Skip to content
DORA

DORA Enforcement: What Regulators Are Checking in 2026

4 min readUpdated 1 July 2026

DORA became fully applicable on 17 January 2025. One year in, the regulatory focus has shifted from guidance to examination. National competent authorities, the ECB, EBA, and sector supervisors have begun active supervision. This article covers what regulators are prioritising in 2026 and the enforcement actions that have followed.


Enforcement Landscape in 2026

DORA enforcement is primarily conducted by:

European Central Bank (ECB) / Single Supervisory Mechanism (SSM): Directly supervises significant credit institutions in the euro area. First DORA-focused supervisory reviews of significant banks began in H2 2025.

European Banking Authority (EBA): Sets regulatory technical standards and coordinates enforcement across national authorities. Conducts oversight of critical ICT third-party providers directly.

National Competent Authorities: Supervise less significant financial institutions, payment institutions, e-money institutions, and investment firms at national level. Enforcement varies by member state — some NCAs began active enforcement in H1 2025; others are still building capacity.

Sector authorities: ESMA (securities), EIOPA (insurance), and national equivalents apply DORA to their respective sectors.


What Regulators Are Finding

Early examination results from ECB and advanced NCAs have identified consistent patterns of non-compliance:

Register of Information deficiencies. The most common finding. Issues include:

  • Incomplete coverage — not all ICT providers listed
  • Missing LEI codes and standardised provider data
  • Criticality not assessed or assessments undocumented
  • Data residency information missing or inaccurate
  • Sub-contractor information absent

Contract gaps. Article 30 provisions missing from existing contracts with critical providers, particularly:

  • Audit rights absent from legacy contracts
  • Incident notification obligations not specified
  • No exit assistance provisions

Incident reporting failures. The 4-hour initial notification requirement is difficult for many entities. Findings include:

  • No pre-established authority contact or notification channel
  • Classification criteria undefined — slow determination of major incident status
  • No pre-built notification templates — teams assembling documentation during the incident

Testing programme documentation gaps. Pen tests and vulnerability scans have been conducted but:

  • Results are not formally documented in a reportable format
  • Remediation is not tracked against findings
  • Testing has not covered production systems

Management body engagement. The ICT risk framework exists but lacks evidence of board approval. Management-level ICT risk reporting is absent or is one-way IT reporting without board-level oversight.


Enforcement Actions So Far

As of early 2026, significant DORA enforcement actions include:

Register of Information penalties: Multiple NCAs in Germany, Netherlands, and France have issued formal findings and remediation orders for Register of Information deficiencies. Fine levels for Register failures: €100,000–€500,000 range for mid-size financial entities.

Contract compliance orders: Several national authorities have issued orders requiring financial entities to renegotiate critical provider contracts to include Article 30 provisions within a defined remediation period.

Incident reporting enforcement: Two ECB supervisory actions related to delayed major incident notifications — one for a 6-hour delay (exceeding the 4-hour window), one for failure to notify at all. Both resulted in formal supervisory letters and enhanced monitoring.

No significant financial fines yet for small entities. Enforcement in 2026 has focused on remediation orders and supervisory engagement rather than maximum fines. This is expected to change as the compliance window for remediation closes.


What Regulators Will Check in Your Examination

If you receive a DORA examination request, expect to be asked for:

  1. Register of Information in the ESA standard format — expect line-by-line review for completeness
  2. Critical provider contracts — two or three samples will be reviewed for Article 30 provisions
  3. Incident logs — all incidents from the past 24 months, including classification rationale and notification records
  4. Board minutes — evidence that ICT risk was discussed and the risk framework was approved
  5. Testing documentation — results from pen tests, vulnerability scans, and resilience exercises from the past 12–24 months
  6. ICT risk management framework — the documented framework and latest risk assessment

Building a DORA-Ready Position for 2026

Priority 1: Complete and validate the Register of Information. This is the most examined document and the most common source of findings.

Priority 2: Audit critical provider contracts against Article 30. Build a contract amendment programme for non-compliant contracts — target completion within 90 days.

Priority 3: Document and test incident notification. Pre-populate authority contacts and notification templates. Run a tabletop exercise to verify the 4-hour window is achievable.

Priority 4: Gather and organise testing documentation. Ensure pen test and vulnerability scan reports from the past 12 months are filed and accessible, with remediation tracking records.

Priority 5: Evidence board engagement. A single board meeting agenda item on ICT risk is not sufficient — establish quarterly board-level ICT risk reporting.

ComplyOne maps your DORA obligations, tracks your readiness across all five pillars, and maintains your audit evidence.

Run your DORA compliance check →