DORA — Regulation (EU) 2022/2554 on digital operational resilience for the financial sector — has been applicable since 17 January 2025. By 2026, the first full supervisory cycles are underway: banks, insurers and asset management companies are no longer asked whether they have a DORA project, but whether the framework is demonstrably implemented, documented and tested. This article is a practical checklist of what financial entities should have in place by 2026 — governance, training, third-party due diligence, the register of information and the personnel dimension. For the underlying obligations on staff and ICT service providers, see our overview of DORA requirements for personnel and ICT service providers.
The 2026 Baseline: From Project to Operative Compliance
The transition period is over. Supervisors now expect DORA compliance to be part of day-to-day operations, not a remediation programme. Concretely, that means: an approved and annually reviewed ICT risk management framework, a functioning training programme, a complete register of information, and documented due diligence for every material ICT third party. If any of these still lives in a project plan, 2026 is the year to close the gap — because the second supervisory cycle will test exactly these artefacts.
ICT Risk Management Framework: Governance and Control Functions
The backbone of DORA is the ICT risk management framework under Articles 5 and 6. By 2026, financial entities should be able to show:
- Ultimate responsibility at the top. The management body defines, approves and oversees the framework and bears the ultimate responsibility for managing ICT risk (Art. 5(2)). This is not delegable to the CISO alone.
- A control function with independence. Entities other than microenterprises must assign responsibility for managing and overseeing ICT risk to a control function with an appropriate level of independence, following the three lines of defence model or an equivalent internal model (Art. 6(4)).
- Documentation and annual review. The framework must be documented and reviewed at least once a year, and after major changes to network and information system infrastructure (Art. 6(5)).
- A monitoring role for third-party arrangements. A dedicated role — or a designated member of senior management — must monitor all arrangements with ICT third-party service providers (Art. 5(3)).
In practice, the 2026 question is not whether these roles exist on paper, but whether they are staffed with people who demonstrably understand ICT risk — which is where the personnel dimension comes in (see below).
Training Under Art. 13(6): Role-Based and Documented
Article 13(6) requires financial entities to include ICT security awareness programmes and digital operational resilience training in their staff training schemes — for all employees and for members of the management body. By 2026, a defensible training programme should include:
- Role-based depth. Everyone needs baseline awareness; staff responsible for ICT risk, critical systems or incident response need substantially more — and the management body needs regular, specific training to keep its knowledge of ICT risk up to date (Art. 5(4)).
- Evidence, not attendance lists. Supervisors will look for documented learning objectives, completion rates and refresher cycles. A training log that shows who completed what, when, is the artefact that survives an inspection.
- Testing of staff, not just systems. DORA’s digital operational resilience testing also covers people: exercises and scenario tests reveal whether staff actually know how to respond to an incident.
Third-Party Due Diligence and the Register of Information (Art. 28)
Article 28 is the operational heart of ICT third-party risk management. By 2026, financial entities should have a repeatable process, not a one-off exercise:
- Pre-contractual assessment for every material provider. Suitability, risk, concentration risk and conflicts of interest must be assessed before contract signature — and the assessment must be documented. In an audit, the supervisor asks which facts were gathered, assessed and recorded, not whether the provider seemed reputable.
- A complete, current register of information. The register covers all contractual arrangements with ICT third-party service providers and must be kept up to date — including the subcontracting chain, because the RTS on subcontracting require the chain of ICT subcontractors supporting critical or important functions to be identified and kept current.
- Ongoing monitoring. Due diligence ends neither at signature nor at onboarding. Providers must be monitored continuously, and the register and risk assessments must be refreshed when the provider’s situation changes — ownership, sanctions exposure, incidents, financial health.
- Contractual enforcement rights. Audit, access, inspection and termination rights under Art. 30 are what make due diligence findings enforceable later. Contracts signed without them are a common finding in supervisory reviews.
For the methodological link between provider due diligence and personnel screening — one review process, two objects — see our article on DORA requirements for personnel and ICT service providers.
Personnel Requirements: Key Positions and Reliability
DORA itself is not a fit-and-proper regime, but it sharpens the personnel dimension of digital resilience in three ways:
- Knowledge and skills of the management body. Members must actively keep up to date with sufficient knowledge and skills to understand and assess ICT risk (Art. 5(4)) — a requirement that supervisors increasingly check against the actual background of board members.
- Suitability of key function holders. The sectoral frameworks — CRD for banks, Solvency II for insurers, the KAGB for asset managers — require key function holders to be fit and proper. DORA adds the ICT dimension: whoever runs ICT risk management, the third-party monitoring role or incident response must be able to demonstrate the relevant expertise.
- Reliability as a documented fact. Where key personnel handle critical systems, access rights or outsourcing relationships, their reliability should be verified and documented — registry data, sanctions lists, adverse media — just as the provider itself is screened. This is where a structured, documented review process pays off twice: once for the entity’s own key personnel, once for the provider’s staff with far-reaching access.
A Practical 2026 Checklist
- ICT risk management framework approved by the management body and reviewed within the last 12 months
- ICT risk control function established with documented independence (three lines of defence)
- Third-party monitoring role or senior management designee in place and active
- Training programme under Art. 13(6) covers all staff and the management body, with documented completion and refresher cycles
- Register of information complete, current and covering the subcontracting chain
- Documented pre-contractual due diligence exists for every material ICT provider
- Contracts include audit, access, inspection and termination rights (Art. 30)
- Key personnel in ICT risk, third-party monitoring and incident response roles are verified as reliable and suitably qualified
How Indicium Supports DORA Implementation
The compliance burden of 2026 is documentation: who was assessed, when, on which facts, with which sources. Indicium applies the same structured methodology to both review objects — ICT service providers and key personnel — and produces a reviewable report with dated sources and human final review (Art. 22 GDPR). If you want to see how the process works in practice, book a demo.
This article provides general information and does not constitute legal advice.