DORA in H2 2026: From Implementation to Examination
DORA has been in force since January 2025. By Q3-Q4 2026, financial institutions should be past initial implementation and into operational maturity. Competent authorities are shifting from guidance mode to examination mode. This checklist covers what to prioritise in the next 6 months.
Q3 2026 Priorities (July-September)
Resilience Testing Programme
- Annual testing plan: Document your 2026-2027 testing programme covering scenario-based tests, performance tests, and vulnerability assessments
- TLPT readiness: If identified by your competent authority for Threat-Led Penetration Testing, engage a TIBER-EU qualified team. TLPT scope must include critical ICT systems.
- Third-party testing: Your testing programme must include scenarios where critical third-party ICT providers fail. Document the test results and remediation actions.
- DR testing: Execute full disaster recovery test for Tier 1 systems. Document achieved RTO/RPO vs targets.
Third-Party Risk Register
- Register update: Review and update the register of all ICT third-party providers (RTS mandate)
- Concentration risk: Assess concentration risk — how many critical services depend on the same provider?
- Exit strategies: Document exit strategies for each critical third-party. Test at least one exit strategy per year.
- Contractual compliance: Review contracts against DORA Art. 30 requirements — audit rights, data location, sub-contracting, incident notification
Q4 2026 Priorities (October-December)
Regulatory Examination Preparation
- Self-assessment: Conduct internal DORA compliance assessment against all Chapter II-V requirements
- Evidence pack: Prepare documentation ready for supervisory examination — policies, test results, incident reports, risk assessments
- Gap remediation: Close identified gaps before year-end. Prioritise by regulatory risk (high-impact findings first).
- Board reporting: Management body update on ICT risk status and DORA compliance (Art. 5(2) requirement)
Incident Reporting Maturation
- Process drill: Run a tabletop exercise simulating a major ICT incident. Test the full reporting chain — detection, classification, initial notification (4 hours), intermediate report (72 hours), final report (1 month).
- Classification alignment: Verify your incident classification criteria align with the RTS on incident classification
- Near-miss tracking: Start tracking significant cyber threats (not just incidents) — DORA requires voluntary reporting of these
Kubernetes Recipes
A practical guide for container orchestration and deployment by Grzegorz Stencel & Luca Berton (Apress).
Watch on Skillshare →Year-End Deliverables
- Updated ICT risk management framework reflecting 2026 testing results and remediation
- Third-party risk register submitted or ready for submission
- 2027 resilience testing plan approved by management body
- Incident response procedures tested and updated
- Board report on DORA compliance status and 2027 priorities
Related Solution
Navigating AI adoption in a regulated environment? Our readiness assessment maps infrastructure, governance, and compliance gaps in 2-3 weeks.
Explore AI Readiness for Regulated Enterprises →
Luca Berton