The DORA Reality Check for Financial Services Engineering
DORA is here. Most financial-services organizations are underprepared. The pragmatic path forward in 90 days.
May 9, 2026·2 min read·By admin
At a glance
Industry
BFSI
Topics
Compliance · SecOps / GRC
Published
May 2026
DORA (Digital Operational Resilience Act) is now in force across the EU. The early audits have begun. Many financial-services organizations are discovering that what they thought was DORA-compliant isn’t.
The three patterns we see
1. ICT third-party register is incomplete. DORA requires a complete register of ICT third-party providers, classified by criticality. Most banks have a procurement record but not a control-risk-classified register.
2. Operational-resilience testing is theoretical. DORA requires regular testing of operational-resilience scenarios. Tabletop exercises don’t qualify; you need actual recovery validation.
3. Incident reporting timing is misunderstood. DORA timing requirements are aggressive. Most organizations’ incident-reporting workflows weren’t designed for sub-4-hour reporting.
The 90-day plan
Build the register first (most foundational). Run an actual recovery test (will surface real gaps). Tighten incident-reporting workflows (operational change, not technical).