DORA Compliance in 2026: A Board-Level Readiness Guide

For most of 2025, the Digital Operational Resilience Act was treated as a documentation exercise. Firms wrote policies, populated registers, and told their boards they were "on track". That grace period is over. Since full application on 17 January 2025, and decisively through 2026, national regulators across the EU have shifted from reading paperwork to demanding proof: real evidence that a firm can withstand, respond to, and recover from an ICT disruption. The question a supervisor now asks is not "do you have a framework" but "show me it works".

DORA Compliance in 2026: A Board-Level Readiness Guide - Richard Keenlyside, Fractional CIO, CTO and CISO
DORA Compliance in 2026: A Board-Level Readiness Guide

For any board with exposure to EU financial services, this is a governance issue before it is a technology one, and it lands squarely on the management body. This is a board-level guide to what DORA actually requires, why 2026 is different, and the readiness steps that matter.

What DORA is, and whether it applies to you

DORA (Regulation EU 2022/2554) is EU law that sets a single, binding standard for digital operational resilience across the financial sector. It applies to around 20 types of financial entity, from banks, insurers and investment firms to payment providers, asset managers and crypto-asset service providers, and, importantly, to the critical ICT third parties that serve them.

UK boards should not assume this is someone else's problem. DORA reaches beyond the EU's borders. A UK firm with EU operations or EU-regulated entities in its group is in scope. A UK technology or outsourcing provider serving EU financial entities can be pulled in through its clients' third-party obligations. And for PE-backed portfolios, a single financial-services or fintech asset with EU exposure can put the group's resilience posture under scrutiny. If you are unsure whether DORA touches you, that uncertainty is itself the first thing to resolve.

The five pillars, in plain English

DORA consolidates what used to be scattered across different rules into five areas:

  • ICT risk management. A documented framework, owned and overseen by the board, for identifying, protecting, detecting, responding to and recovering from ICT risk.
  • Incident management and reporting. Classifying ICT-related incidents and reporting the major ones to your regulator within strict timelines. This demands detection and escalation that actually work under pressure, not on paper.
  • Digital operational resilience testing. Regular testing of your defences, rising to threat-led penetration testing (TLPT) for larger, more significant entities.
  • ICT third-party risk. Active oversight of your technology supply chain, underpinned by the Register of Information: a complete inventory of every ICT provider, contract and dependency.
  • Information sharing. Voluntary participation in cyber threat intelligence sharing, encouraged as part of a proactive posture.

If your organisation already runs an ISO 27001 information security management system, you are not starting from zero. Much of DORA's ICT risk management and third-party expectation maps onto controls you may already operate. The work is in closing the specific gaps DORA adds, not rebuilding from scratch, and the fastest readiness programmes I have seen start exactly there.

Why 2026 is different: from paperwork to proof

Three shifts make this year the one that matters.

First, enforcement has teeth. Supervisors are now cross-checking data automatically. Your Register of Information is filed alongside those of every other firm using the same critical provider, and inconsistencies or late updates are flagged quickly. Incomplete registers have been the single most common trigger for supervisory letters in the first enforcement cycle, and it is worth knowing the Register is consistently reported as the hardest requirement to get right.

Second, the money is real. Entities face fines of up to 2% of total annual worldwide turnover. Critical ICT providers can be fined daily until they comply. And in several jurisdictions, senior executives now face personal fines running to seven figures for failing to oversee ICT risk adequately.

Third, and most important for a board, accountability is personal and explicit. DORA places ultimate responsibility for digital operational resilience on the management body. Board members are expected to undergo ICT risk training, and supervisors are reading board minutes to confirm that resilience is a standing agenda item rather than an afterthought. "We delegated it to IT" is no longer a defence.

A 90-day board readiness sprint

If DORA has drifted down your agenda, here is how I would bring it back under control quickly.

Days 1 to 30: establish the truth. Confirm scope: which entities and which EU touchpoints bring you in. Run an honest gap analysis against the five pillars, mapping to your existing ISO 27001 or NIST controls so you reuse what already works. Above all, get eyes on the Register of Information: is it complete, accurate and owned by someone, or scattered across procurement, business units and subsidiaries? This is almost always where the real exposure sits.

Days 31 to 60: close the priority gaps. Fix the Register first. Tighten incident classification and reporting so a major incident is detected, escalated and reported inside the required window, tested with a real scenario rather than assumed. Review your critical third-party contracts against DORA's requirements, and build exit strategies to reduce concentration risk on any single provider.

Days 61 to 90: embed and evidence. Stand up your resilience testing programme, including TLPT where you are in scope. Put DORA on the board agenda as a permanent item with clear ownership, and make sure the audit trail, incident logs, test results and remediation records, is structured and retrievable, because supervisors now want evidence, not assurances. The goal is not a binder that says you are compliant. It is a live, demonstrable operational capability.

Turning a compliance burden into resilience

The firms that treat DORA as a box-ticking project will keep failing supervisory reviews and carrying personal risk at board level. The firms that treat it as what it actually is, a mandate to genuinely withstand and recover from disruption, come out with something worth having: a more resilient business that regulators, investors and customers can trust.

Frequently asked questions

What is DORA compliance?
DORA compliance means meeting the Digital Operational Resilience Act's binding requirements for managing ICT risk, reporting major incidents, testing resilience, and overseeing technology suppliers, and being able to prove to a regulator that those measures work in practice rather than only on paper.

Does DORA apply to UK firms?
It can. DORA is EU law, but it reaches UK firms with EU operations or EU-regulated group entities, and UK technology providers serving EU financial entities through their clients' third-party obligations. Any group with EU financial-services exposure should confirm its position rather than assume it is out of scope.

What are the five pillars of DORA?
ICT risk management, ICT incident management and reporting, digital operational resilience testing, ICT third-party risk management, and information sharing. Together they require a board-owned framework that can withstand, respond to and recover from ICT disruption.

What is the DORA Register of Information?
It is a complete, structured inventory of every ICT third-party provider, contract and dependency an entity relies on. Regulators cross-check it automatically, and incomplete or inconsistent registers have been the leading cause of supervisory letters, which is why it is widely reported as DORA's hardest requirement.

What are the penalties for DORA non-compliance?
Financial entities can face fines of up to 2% of total annual worldwide turnover, critical ICT providers can be fined daily until they comply, and in some jurisdictions individual senior executives face personal fines for inadequate oversight. Beyond the fines, the reputational and supervisory consequences of a failed review are significant.

Get DORA-ready before the supervisor calls

If your board needs an experienced, independent hand to assess your DORA exposure, fix the gaps, and put resilience on a footing that will survive scrutiny, book a confidential conversation. I help boards and PE-backed businesses turn regulatory pressure into genuine operational resilience, drawing on hands-on fractional and interim CISO leadership and ISO 27001 delivery. If your wider concern is cyber resilience and incident readiness, an interim CISO can stand that capability up fast.