DORA Compliance 2026: What UK Financial Services CISOs Must Own Now
- Ensure your incident classification procedure is DORA-aligned — the distinction between major and non-major incidents must be documented, tested, and approved by t
UK financial services CISOs must own DORA compliance: Member States shall lay down the rules on penalties applicable to infringements of this Regulation.
Under DORA (Regulation EU 2022/2554 — the Digital Operational Resilience Act), which entered full application on 17 January 2025, financial entities and their ICT third-party service providers must demonstrate robust digital operational resilience across five pillars: ICT risk management, incident management, resilience testing, third-party risk management, and information sharing. DORA is now in its enforcement maturity phase: European supervisors are conducting their first formal assessments, and gaps in any pillar may result in supervisory measures. For UK financial services firms with EU customers, EU operations, or EU ICT service provider relationships, DORA’s reach extends well beyond the EU’s geographic borders.
Which UK Financial Services Firms Are in DORA’s Scope?
DORA applies to more than 22,000 financial entities and ICT service providers operating within the EU. UK firms fall in scope on three grounds: they are authorised by an EU regulator; they provide ICT services to EU-regulated financial entities; or they are part of a group that includes EU-regulated entities. Many large UK banks, insurers, asset managers, and payment service providers are in scope through their EU subsidiaries, branches, or client relationships.
The scope also extends to Critical ICT Third-Party Providers (CTPPs). UK technology companies and cloud providers that supply services to EU-regulated financial firms can be designated as CTPPs by European Supervisory Authorities (ESAs), triggering direct oversight, oversight fees, and binding recommendations. UK CISOs at technology vendors supplying EU financial services firms must assess their own CTPP designation risk.
The PRA and FCA have not implemented DORA directly into UK law — UK firms are subject to existing UK operational resilience rules under SS1/21, PS6/21, and the FCA’s SYSC sourcebook. However, UK firms operating in the EU must comply with DORA for their EU-regulated entities, and the PRA has indicated it will monitor DORA developments closely. According to PwC’s DORA impact assessment for UK firms, over 60% of large UK financial services groups are in DORA’s direct or indirect scope.
Executive Action
- Conduct a DORA scoping assessment: identify every EU-regulated entity, EU client relationship, and EU ICT service provider connection that brings your organisation into DORA’s scope.
- Map your ICT third-party relationships against the CTPP designation criteria — if any of your critical suppliers could be designated, engage with them on their DORA readiness now.
- Review the INFORMD cybersecurity briefing library for the latest guidance on UK operational resilience alignment with DORA requirements.
What Are the Five DORA Pillars CISOs Must Govern?
DORA’s five pillars represent the minimum compliance architecture that every in-scope firm must maintain. CISOs own the technical implementation of each pillar; the management body — including the board — bears ultimate accountability for ICT risk management and cannot delegate this responsibility entirely to IT.
Pillar 1: ICT Risk Management. Firms must implement a robust ICT Risk Management Framework that identifies, classifies, and manages ICT risks across all systems, processes, and third parties. The framework must be board-approved, regularly tested, and capable of addressing risks from cyber attacks, system failures, and operational disruptions. CISOs must produce an annual ICT risk assessment aligned to the framework.
Pillar 2: ICT Incident Management. DORA establishes stringent incident management requirements: 24/7 monitoring capabilities, classification systems distinguishing major from non-major incidents, and documented response procedures with clear escalation paths. Major ICT incidents must be reported to the relevant competent authority within prescribed timeframes — initially within 4 hours of classification, with a full report within 72 hours.
Pillar 3: Digital Operational Resilience Testing. All in-scope firms must conduct annual vulnerability assessments and scenario-based evaluations. Significant financial entities must also conduct Threat-Led Penetration Testing (TLPT) at least every three years. TLPT is a sophisticated, red-team exercise that tests ICT systems against real-world attack scenarios — it is significantly more demanding than standard penetration testing.
Pillar 4: ICT Third-Party Risk Management. Firms must satisfy themselves of their ICT third parties’ resilience and must include DORA-specific contractual obligations in all ICT service contracts. Existing contracts must be reviewed and amended to include performance SLAs, audit rights, business continuity requirements, and termination provisions that enable orderly transition. According to DORA’s regulatory technical standards, contracts with critical ICT third parties must include exit strategies and data portability provisions.
Pillar 5: Information Sharing. DORA encourages — and in some cases requires — financial entities to participate in cyber threat intelligence sharing arrangements. CISOs should engage with CERT-UK, the Financial Sector Cyber Collaboration Centre (FSCCC), and sector-specific ISACs to maintain situational awareness and demonstrate compliance with DORA’s information sharing obligations.
Executive Action
- Map your current ICT risk management, incident response, and third-party risk programmes against each DORA pillar and produce a gap register with remediation timelines.
- Identify whether your firm is a “significant financial entity” requiring TLPT — if so, begin scoping your first TLPT engagement now, as qualified TLPT providers have long lead times.
- Review all critical ICT vendor contracts for DORA compliance — prioritise contracts with cloud providers, core banking platforms, and payment processors.
How Should the CISO Structure the DORA Compliance Programme?
DORA compliance is not a project with a completion date — it is a permanent operational framework that must be maintained, tested, and reported on continuously. CISOs who treated DORA as a 2025 implementation exercise must now shift to an ongoing compliance operating model.
A mature DORA compliance programme has four structural elements: governance (a DORA Steering Committee co-chaired by the CISO and CRO, with quarterly board reporting); operations (dedicated ICT risk management, incident management, and third-party risk teams with clear DORA accountability); testing (an annual resilience testing calendar covering vulnerability assessments, scenario exercises, and TLPT scheduling); and supplier management (a DORA contract review programme covering all critical and important ICT third parties).
Many institutions are creating a dedicated DORA Coordinator or Digital Operational Resilience Officer role — a single point of contact for regulators and internal coordination. In smaller organisations, this function can be combined with existing CISO or CRO responsibilities, but the accountability must be documented and assigned explicitly. The management body must demonstrate active engagement with DORA — passive approval of a CISO’s compliance report is not sufficient. Use the INFORMD project review checklist to structure your DORA programme governance framework and present your resilience posture to the board.
Executive Action
- Establish a DORA Steering Committee with CRO and CISO co-chairs, quarterly board reporting, and a documented terms of reference approved by the management body.
- Produce a DORA compliance roadmap with milestones for each pillar — share this with your EU-regulator and include it in your ICT risk management board pack.
- Designate a DORA Coordinator with explicit accountability for regulatory liaison, internal coordination, and compliance programme management.
What Are the DORA Penalties and Supervisory Expectations in 2026?
DORA’s enforcement regime is among the most stringent in EU financial regulation. For serious breaches, financial institutions face fines up to 10% of annual worldwide turnover or €10 million, whichever is higher. Individual senior managers — including CISOs — face personal fines up to €1 million. For Critical ICT Third-Party Providers, fines can reach 1% of average daily worldwide turnover, applied for up to six consecutive months until compliance is achieved.
The 2026 enforcement environment reflects DORA’s transition from implementation to supervision. European Supervisory Authorities are conducting their first formal DORA assessments in 2026, with a particular focus on ICT risk management frameworks and third-party risk management. Firms without documented, board-approved ICT risk management frameworks are the highest-priority supervisory targets.
Reputational exposure adds to the financial risk. ICT-related incidents at regulated financial firms must be reported to regulators within tight timeframes — and material incidents will attract media and investor scrutiny. CISOs must ensure their incident classification procedures are robust: under-classifying a major incident to avoid regulatory reporting is a serious compliance risk in itself. Access the INFORMD contact page to discuss DORA programme support for your organisation.
Executive Action
- Ensure your incident classification procedure is DORA-aligned — the distinction between major and non-major incidents must be documented, tested, and approved by t
