DORA Enforcement: What UK Financial Services CISOs Must Now Prove
DORA enforcement moved from initial compliance review to active supervision in 2026: UK financial services CISOs with EU operations must now produce evidence of operational resilience — not just policy documents declaring it.
Why Is DORA Enforcement Now a Live Concern for UK Financial Services CISOs?
The Digital Operational Resilience Act (EU Regulation 2022/2554) entered into full application on 17 January 2025, applying to financial entities operating within the EU and to ICT third-party service providers serving them. For UK financial services firms — banks, insurers, investment firms, payment institutions — that operate EU-regulated subsidiaries, branches, or serve EU clients through EU entities, DORA compliance is not optional, regardless of Brexit. The regulatory obligation sits on the EU-regulated entity, and the CISO is typically accountable for the technical implementation.
The first year of DORA application (2025) was characterised by national competent authorities (NCAs) assessing initial compliance submissions. In 2026, that phase is over. NCAs across the EU — including the Central Bank of Ireland, the Dutch AFM, the German BaFin, and France’s ACPR — are now in active supervision mode: cross-referencing Register of Information submissions, scrutinising ICT incident reports, and beginning enforcement engagement with entities showing gaps between their documented frameworks and actual resilience capabilities.
The critical shift is from paperwork to proof. Under DORA, CISOs cannot simply present a policy framework and a risk register. NCAs are now asking to see operational evidence: test results, incident timelines, third-party contract amendments, and management body sign-off records. For UK CISOs managing EU-regulated entities, this is the year when the gap between declared compliance and demonstrable resilience becomes a real enforcement exposure.
Executive Action:
- Confirm with your EU-regulated entity’s legal and compliance teams which national competent authority supervises each entity — the enforcement posture varies significantly, and CISOs need to understand the specific NCA appetite before any supervisory engagement.
- Review whether your current DORA governance structure has management body (board-level) sign-off on the ICT risk framework as required by Article 5 — NCAs are specifically checking that ICT risk ownership sits with the management body, not solely with the CISO.
- Confirm that your Register of Information submission (ICT third-party arrangements as of 31 December 2025, submitted by 30 April 2026) is complete, accurate, and consistent with your actual contractual arrangements — NCAs are cross-checking submissions against other regulatory data.
What ICT Resilience Evidence Must UK CISOs Be Able to Produce in 2026?
DORA’s operational resilience requirements are structured across five pillars: ICT risk management, ICT incident reporting, digital operational resilience testing, ICT third-party risk management, and information sharing. In 2026, CISOs need to be able to produce primary evidence in each pillar — not just refer NCAs to a policy document.
On ICT risk management (Articles 5–16), the management body is required to define, approve, and oversee the ICT risk management framework. Article 5 is explicit that this responsibility belongs to the management body — not the CISO acting alone. CISOs must be able to demonstrate that the board has approved the framework, reviews it at least annually, and has been briefed on the entity’s ICT risk exposure. Board minutes and sign-off records are the primary evidence.
On ICT incident reporting (Articles 17–23), major incidents must be reported to the NCA within four hours of classification, with an intermediate report within 24 hours and a final report within one month. CISOs need to demonstrate that their incident classification methodology is documented, tested, and calibrated against DORA’s materiality thresholds — and that the four-hour reporting clock is operationally achievable, not just theoretically possible. NCAs in 2026 are reviewing incident report timelines against the internal logs of when incidents were first detected.
On digital operational resilience testing (Articles 24–27), all financial entities must conduct basic resilience testing annually. Significant financial entities — those designated by NCAs based on systemic importance — are additionally required to conduct Threat-Led Penetration Testing (TLPT) at least every three years. For UK CISOs managing entities that have been or may be designated as significant, TLPT planning needs to begin well in advance of the three-year window.
Executive Action:
- Conduct a DORA evidence audit across all five pillars — map each regulatory requirement to the specific primary evidence that would be produced if an NCA requested it, and identify where evidence exists only on paper rather than in operational reality.
- Test your four-hour incident reporting capability — run a tabletop exercise that measures the actual time from detection to NCA notification, identify the bottlenecks, and fix them before you need them live.
- Check whether any EU-regulated entity you operate has been designated as significant by its NCA — if so, TLPT planning should already be underway, and if not, confirm in writing with the NCA that designation has not occurred.
How Does DORA’s Third-Party Risk Framework Affect UK CISOs’ Vendor Obligations?
Chapter V of DORA (Articles 28–44) sets out the most operationally demanding requirements for many UK CISOs: the ICT third-party risk management framework, which governs contracts with all ICT service providers, with enhanced obligations for Critical ICT Third-Party Service Providers (CTPPs) designated by the European Supervisory Authorities (EBA, ESMA, EIOPA).
The Register of Information — a structured record of all ICT third-party arrangements — was a critical 2026 milestone. The deadline for submitting the Register (covering ICT third-party arrangements as of 31 December 2025) was 30 April 2026. NCAs are now using these submissions as a primary supervisory tool: cross-referencing them against other regulatory filings, checking for completeness, and identifying entities whose reported ICT third-party exposure appears inconsistent with their business model.
For UK CISOs, the contract amendment process is the most time-consuming ongoing obligation. DORA Article 30 specifies mandatory contractual provisions for ICT service agreements — including exit strategies, audit rights, sub-contracting visibility, and performance monitoring. Many contracts with major cloud providers and managed service providers required renegotiation to include these provisions. CISOs who have not yet completed this process, or who have accepted “DORA-compliant” contractual addenda from vendors without verifying they actually meet Article 30, need to complete that work in 2026.
For CISOs who want a structured framework to assess their organisation’s DORA compliance posture, the operational resilience assessment tools at INFORMD provide a board-ready gap analysis covering all five DORA pillars.
Executive Action:
- Verify that your Register of Information submission (30 April 2026 deadline) was complete and has been acknowledged by the relevant NCA — if it was submitted late or has gaps, contact the NCA proactively rather than waiting for a supervisory enquiry.
- Review all ICT service contracts against Article 30 mandatory provisions — do not rely on vendor-supplied “DORA addenda” without independent legal review confirming they satisfy your specific obligations.
- Monitor the EBA, ESMA, and EIOPA register of designated CTPPs — where a critical supplier is designated, enhanced oversight obligations attach immediately, and your contract and monitoring framework must reflect this.
How Should UK CISOs Brief the Board on DORA Exposure?
One of DORA’s most significant governance implications is that Article 5 places ICT risk management accountability explicitly on the management body — which under EU company law typically means the board of directors or equivalent. For UK CISOs managing EU entities, this means the board of that entity must be engaged with ICT risk in a way that goes well beyond receiving a quarterly cybersecurity dashboard.
Article 5(4) specifies that the management body must define and approve the ICT risk management framework, set the risk appetite for ICT risk, approve the ICT business continuity policy, and be adequately trained in ICT risk. This last requirement — management body training — is one that NCAs are beginning to probe. CISOs should be able to demonstrate that board members have received appropriate ICT risk training and that this is recorded.
The CISO’s role in relation to DORA board obligations is to act as the management body’s primary source of ICT risk intelligence — providing the evidence, analysis, and escalation pathways that enable the board to meet its Article 5 duties. This is a significant uplift for many UK financial services boards, where cybersecurity has historically been delegated to a technology subcommittee rather than owned at board level.
Executive Action:
- Map each Article 5 management body obligation to a specific board process — approval of the ICT risk framework, annual review, risk appetite setting, BCP sign-off, and training — and confirm each has a documented evidence trail.
- Deliver a structured DORA briefing to the boards of all EU-regulated entities you support — frame it around their specific Article 5 obligations, the evidence NCAs will look for, and the decisions they need to make.
- Include DORA enforcement exposure in the enterprise risk register for any UK group with EU-regulated entities — quantify the potential penalty exposure and the reputational risk of an NCA enforcement action, and ensure group leadership understands the stakes.
INFORMD provides intelligence briefings, tools and frameworks for senior business leaders across technology, finance, strategy and compliance. Based in Milton Keynes, UK, we help executives stay informed and act with confidence. Explore our full briefing library or access our free assessment tools.
Stay ahead. Subscribe to INFORMD’s weekly executive briefing at informd.co.uk.
DORA applies to EU-regulated financial entities and their ICT third-party providers. UK firms with EU-regulated subsidiaries, branches, or EU-licensed operations must comply via those entities. The obligation sits on the EU entity, not the UK parent — but the UK CISO typically owns the technical implementation across the group.
The Register of Information — a structured record of ICT third-party arrangements as of 31 December 2025 — was due for submission to national competent authorities by 30 April 2026. NCAs are now cross-checking these submissions against other regulatory data. Late or incomplete submissions are a supervisory risk.
Article 5 requires the management body to define and approve the ICT risk management framework, set ICT risk appetite, approve the business continuity policy, and ensure board members receive adequate ICT risk training. These are board-level obligations — they cannot be fully delegated to the CISO.
Under DORA Articles 17–23, major ICT incidents must be reported to the national competent authority within four hours of classification as major (initial notification), with an intermediate report within 24 hours and a final report within one month of closure.
