Back to Newsroom
DORA · NexCyber Editorial

DORA one year on: lessons from the first 12 months of go-live

The Digital Operational Resilience Act (DORA) marked a significant shift in the regulatory landscape for financial entities within the EU. Since its enforcement on 17 January 2025, the first year has highlighted several recurring challenges. Key issues have emerged around the completeness of the Register of Information, the scope agreement for Threat Led Penetration Testing (TLPT), and transparency in sub-outsourcing chains. This article delves into these areas, offering insights and guidance fo

The Digital Operational Resilience Act (DORA) marked a significant shift in the regulatory landscape for financial entities within the EU. Since its enforcement on 17 January 2025, the first year has highlighted several recurring challenges. Key issues have emerged around the completeness of the Register of Information, the scope agreement for Threat Led Penetration Testing (TLPT), and transparency in sub-outsourcing chains. This article delves into these areas, offering insights and guidance for financial institutions navigating the complexities of DORA compliance.

Incomplete Fields in the Register of Information

One of the foundational elements of DORA compliance is the establishment and maintenance of a comprehensive Register of Information. This register is critical for ensuring transparency and accountability in managing ICT risks. However, financial entities have encountered recurring difficulties in ensuring the completeness of this register, particularly in six specific fields.

1. ICT Asset Inventory

The ICT asset inventory is a cornerstone of the Register of Information, yet many entities have struggled to maintain an up-to-date and exhaustive list. This inventory should include all hardware, software, and network components. Incomplete inventories can lead to gaps in risk assessment and management.

2. Third-Party Service Providers

Accurate documentation of third-party service providers is essential for assessing external risk exposure. Entities often fail to capture detailed information on these providers, including their roles, services provided, and risk assessments.

3. Incident Response Plans

While many organizations have incident response plans, these are often not fully documented in the register. Complete and detailed plans are necessary to ensure rapid and effective responses to ICT incidents.

4. Business Continuity Plans

Similar to incident response plans, business continuity plans are frequently incomplete. These plans should outline strategies for maintaining operations during disruptions and are crucial for operational resilience.

5. Risk Assessment Reports

Entities are required to conduct regular risk assessments and document these in the register. However, many reports lack depth or are not updated regularly, undermining their effectiveness.

6. Compliance Documentation

Finally, documentation of compliance with DORA and other relevant regulations is often insufficient. Entities must ensure that all compliance activities are thoroughly documented to demonstrate adherence to regulatory requirements.

Settling TLPT Scope Disputes

Threat Led Penetration Testing (TLPT) is a critical component of DORA, designed to test the resilience of financial entities against cyber threats. However, disputes often arise between white teams (defenders) and red teams (attackers) regarding the scope of these tests.

Defining the Perimeter

A common point of contention is the definition of the testing perimeter. White teams may seek to limit the scope to critical systems, while red teams advocate for broader testing to uncover potential vulnerabilities. Effective communication and negotiation are key to reaching a consensus that satisfies both security and operational considerations.

Risk-Based Approach

Adopting a risk-based approach can help in resolving scope disputes. By prioritizing systems and processes based on their risk profile, entities can ensure that TLPT efforts are focused on areas with the greatest potential impact.

Documentation and Agreement

Clear documentation of the agreed scope, objectives, and methodologies is essential. This not only helps in aligning expectations but also provides a reference point for evaluating the outcomes of the testing.

Transparency in Sub-Outsourcing Chains

The complexity of modern supply chains, particularly in ICT services, has introduced significant challenges in managing sub-outsourcing risks. DORA emphasizes the need for transparency in these chains to mitigate fourth-party concentration risks.

Identifying Fourth-Party Providers

Financial entities must ensure that they have visibility into their sub-outsourcing chains. This involves identifying all fourth-party providers and understanding their roles and potential impacts on operational resilience.

Assessing Concentration Risks

Concentration risks arise when multiple services rely on a single provider or a small group of providers. Entities must assess these risks and develop strategies to diversify their supplier base where necessary.

Contractual Clauses and Monitoring

Incorporating specific contractual clauses related to sub-outsourcing transparency and risk management is crucial. Additionally, continuous monitoring of fourth-party providers can help in identifying emerging risks and ensuring compliance with DORA requirements.

Collaboration and Information Sharing

Effective management of sub-outsourcing risks requires collaboration and information sharing across the supply chain. Entities should engage with their providers to foster a culture of transparency and resilience.

Next Step with NexCyber

Navigating the complexities of DORA compliance requires a strategic approach and robust tools. NexCyber offers a comprehensive DORA register diagnostic service to help financial entities ensure the completeness and accuracy of their Register of Information. Our platform provides insights and guidance on addressing TLPT scope disputes and enhancing transparency in sub-outsourcing chains.

Visit [NexCyber's DORA assessment page](https://www.nexcyber.eu/assess?utm_source=editorial&utm_campaign=dora-january-2026-go-live-lessons) to learn more about how we can support your compliance journey.

Want the regulatory deep-dive ?

Our regulatory engineering team publishes implementation guides + practical checklists for each regulatory update.

Browse Knowledge Base →