Financial Services
DORA moves from questionnaires to enforcement
DORA has applied to EU financial entities since January 2025. In 2026 national competent authorities began acting on the Register of Information data they collected.

What does DORA enforcement look like in 2026?
Supervision has moved past questionnaires. DORA has applied to EU financial entities since January 2025, and in 2026 national competent authorities began acting on the Register of Information data they collected, testing ICT third party oversight, incident reporting timelines and resilience testing evidence. The practical shift is from documented policy to demonstrable operation.
Key facts
DORA (Regulation (EU) 2022/2554) has applied since 17 January 2025.
Register of Information submissions gave supervisors comparable data across firms.
Industry reporting through 2026 describes the first compulsion payments and remediation orders.
Where the regime is
DORA sets requirements for ICT risk management, incident reporting, operational resilience testing and ICT third party risk for a wide set of EU financial entities. It has been applicable since January 2025.
The first eighteen months were dominated by data collection: registers, questionnaires and baseline readiness assessments. Industry coverage through the first half of 2026 describes supervisors shifting to remediation orders and compulsion payments.
Readiness is still uneven
Reported survey figures remain uncomfortable. Coverage of the Span Cyber Security Arena conference cited a claim that 96 percent of EMEA financial services firms say their data resilience does not yet meet DORA expectations.
Treat single survey numbers as directional, not as fact about any one firm. The consistent signal is that register quality, not policy wording, is what separates prepared firms from paperwork firms.
The skill that gets hired
Register of Information work is unglamorous and in demand: contract inventories, function criticality, subcontracting chains and exit plans.
That is exactly the kind of delivery work that turns a theoretical GRC CV into one with evidence behind it.
What it means for you
If you want a resilience role in financial services, learn to build and defend a third party register. It is the artifact supervisors actually read.
Regulation only pays you if you can show the work.
The GRC Experience Program builds practical project experience, interview-ready stories and the positioning to prove it.
Turn This Into Something You Can Prove.
Short fit call. Clear next step. If neither program is right for you, we'll tell you.
Related posts

NIS2 reaches its October 2026 compliance milestone
Transposition dragged across member states. The obligations on essential and important entities are now landing in national law, with management accountability attached.
Read article
The 2026 tech job market is splitting in two, and upskilling is the bridge
Layoffs and record AI hiring are happening at the same time. The data from the WEF, Indeed, Dice and ManpowerGroup points to one conclusion: the market is not shrinking, it is re-sorting around skills.
Read article
The GRC market is on track to triple, and the scarce skill is judgment, not tooling
Grand View Research puts enterprise GRC at 72.4 billion dollars in 2025 and 203.7 billion by 2033. ISC2 finds 59 percent of practitioners reporting critical or significant skills gaps. The demand is for people who can explain risk, not only collect evidence.
Read article