Compliance

DORA Is Live. What Financial Services Firms Need to Do Now

G
Jonathan Garzon
Founder & CEO, Garzon Cyber Solutions
March 2026 · 3 min read

DORA is no longer a project. It is now a live supervisory regime, and the first enforcement cycle is already exposing the gap between paper compliance and operational reality.

What the regulation actually demands

The Digital Operational Resilience Act harmonises ICT risk, incident reporting, resilience testing, third-party oversight, and information sharing across 21 categories of financial entities. The intent is straightforward: make operational resilience a board-level accountability, not an IT workstream.

Where the gaps are widest

  • Third-party concentration risk. Most firms still cannot produce a complete, current register of critical ICT providers with the contractual clauses DORA requires. The major cloud providers dominate the register, and regulators are actively watching concentration.
  • Threat-led penetration testing. TLPT is not a pen test with a new label. It is adversarial, intelligence-led, and scoped against live production. Firms running annual vulnerability scans and calling it resilience testing are exposed.
  • Incident classification and reporting. The 72-hour early notification and downstream reporting windows are tight. Firms that have not rehearsed the decision tree will miss them under pressure.
  • Board ownership. DORA places explicit accountability on the management body. "Delegated to the CIO" is not a defensible answer.

The commercial read

DORA is not just a cost. It is a forcing function that rationalises a fragmented resilience stack, exposes weak vendors, and gives well-run firms a legitimate differentiator with institutional counterparties and regulators. The firms treating it as a board programme, not a compliance line item, will emerge with cleaner architecture and stronger negotiating leverage over their providers.

The enforcement posture is already shifting from education to expectation. The next twelve months will reward the prepared and expose the rest.

Where does this sit on your own risk register?

A short, practical conversation about where the exposure actually is, and what a proportionate response looks like. No obligation and no product pitch.

Start the Conversation →
#NIS2#Compliance#CyberSecurity#Governance#Regulation#GarzonCyberSolutions