Internet Security Auditors Blog

DORA: From Regulatory Obligation to Real Digital Resilience

Written by Alberto Villar Arévalo | Sep 16, 2026, 12:06:45 PM
DORA applies from 17 January 2025. Its objective is to ensure that financial entities can withstand technological disruptions, respond to them, and recover their services. To demonstrate this, documentation must correspond to implemented controls and verifiable results. The question management should ask is: what services could the organization continue to provide if a critical technological dependency failed tomorrow? [1–2].

The Regulation (EU) 2022/2554 covers, among others, credit institutions, payment institutions, insurance companies, and investment firms within its scope. Compliance requires consideration of exclusions, the proportionality principle, and specific cases where a simplified framework applies. The size of an entity alone does not allow it to freely choose a less demanding regime. [1, Arts. 2, 4 and 16].

Resilience starts with the financial service

A disruption may result from a cyberattack, a system failure, or a poorly executed change. Its impact depends on the operations it prevents, such as processing payments, handling claims, or executing orders. The assessment should link these functions to their processes, data, systems, and providers, and establish priorities and recovery objectives consistent with the impact on business operations. [1, Arts. 8, 11 and 12].

Consider a recovery test for a payment service. Restoring the application is one step; validation must also verify access rights, connectivity, balance consistency, and the handling of pending transactions. If a dependency is missing or duplicate transactions appear, the recovery of the service cannot yet be considered demonstrated.

Management must govern technology risk

DORA assigns ultimate responsibility for technology risk to the management body. This involves approving and overseeing the strategy, allocating resources, and reviewing continuity plans, audits, and third-party dependencies. Evidence should demonstrate decisions regarding risks and deficiencies, including assigned owners and follow-up on remediation actions. [1, Art. 5].

As a cybersecurity auditor, I recommend assessing compliance through a complete critical or important function. Following its path from risk assessment to a recovery test makes it possible to verify whether responsibilities, technical controls, and procedures operate in a coordinated manner.

From obligations to evidence

Author's interpretation based on DORA, Arts. 5–14, 17–19, 24–30 and 45. The evidence examples are illustrative and do not represent an exhaustive list of requirements.

Responding and testing with clear criteria

Incident management must enable the detection, recording, classification, and response to incidents, with clearly defined responsibilities and communication channels. Major incidents must be reported to the competent authority according to the applicable criteria, timelines, and reporting templates. To test this capability, organizations should rehearse decision-making under incomplete information and retain a timeline showing what was known, what was decided, and what was communicated. [1, Arts. 17–20; 2].

Entities that are not microenterprises must perform appropriate testing, at least annually, on all systems and applications supporting critical or important functions. Advanced threat-led penetration testing is required only for entities selected under Article 26; it is not a universal obligation. Test results must lead to corrective actions whose effectiveness is subsequently validated. [1, Arts. 24–26].

Managing providers throughout the relationship

The entity retains responsibility even when technology services are outsourced. The register of information must include all arrangements relating to ICT services and distinguish those supporting critical or important functions. Effective management requires assessing providers and concentration risks, reviewing contracts, and, for services supporting critical or important functions, preparing and adequately testing exit strategies. A termination clause should be executable without jeopardizing service continuity. [1, Arts. 28–30].

Measuring the capabilities that matter to the business

I recommend that management use indicators linked to service performance and outstanding deficiencies. Objectives should be based on the business impact analysis and the entity's risk profile; DORA does not prescribe a single recovery time objective for all functions. The table below provides examples to guide that review. [1, Arts. 6, 11–13].

Aspect to be Assessed Proposed Indicator or Evidence
Service recovery Actual recovery time and data loss compared with approved objectives.
Testing coverage
Critical or important functions tested together with their dependencies.
Incident response
Detection, classification, decision-making, and notification times.
Remediation and substitution capability
Overdue deficiencies, validated closures, and exit test results.

The cost of keeping deficiencies open

Non-compliance may lead to corrective measures, financial penalties, and the publication of infringements, according to the applicable enforcement regime. Articles 50 and 51 leave the specific details to national frameworks and competent authorities; they do not establish a general percentage-based fine applicable to all financial entities. In addition to regulatory exposure, organizations may incur service interruption costs, recovery expenses, potential claims, and reputational damage. [1].

How to move forward with demonstrable results

The starting point should be a gap analysis comparing applicable requirements against actual evidence. Based on the results, organizations should prioritize the most exposed functions, address dependencies that lack viable alternatives, and conduct exercises involving both business units and relevant providers. Each deficiency should have an assigned owner, a target date, and a verifiable closure criterion.

At Internet Security Auditors, we can support your organization with DORA assessments, risk analysis, contract and procedure reviews, technical testing, and the monitoring of corrective actions.



If you need to assess your current capabilities, I recommend starting with a critical or important function and demonstrating its full recovery. This exercise helps identify where investment should be focused and what decisions management needs to make.

References
[1] Regulation (EU) 2022/2554 on digital operational resilience for the financial sector. Articles cited throughout the text and Article 64 regarding its application.
[2] European Insurance and Occupational Pensions Authority (EIOPA). Information on DORA and its related implementing standards.

Sources consulted on 10 September 2026. Infographic and examples created by the author.