All articles

Financial Services

DORA moves from questionnaires to enforcement

DORA has applied to EU financial entities since January 2025. In 2026 national competent authorities began acting on the Register of Information data they collected.

SkillHat Editorial Team5 min read
DORA moves from questionnaires to enforcement

What does DORA enforcement look like in 2026?

Supervision has moved past questionnaires. DORA has applied to EU financial entities since January 2025, and in 2026 national competent authorities began acting on the Register of Information data they collected, testing ICT third party oversight, incident reporting timelines and resilience testing evidence. The practical shift is from documented policy to demonstrable operation.

Key facts

DORA (Regulation (EU) 2022/2554) has applied since 17 January 2025.

Register of Information submissions gave supervisors comparable data across firms.

Industry reporting through 2026 describes the first compulsion payments and remediation orders.

Where the regime is

DORA sets requirements for ICT risk management, incident reporting, operational resilience testing and ICT third party risk for a wide set of EU financial entities. It has been applicable since January 2025.

The first eighteen months were dominated by data collection: registers, questionnaires and baseline readiness assessments. Industry coverage through the first half of 2026 describes supervisors shifting to remediation orders and compulsion payments.

Readiness is still uneven

Reported survey figures remain uncomfortable. Coverage of the Span Cyber Security Arena conference cited a claim that 96 percent of EMEA financial services firms say their data resilience does not yet meet DORA expectations.

Treat single survey numbers as directional, not as fact about any one firm. The consistent signal is that register quality, not policy wording, is what separates prepared firms from paperwork firms.

The skill that gets hired

Register of Information work is unglamorous and in demand: contract inventories, function criticality, subcontracting chains and exit plans.

That is exactly the kind of delivery work that turns a theoretical GRC CV into one with evidence behind it.

What it means for you

If you want a resilience role in financial services, learn to build and defend a third party register. It is the artifact supervisors actually read.

Regulation only pays you if you can show the work.

The GRC Experience Program builds practical project experience, interview-ready stories and the positioning to prove it.

Turn This Into Something You Can Prove.

Short fit call. Clear next step. If neither program is right for you, we'll tell you.

Build Experience You Can Explain.

Explore SkillHat’s practical programs for GRC careers and expertise-led businesses.