Skip to main content
← All posts·
Regulatory Compliance

DORA Compliance: Q3-Q4 2026 Planning Checklist for Financial Institutions

DORA compliance planning checklist for Q3-Q4 2026. Quarterly priorities for financial institutions: resilience testing programme, third-party register updates, incident reporting maturation, RTS compliance gaps, and regulatory examination preparation.

Luca Berton10 min read

DORA in H2 2026: From Implementation to Examination

DORA has been in force since January 2025. By Q3-Q4 2026, financial institutions should be past initial implementation and into operational maturity. Competent authorities are shifting from guidance mode to examination mode. This checklist covers what to prioritise in the next 6 months.

Q3 2026 Priorities (July-September)

Resilience Testing Programme

  • Annual testing plan: Document your 2026-2027 testing programme covering scenario-based tests, performance tests, and vulnerability assessments
  • TLPT readiness: If identified by your competent authority for Threat-Led Penetration Testing, engage a TIBER-EU qualified team. TLPT scope must include critical ICT systems.
  • Third-party testing: Your testing programme must include scenarios where critical third-party ICT providers fail. Document the test results and remediation actions.
  • DR testing: Execute full disaster recovery test for Tier 1 systems. Document achieved RTO/RPO vs targets.

Third-Party Risk Register

  • Register update: Review and update the register of all ICT third-party providers (RTS mandate)
  • Concentration risk: Assess concentration risk — how many critical services depend on the same provider?
  • Exit strategies: Document exit strategies for each critical third-party. Test at least one exit strategy per year.
  • Contractual compliance: Review contracts against DORA Art. 30 requirements — audit rights, data location, sub-contracting, incident notification

Q4 2026 Priorities (October-December)

Regulatory Examination Preparation

  • Self-assessment: Conduct internal DORA compliance assessment against all Chapter II-V requirements
  • Evidence pack: Prepare documentation ready for supervisory examination — policies, test results, incident reports, risk assessments
  • Gap remediation: Close identified gaps before year-end. Prioritise by regulatory risk (high-impact findings first).
  • Board reporting: Management body update on ICT risk status and DORA compliance (Art. 5(2) requirement)

Incident Reporting Maturation

  • Process drill: Run a tabletop exercise simulating a major ICT incident. Test the full reporting chain — detection, classification, initial notification (4 hours), intermediate report (72 hours), final report (1 month).
  • Classification alignment: Verify your incident classification criteria align with the RTS on incident classification
  • Near-miss tracking: Start tracking significant cyber threats (not just incidents) — DORA requires voluntary reporting of these
📘 Book

Kubernetes Recipes

A practical guide for container orchestration and deployment by Grzegorz Stencel & Luca Berton (Apress).

Watch on Skillshare →

Year-End Deliverables

  1. Updated ICT risk management framework reflecting 2026 testing results and remediation
  2. Third-party risk register submitted or ready for submission
  3. 2027 resilience testing plan approved by management body
  4. Incident response procedures tested and updated
  5. Board report on DORA compliance status and 2027 priorities
DORA
compliance planning
2026
financial institutions
resilience testing
quarterly planning

Related Solution

Navigating AI adoption in a regulated environment? Our readiness assessment maps infrastructure, governance, and compliance gaps in 2-3 weeks.

Explore AI Readiness for Regulated Enterprises →

Need help applying this in your organization?

Get a free 30-minute assessment with actionable recommendations — whether we work together or not.

Book Your Free AI Platform Assessment

18+ years experience · Ex-Red Hat & Dell · Speaker at KubeCon EU 2026

Luca Berton

Written by

Luca Berton

CEO at Open Empower. 18+ years building enterprise infrastructure at JPMorgan Chase, Red Hat & Dell. Author of 9 technical books. Speaker at Red Hat Summit and KubeCon EU 2026. Instructor on Coursera, Pluralsight & Udemy.

Get more insights like this

Practical AI infrastructure and platform engineering guides — delivered to your inbox.

Subscribe to Newsletter →