DORA: From Regulation to Reality

When the Digital Operational Resilience Act (“DORA”) became applicable in January 2025, it marked a structural shift in how European financial institutions are expected to manage technology risk. DORA moved digital resilience – the ability of a financial institution to withstand, respond to and recover from technology disruptions –  from a largely technical conversation into the domain of boards, legal teams, and senior management. Eighteen months on, a clear picture is emerging of where the sector stands – and where it is falling short.

Deloitte Luxembourg’s Q1 2026 European survey, published in July 2026, gathered responses from 50 financial entities across 13 countries, predominantly banks and credit institutions (52%), insurers (26%), and asset managers and intermediaries. Most respondents are small to midsized: 67% report annual revenues below one billion euros, and the same proportion serves fewer than one million customers. The profile closely mirrors the Luxembourg financial centre but carries broader relevance for any jurisdiction where midsized institutions, cross-border groups, and specialised service providers define the market.

The headline finding is sobering: only 7% of respondents consider themselves fully compliant with DORA today. A further 44% expect to reach that point by year-end 2026, while nearly half project timelines extending into 2027 or 2028. Full compliance, in this context, means all articles addressed at both documentation and implementation level – a threshold that most institutions are still working toward.

A Two-Speed Landscape

The survey reveals a pronounced maturity gap across DORA’s four pillars. ICT risk management (Pillar I) and incident management and reporting (Pillar II) show the strongest progress, with more than 60% of entities reporting at least 90% completion. These pillars benefited from pre-existing regulatory frameworks and established internal practices.

The picture changes markedly for digital operational resilience testing (Pillar III) and ICT third-party risk management (Pillar IV), where only around one-third of entities have reached comparable maturity. These pillars demand genuinely new capabilities such as structured testing programmes, supply chain mapping, contractual renegotiation with providers, and institutions are finding them considerably harder to put into practice.

For firms operating across jurisdictions, this gap matters. A banking group headquartered in Spain with fund administration in Luxembourg and technology providers serving Latin American operations faces compounded complexity: multiple regulatory expectations, layered provider relationships, and resilience obligations that extend well beyond the home market.

Third-Party Risk: The Central Friction Point

The single most cited challenge – flagged by 32% of respondents – is negotiating revised contractual arrangements with ICT providers to incorporate DORA-mandated clauses. A further 29% point to completing due diligence and risk assessments on providers as their primary difficulty.

These are not abstract concerns. The survey finds that 27% of institutions have been unable to secure agreement on incident notification timelines, with providers declining to commit to to informing their clients of an incident in below 72 hours. Meanwhile, 41% of entities still exclude providers from validation of their incident response plans, and only 13% train providers on their role and include them in crisis resilience simulations.

Supply chain visibility remains the largest unresolved gap such that 83% of entities have mapped only their direct, rank-one providers –  that is, the companies they contract with directly – and only 15% have reached rank two (subproviders within those companies), none has mapped the full chain as required by the DORA reporting template of the register of information. Exit strategies – documented plans for switching to an alternative provider or bringing services in‑house should a provider fail – for non-substitutable providers supporting critical functions exist at 61% of entities, but 39% have yet to document them. On-site inspection of critical providers, a cornerstone of the regulation, is at an early stage for most, with 29% not yet started.

In financial centres where common providers serve multiple institutions, incomplete supply chain visibility is not merely an entity-level gap but a broader systemic consideration.

“A banking group headquartered in Spain with fund administration in Luxembourg and technology providers serving Latin American operations faces compounded complexity: multiple regulatory expectations, layered provider relationships, and resilience obligations that extend well beyond the home market.”
Testing: Breadth Without Depth

Most institutions now run vulnerability scans, annual penetration tests, and backup and failover drills – standard checks that verify whether systems and recovery mechanisms work as intended. However, advanced testing remains limited. Threat-led penetration testing (TLPT), a more sophisticated form of testing in which independent specialists simulate realistic cyberattacks against live systems, mandatory under DORA Article 26 for systemically significant institutions – is still adopted by only a subset of respondents, while just 12% of entities include scenarios involving ICT provider insolvency or political risks in the provider’s jurisdiction when testing business continuity plans — a striking shortfall given current geopolitical conditions.

Governance Foundations and Persistent Gaps

On the positive side, however, 62% of institutions identify their critical and important functions (CIFs) – the business activities whose disruption would have the most serious consequences – through a business-led approach grounded in Business Impact Analysis, assessing customer impact, financial stability, and regulatory obligations. Most keep the number of CIFs manageable, with 49% identifying fewer than ten.

Yet the criteria applied when mapping ICT assets to those functions reveal an imbalance. All respondents consider availability, but only 15% apply the full CIA triad – confidentiality, integrity, and availability. For institutions engaged in asset management, private wealth, or fund administration, where data integrity and confidentiality are as material as service uptime, this gap deserves prompt attention.

Budgets reflect a gradual pace: 68% plan to spend less than two million euros on DORA compliance in 2026, beyond business-as-usual activities. Central teams remain small. This raises a legitimate question about whether current investment levels are sufficient to close the more demanding gaps within the timelines institutions themselves project.

Strategic Priorities for Leadership

For boards, compliance leaders, and risk managers, the survey points to three immediate priorities. First, accelerate work on Pillars III and IV – resilience testing and third‑party risk management – where the maturity deficit is most acute. Second, broaden resilience criteria beyond availability to encompass confidentiality and integrity, particularly where business models depend on data sensitivity. Third, treat provider negotiations, supply chain mapping, and exit planning not as compliance exercises but as strategic risk decisions that require sustained investment and executive sponsorship.

DORA is not a project with an end date. It is an ongoing capability that institutions must build, test, and refine. For cross-border groups navigating multiple jurisdictions, the imperative is clear: operational resilience must be governed with the same rigour applied to capital and liquidity; because in a digitally interconnected financial system, it is no less critical.

Authors

Stephane Hurtaud

Partner in Technology & Transformation → Cyber, Financial Services
Deloitte Luxembourg

Avelino Álvarez Suárez

Partner Audit and Assurance
Deloitte Luxembourg

Hatice Baskaya

Director in Technology & Transformation → Cyber, Financial Services
Deloitte Luxembourg

Related publications

By browsing this website, you agree to our privacy policy.
I Agree