party service providers are set out in Commission Delegated Regulation (EU) 2024/1502. The incident classification criteria are in Commission Delegated Regulation (EU) 2024/1772. The detailed content of the policy on contractual arrangements supporting critical or important functions is in Commission Delegated Regulation (EU) 2024/1773. The ICT risk management tools and the simplified framework are in Commission Delegated Regulation (EU) 2024/1774. The standard register templates are in Commission Implementing Regulation (EU) 2024/2956.


Critical third-party designation. The European Supervisory Authorities published their joint roadmap towards CTPP designation in February 2025. The first formal designations are advancing. For most mid-market firms, the practical implication is downstream: when a provider becomes critical, additional reporting and concentration-risk implications attach.


Joint Committee communications. The ESA Joint Committees published clarifications, Q&A material, and supervisor expectations through 2025, and have signalled supervisory priorities for 2026 that concentrate on third-party concentration analysis quality, ICT register completeness, and incident classification accuracy.


National supervisor activity. The Central Bank of Ireland, BaFin, and ACPR have each issued communications setting out their expectations on specific elements of the regime. Direct enforcement actions for DORA breaches have been limited, the year was about engagement, not punishment. That changes in 2026.


Three Pressure Points


Three areas of ICT risk management are receiving the bulk of supervisor attention. The pattern is consistent across national supervisors and is the most reliable signal of where 2026 enforcement will concentrate.


Third-Party Concentration


This is the area where 2026 enforcement attention will concentrate hardest. The DORA third-party risk pillar contains a specific obligation to identify, assess, and where appropriate report situations where dependence on specific ICT third-party providers, or networks of related providers, creates systemic exposure.


The pattern that catches firms is the apparent-multi-vendor that is actually a concentration. Three different SaaS vendors at the contract level, all running on AWS underneath. Three different fraud, KYC, and customer-support tools, all using the same AI sub-processor. Direct-vendor concentration analysis is necessary but not sufficient. This is where third party risk management under DORA regulation moves beyond contract-level analysis - the supervisor's expectation, particularly for ICT services classified as supporting critical or important functions, is moving toward fourth-party visibility - knowing not only your direct vendors, but their critical providers and the providers of those providers.

The work to close the gap is partly contractual (renegotiating sub-processor disclosure obligations) and partly operational (building third-party intelligence into the register-currency layer). Most firms have done the former at a contract-template level and the latter not at all.


Register Currency


Most firms produced an DORA ICT register entry under Article 8 register for the 17 January 2025 deadline. Most of those registers were correct on the day they were signed off. Most are now wrong.

The reason is structural, not procedural. Financial entities adopt new SaaS and ICT services every week - through procurement, through subscription renewals, through embedded AI features turning on inside existing tools, through engineering teams adopting devtools on team budgets. The DORA ICT register, maintained quarterly in a spreadsheet by a small team, cannot keep up with that change rate.

What Montro Finds At Onboarding

When a financial entity comes to Montro for the first time, they almost always bring their Article 8 register. This register is well organised and validated, and was correct on the day it was filed. What Montro's discovery layer finds in the weeks thereafter is a different picture. All the contracted vendors are there. The AI features activated inside those vendors since January 2025 are not. The devtools the engineering team adopted on team budgets are not. The embedded AI sub-processors three levels beneath the contracted relationship are not.


The register was not wrong when it was filed. It became wrong the moment the environment kept moving and the register did not. This is the central ICT risk management failure mode in year two of DORA compliance, not the initial build, but the currency of what was built.

The supervisor's question is not whether the register existed on the deadline; it is whether the register is true today, and how quickly the firm can produce a defensible version. The implication is that the time from request to defensible production is itself part of what is measured.


Incident Classification Accuracy


Article 19 sets the four-hour clock for major-incident notification. The classification criteria - number of clients affected, financial impact, geographic spread, duration, criticality of services impacted, reputational impact, data losses, are partly quantitative and partly qualitative. The classification call has to be made under time pressure, often with incomplete information about impact scope, by a duty officer who may not have specialist regulatory training.


Two failure modes are showing up in supervisor reviews. Under-classification, where a firm calls a major incident as non-major and the supervisor disagrees on retrospective review. Over-classification, where the firm produces unnecessary reporting noise that affects the supervisor's view of incident management capability. Both are remediable, but the remediation is preparation, not response: a documented classification decision matrix, a duty officer with delegated regulatory authority, tabletop exercises specifically for the four-hour notification.


What Good Year-Two Practice Looks Like


For a CISO at a mid-market in-scope financial entity allocating 2026 governance budget, three areas warrant priority attention.

  1. Bring the DORA ICT register current and keep it current. The register-currency layer that draws from operational sources continuously - SSO, procurement, expense management, identity provider, is the architectural fix. Quarterly manual refresh is no longer adequate to the supervisor's expectation, even where the documentary obligations have not formally changed.
  2. Close the third-party concentration analysis at the sub-processor level. Direct-vendor analysis was sufficient for go-live. Fourth-party visibility is where the supervisor is moving. The work splits between contract renegotiation (pushing for sub-processor disclosure as a contractual obligation, particularly at renewal) and operational tracking (building the sub-processor intelligence into the live DORA ICT register rather than maintaining it as a separate analysis).
  3. Test the four-hour incident classification process under realistic conditions. Tabletop exercises with deliberately ambiguous scenarios that stress the duty officer's regulatory authority. The output of each tabletop is twofold, a refined classification matrix, and evidence that the firm rehearses the call rather than discovering it under pressure.


The Pattern of Supervisor Attention


The first DORA enforcement actions in 2026 will likely include cases where firms identified concentration superficially, where registers were last refreshed quarterly with significant SaaS adoption since, and where incident classifications had documented gaps under retrospective review. The selection criteria for early enforcement, under regimes like this, typically include the materiality of the apparent breach, the firm's responsiveness to prior supervisory engagement, and the systemic relevance of the firm in question.


Most mid-market firms will not be subject to DORA enforcement in 2026. The firms that are will be selected partly to demonstrate the regime's enforcement capability and to set expectations for the broader population. Engaging constructively with supervisor communication, addressing identified gaps before they become findings, and maintaining the live operational layer beneath the documentary compliance, that is the year-two job.


Frequently Asked Questions


Has the EU issued any DORA enforcement actions yet?


Direct enforcement actions have been limited through year one, supervisors focused on engagement over punishment. That posture is shifting in 2026, with ESA communications signalling concentration analysis, register completeness, and incident classification as the priority areas for scrutiny.


What is a Critical ICT Third-Party Provider under DORA?


A CTPP is an ICT provider designated by the European Supervisory Authorities as systemically important to financial services. Designation triggers direct regulatory oversight by a Lead Overseer and additional concentration-risk obligations for financial entities that depend on that provider.


What does fourth-party visibility mean under DORA?


Fourth-party visibility means knowing not just your direct ICT vendors but the critical providers; those vendors depend on the sub-processors beneath your contracts. For ICT services supporting critical or important functions, supervisors are moving toward expecting this level of supply chain transparency.


What is the four-hour clock under DORA Article 19?


Article 19 requires financial entities to submit an initial notification to their competent authority within four hours of classifying an incident as major. The classification call, often made under time pressure with incomplete information, is where most firms are least prepared.

Namita Razdan

Namita Razdan

Co-founder

Fifteen years of financial services compliance and technology consulting across HSBC, EY, Accenture, and NTT Data - and the person in the room when regulators ask the hard questions. At Montro, she owns regulatory accuracy and sets the firm's position on EU AI Act, DORA, NIS2, and GDPR.

Blog

Read next

Explore more from our library

View all

Stay informed on EU AI governance

Monthly updates on regulatory changes, compliance trends, and platform releases

By subscribing you agree to our Terms and Conditions and Privacy Policy

Montro AI governance dashboard showing tool risk tiers