Over a year and a half down the road, the conversation has shifted. The focus is no longer on understanding the regulation or implementing a compliance programme. Instead, organisations are being asked to demonstrate that they can withstand, respond to and recover from operational disruption.
This time period has provided the industry with a useful opportunity to assess whether the effort invested in DORA has translated into meaningful improvements in resilience, or whether it has largely resulted in additional governance and compliance activity.
What Was DORA Trying to Fix?
DORA was introduced in response to a growing dependency on technology across the financial sector.
Financial institutions now rely on complex technology ecosystems to deliver critical services, often involving multiple suppliers, cloud platforms and outsourced providers. Whilst these arrangements have enabled innovation and efficiency, they have also increased the potential impact of cyber incidents, system failures and third-party disruptions.
Prior to DORA, approaches to operational resilience varied considerably across EU Member States. Organisations were often subject to different regulatory expectations depending on their jurisdiction, making it difficult to achieve a consistent level of resilience across the sector.
DORA sought to address this by creating a single framework for managing ICT risk, strengthening oversight of critical suppliers and improving the resilience of financial services as a whole.
The Build Up: Preparing for DORA During 2023 and 2024
For many organisations, the two years leading up to January 2025 were focused on readiness activities.
Programmes were established, gap assessments were completed, governance frameworks were updated and policies were rewritten. New processes were introduced, supplier inventories were reviewed and reporting arrangements were established.
In many cases, this work was necessary and delivered genuine improvements. However, as is often the case with the introduction of new regulatory requirements, organisations have tended to focus on compliance deliverables rather than operational outcomes.
This was understandable. DORA introduced a significant volume of requirements within a relatively short timeframe, and organisations naturally prioritised demonstrating readiness. The result was that many firms entered 2025 with frameworks and documentation in place, but with relatively limited evidence that these were operationally effective and resilient in the face of a real disruption.
Go Live and the First Friction Points
Once DORA became enforceable, several common challenges began to emerge.
The most visible was the Register of Information requirement. Whilst many organisations believed they had a good understanding of their supplier landscape, creating a complete and accurate inventory proved more difficult than expected. Information was often out of date, incomplete and spread across procurement functions, legal teams, business units and subsidiary organisations, with ownership varying considerably.
The challenge became evident during the European Supervisory Authorities' dry run exercise for DORA Register of Information reporting, which was published in December 2024. The voluntary exercise involved almost 1000 financial entities from across the EU, who submitted Registers of Information detailing their contractual arrangements with ICT third party service providers. The exercise provided an early indication of the quality and completeness of supplier data held across the sector. Only 6.5% of participating organisations successfully passed all data quality checks. Many organisations simply did not have a single, reliable view of their ICT dependencies.
In our experience, the challenge was rarely the production of the register itself. More often, organisations struggled to establish ownership of supplier information and understand how third party services supported critical business services. Activities such as dependency mapping proved valuable in supporting DORA requirements.
There were also wider implementation challenges across Europe. In March 2025, the European Commission opened infringement procedures against thirteen Member States for failing to fully transpose the DORA Directive.
At the same time, industry surveys conducted during 2025 also suggested that many financial institutions continued to face implementation challenges beyond the January compliance deadline, particularly in areas such as third party risk management, resilience testing and the Register of Information.
Taken together, these developments highlighted that implementation was proving far more challenging than many had anticipated.
A Key Milestone: Critical ICT Third-Party Providers
One of the most significant developments occurred on 18 November 2025, when the European Supervisory Authorities (ESAs) published the first list of designated Critical ICT Third-Party Providers (CTPPs).
The list included several of the technology providers that underpin large parts of the financial sector, including AWS, Microsoft Azure, Google Cloud, Bloomberg, IBM and Tata Consultancy Services.
This was a critical moment reflecting an increasingly apparent reality; the resilience of the financial sector is increasingly reliant on a relatively small number of technology providers. Many technology providers were not previously subject to direct financial sector oversight in the same way as regulated financial institutions.
The CTPP designation framework was introduced to address this gap and identify those providers that support critical functions across the financial sector. This enables the ESAs, through DORA, to conduct direct oversight and assess whether these organisations maintain the appropriate operational resilience arrangements with the aim of strengthening resilience across the wider financial services infrastructure, whilst also reducing the risk of a single point of failure through a critical provider.
The Lessons: What Organisations Got Wrong and What They Got Right
One of the clearest lessons from DORA implementation is that resilience is demonstrated through an organisation’s practical ability to respond and recover from an event rather than documentation and governance alone.
Many organisations entered implementation with strong governance frameworks supported through established policies. However, testing exercises frequently exposed disconnects between documented arrangements and operational reality. In our experience, the organisations that performed best were often those that had invested time understanding how critical services actually operated, rather than focusing solely on regulatory requirements. This included mapping services end to end including people, processes, technologies and supporting third parties to help organisations identify previously unseen dependencies, ownership gaps and recovery challenges.
Third-party risk has also evolved from a focus on contract management to practical operational resilience.
Historically, organisations concentrated on due diligence, contractual protections and assurance activities. Whilst these remain important, recent events have reinforced the need to understand what happens when a supplier experiences disruption. Recovery strategies, alternative arrangements and dependency mapping have become increasingly important.
Unsurprisingly, governance has been another area where differences in maturity have become apparent.
DORA places accountability for ICT risk management on the organisation’s senior management. Organisations that have embedded resilience accountability within senior leadership and business decision making appear better positioned than those where DORA remains largely the responsibility of compliance, risk or technology teams.
What organisations did get right was recognising that operational resilience is not a standalone programme. The strongest implementations identified by Bridewell were often those that integrated DORA requirements into existing governance, risk management and operational processes rather than creating entirely new structures.
Where We Are Now
During 2026, supervisory attention has increasingly shifted from implementation towards effectiveness.
Questions that previously focused on plans, policies and readiness are now focused on evidence. Regulators are increasingly seeking assurances that organisations understand and can demonstrate resilience in practice, particularly where critical services, third-party relationships and severe disruption scenarios are concerned.
This reflects the movement into the next phase of DORA’s implementation. Organisations are moving beyond initial compliance and beginning to identify where resilience arrangements operate effectively and where further improvements are required.
What Good Looks Like Going Forward
The organisations that appear most mature share several common characteristics.
They maintain a clear understanding of their critical services, supporting dependencies and recovery priorities. They also maintain visibility of their dependencies and have realistic plans for managing disruption when those dependencies fail.
Even more importantly, they test those arrangements regularly.
Exercises, scenario testing and lessons learned activities provide far greater assurance than policies alone. They help organisations identify weaknesses before they become incidents and enable resilience arrangements to evolve as services and threats change.
This approach is unlikely to remain limited to the EU. Similar themes are already emerging elsewhere, including through the UK's proposed Cyber Security and Resilience Bill. The direction of travel is clear, regulators increasingly expect organisations to demonstrate resilience through outcomes rather than compliance through documentation.
Conclusion
Looking back, DORA has achieved something valuable. DORA has forced organisations to examine how reliant they are on technology and whether they genuinely understand the dependencies that support their services.
Whilst the initial focus was naturally on compliance, the lessons emerging since January 2025 suggest that operational resilience is ultimately about far more than meeting regulatory requirements. It requires visibility of critical services, effective governance, informed decision making and confidence that plans will work when tested.
In Bridewell’s experience, the organisations deriving the greatest value from DORA are not necessarily those with the most mature compliance programmes. They are the ones using the regulation as a catalyst to strengthen resilience across the organisation and improve their ability to respond when disruption occurs.