Compliance

DORA Compliance Checklist for CTOs & CIOs (2026)

DORA Compliance Checklist for CTOs & CIOs

If your organization touches EU financial services — as a bank, insurer, payment provider, crypto-asset firm, or as an ICT vendor selling to any of them — a DORA compliance checklist is no longer optional homework. The Digital Operational Resilience Act (DORA) has been fully in force since January 17, 2025, and 2026 is the year national regulators stop reviewing paperwork and start demanding proof: real-time evidence of resilience, tested incident response, and a fully mapped ICT supply chain. This guide breaks DORA’s five pillars into a checklist your IT and security teams can actually execute, and shows where a structured compliance audit can shortcut the gap analysis.

In short: DORA compliance means proving — with documentation, tested controls, and a maintained Register of Information — that your organization can identify, withstand, respond to, and recover from ICT-related disruptions. It rests on five pillars: ICT risk management, incident reporting, resilience testing, third-party risk management, and information sharing. Non-compliance can cost up to 2% of global annual turnover or €10 million, whichever is higher.

What Is DORA, and Who Needs to Comply?

What it is: The Digital Operational Resilience Act (Regulation (EU) 2022/2554) is an EU regulation that standardizes how financial entities and their critical technology vendors manage, report, and recover from ICT risk. Unlike earlier frameworks that treated cybersecurity as a checkbox, DORA is built around demonstrable operational resilience — your ability to keep critical functions running through a cyberattack, outage, or vendor failure, not just your ability to write a policy about one.

Who it applies to: Per the European Banking Authority, DORA’s enforcement perimeter now covers more than 22,000 financial entities — banks, insurers, investment firms, payment institutions, crypto-asset service providers, and trading venues — plus an estimated 15,000 ICT third-party providers that serve them, including cloud platforms, SaaS vendors, and data center operators. If your product touches an EU-regulated financial entity’s critical or important function, DORA reaches you contractually even if you’re not a financial institution yourself. Fintech platforms in particular should check our breakdown of DevOps and cloud infrastructure for fintech for how this plays out operationally.

When it’s enforced: DORA became directly applicable across all EU member states on January 17, 2025. 2025 functioned as a de facto transition year, with regulators focused on readiness assessments. In 2026, national competent authorities (NCAs) have moved to active enforcement — formal audits, information requests, and financial penalties are now standard practice.

The DORA Compliance Checklist: 5 Pillars You Must Cover

Every credible DORA compliance checklist is organized around the regulation’s five pillars. Treat each one as a workstream with its own owner, evidence trail, and testing cadence — not a document to file away after the initial audit.

The DORA Compliance Checklist: 5 Pillars You Must Cover

Pillar 1: ICT Risk Management Checklist

This is DORA’s foundation — a governance framework that your board formally owns, not just IT. Auditors will look for evidence, not intent.

  • ICT risk management framework documented, board-approved, and reviewed at least annually
  • Complete inventory and classification of ICT assets, systems, and data flows supporting critical or important functions
  • Defined risk tolerance thresholds tied to business-impact analysis
  • Identity, access, and network security controls mapped to identified risks
  • Business continuity and disaster recovery plans tested, not just written
  • Clear internal accountability — a named function (often the CISO or a dedicated resilience lead) reporting risk posture to the board

Most of this pillar overlaps with existing frameworks — if you’ve already built a risk management system for ISO 27001, you’re covering roughly 60–70% of DORA’s ICT risk requirements already.

Pillar 2: ICT Incident Reporting Checklist

DORA replaces vague “notify without undue delay” language with hard deadlines. Your incident response runbook needs these timers built in, not calculated manually under pressure.

  • Incident classification criteria in place (severity, client impact, reputational impact, geographic spread, duration)
  • Initial notification to the relevant national competent authority within 4 hours of classifying an incident as major
  • Intermediate report submitted within 72 hours with updated status and impact assessment
  • Final report submitted within one month, including root cause and remediation
  • Designated Critical ICT Third-Party Providers report major incidents to their Lead Overseer within 2 hours
  • Incident logging and evidence retention process that survives an auditor’s request for the last 12 months of history

Pillar 3: Digital Operational Resilience Testing Checklist

DORA does not accept a policy document as proof of resilience — it requires proof you’ve broken your own systems on purpose and recovered.

  • Annual basic testing program covering vulnerability assessments, scenario-based tests, and network security assessments
  • Threat-Led Penetration Testing (TLPT) every three years for entities identified as significant, simulating real adversary tactics against production-like environments
  • Testing results tracked to remediation with owners and deadlines, not just filed as a report
  • Independent testers used where required, with results reported to management and regulators as applicable

Pillar 4: ICT Third-Party Risk Management Checklist

This is the pillar catching the most organizations off guard in 2026, largely because of one deliverable: the Register of Information (RoI).

  • Register of Information covering every ICT third-party contract supporting critical or important functions, in the ITS 2024/2956 format
  • RoI submitted to your national competent authority ahead of the 2026 deadline (most EU states set 31 March 2026; the Netherlands set 22 March 2026)
  • Pre-contractual due diligence process for new ICT vendors, including sub-outsourcing chain visibility
  • Contracts updated with DORA-mandated clauses: audit rights, exit strategies, service levels, and incident cooperation
  • Concentration risk assessed — how many critical functions depend on a single cloud or SaaS provider
  • Monitoring in place for providers designated as Critical ICT Third-Party Providers (CTPPs) by the European Supervisory Authorities

If your third-party register includes payment processors, the due-diligence bar is even higher — cross-check it against the controls covered in our PCI DSS audit guide and, for entities also subject to U.S. financial rules, our SOX compliance overview.

Pillar 5: Information and Intelligence Sharing Checklist

The lightest-touch pillar — encouraged, not mandated — but still worth formalizing so it doesn’t fall through the cracks during an audit.

  • Participation (or a documented decision not to participate) in a threat-intelligence sharing arrangement with peers or sector groups
  • Internal process to act on shared indicators of compromise and TTPs, not just receive them
  • Legal and data-protection review of any information-sharing arrangement before joining

Reality check: Most organizations we assess have partial coverage on Pillars 1–3 from prior ISO 27001 or SOC 2 work, but a near-blank Register of Information for Pillar 4. Third-party risk management is where a targeted cloud infrastructure and vendor review pays off fastest.

Full DORA Compliance Checklist by Pillar

Use this table as a working audit tracker — assign an owner and a status to each row before your next internal review.

PillarCore RequirementTypical OwnerEvidence Needed
ICT Risk ManagementBoard-approved risk framework, asset inventory, tested BC/DR plansCISO / IT GovernanceFramework doc, risk register, DR test logs
Incident Reporting4-hour / 72-hour / 1-month reporting cadence to NCASOC / Incident Response LeadIncident log, timestamped reports, escalation records
Resilience TestingAnnual testing plus TLPT every 3 years for significant entitiesSecurity / DevSecOpsTest reports, remediation tickets, retest evidence
Third-Party RiskRegister of Information, due diligence, DORA-compliant contractsProcurement / IT AuditRoI submission, contract addenda, vendor risk scores
Information SharingThreat-intel participation and internal action processCISO / LegalMembership records, IOC-response workflow
Full DORA Compliance Checklist by Pillar

DORA Compliance Timeline: Key 2026 Deadlines

DORA compliance in 2026 is not a one-time deadline — it’s a recurring supervisory cycle. These are the dates IT and security leaders should have on their calendar right now.

  • Ongoing: Full DORA applicability since January 17, 2025 — every requirement below is already enforceable.
  • Q1 2026 (31 March for most member states; 22 March for the Netherlands): Annual Register of Information submission to your national competent authority.
  • Throughout 2026: National regulators cross-reference registers across entities, flagging providers that appear inconsistently or “sub-outsourcing chains that don’t exist” for major cloud vendors — expect follow-up requests if your data doesn’t match your vendors’ filings.
  • Rolling: Designated Critical ICT Third-Party Providers — 19 named by the ESAs in November 2025, including major hyperscalers — now operate under direct ESA oversight. Confirm whether any of your critical vendors are on that list and adjust monitoring accordingly.

What Happens If You’re Not DORA Compliant?

Regulators have made clear that 2026 is the enforcement year, and the penalty structure reflects it:

  • Financial entities: Per the official DORA regulation text, fines up to 2% of total annual global turnover or €10 million, whichever is higher, plus individual penalties up to €1 million for accountable executives.
  • Critical ICT Third-Party Providers: Daily penalty payments of up to 1% of average daily global turnover for continued non-compliance, for up to six months, plus corrective measures dictated by the Lead Overseer.
  • Member-state variation: Some countries go further — Italy allows ceilings up to €20 million or 10% of turnover, and Article 52 permits criminal penalties, including imprisonment, for the most severe violations.

Beyond fines, the operational cost is often higher: emergency remediation under regulatory scrutiny, contract renegotiation with vendors, and lost enterprise deals once prospective financial-sector clients ask for your DORA evidence during procurement.

Common DORA Compliance Mistakes IT Teams Make

Across compliance audits, the same gaps recur regardless of company size:

  • Treating DORA as a paperwork exercise. A written policy with no test logs, no incident drill records, and no remediation tracking won’t survive an NCA review.
  • Underestimating the Register of Information. Mapping every ICT contract, sub-outsourcer, and data flow into the ITS 2024/2956 format takes longer than teams expect — start well before the March deadline, not the week of.
  • Missing concentration risk. Multiple critical functions quietly depending on one cloud region or one SaaS vendor is a red flag regulators specifically look for.

These same failure patterns show up across regulatory checklists generally — our FISMA audit checklist walks through a comparable evidence-first approach if you’re benchmarking your audit process against other frameworks.

Turn This Checklist Into an Audit-Ready Program

Gart Solutions runs compliance audits that map your current ICT risk management, incident response, and third-party contracts directly against DORA, ISO 27001, SOC 2, and NIST requirements — then translate the gaps into a DevOps-executable remediation plan. We work across AWS, Azure, and GCP, so the controls we recommend get built into your CI/CD and cloud infrastructure, not bolted on as a separate process. For teams that need ongoing resilience testing and incident readiness without hiring a full internal security function, our SRE and disaster recovery services and fractional CTO engagements plug directly into your existing team.

Get a free DORA readiness consultation
Fedir Kompaniiets

Fedir Kompaniiets

Co-founder & CEO, Gart Solutions · Cloud Architect & DevOps Consultant

Fedir is a technology enthusiast with over a decade of diverse industry experience. He co-founded Gart Solutions to address complex tech challenges related to Digital Transformation, helping businesses focus on what matters most — scaling. Fedir is committed to driving sustainable IT transformation, helping SMBs innovate, plan future growth, and navigate the “tech madness” through expert DevOps and Cloud managed services. Connect on LinkedIn.

FAQ

What is DORA compliance?

DORA compliance means meeting the requirements of the EU Digital Operational Resilience Act (Regulation (EU) 2022/2554), which requires financial entities and their critical ICT vendors to manage ICT risk, report major incidents on strict timelines, test resilience regularly, manage third-party risk through a Register of Information, and participate in threat-intelligence sharing where appropriate.

Who needs to comply with DORA?

DORA applies to more than 22,000 EU financial entities — banks, insurers, payment and e-money institutions, investment firms, crypto-asset service providers, and trading venues — plus roughly 15,000 ICT third-party providers, including cloud, SaaS, and data center vendors that support those entities' critical functions.

When is the DORA Register of Information deadline in 2026?

Most EU competent authorities set the entity submission deadline for the 2026 cycle at 31 March 2026, with the Netherlands requiring submission by 22 March 2026. National authorities then consolidate and forward registers to the European Supervisory Authorities.

What happens if a company is not DORA compliant?

Non-compliant financial entities face fines up to 2% of global annual turnover or €10 million (whichever is higher), with individual penalties up to €1 million for responsible executives. Designated Critical ICT Third-Party Providers face daily penalties of up to 1% of average daily global turnover, and some member states permit criminal penalties for severe violations.

How do you conduct a DORA gap analysis?

Start by mapping current controls against each of DORA's five pillars — ICT risk management, incident reporting, resilience testing, third-party risk, and information sharing — then identify where documentation exists but testing evidence doesn't. A structured compliance audit typically surfaces gaps in the Register of Information and incident-reporting timelines first, since these are the most process-heavy requirements.

Why is third-party risk management important under DORA?

Financial entities increasingly depend on a small number of cloud and SaaS providers, creating concentration risk that regulators consider a systemic threat. DORA's Register of Information and Critical ICT Third-Party Provider oversight regime exist specifically to give regulators visibility into these dependencies before a single vendor outage cascades across the financial system.

How is DORA different from ISO 27001 or NIS2?

ISO 27001 is a voluntary, certifiable information security management standard, and NIS2 covers a broader set of essential and important entities across the EU with less prescriptive ICT-specific testing requirements. DORA is financial-sector-specific, legally binding without certification, and uniquely detailed on incident-reporting timelines, third-party oversight, and mandatory resilience testing — organizations already aligned with ISO 27001 or NIS2 usually have a head start but still need DORA-specific controls.
arrow arrow

Thank you
for contacting us!

Please, check your email

arrow arrow

Thank you

You've been subscribed

We use cookies to enhance your browsing experience. By clicking "Accept," you consent to the use of cookies. To learn more, read our Privacy Policy