DORA
You're Not a Bank. DORA Still Applies. And the First Inspections Have Started.
DORA has been fully applicable since 17 January 2025. Most non-banks read that as someone else's problem. In 2026, that misread becomes a supervisory problem.

For sixteen months, “DORA is for banks” has been the comfortable story most fintechs, payment institutions, and IT vendors told themselves. It was never accurate, and in 2026 it has stopped being safe. The Digital Operational Resilience Act has been fully applicable since 17 January 2025, no transitional period, no grandfathering — and the regulators who waited through 2025 to give firms time to settle are now opening the inspection cycle they always said they would.
If you process payments, custody crypto-assets, manage portfolios, run a crowdfunding platform, or sell critical IT services into any of the above, DORA already applies to you. The first round of supervisory action in France will not be aimed at the largest banks. It will be aimed at the firms that thought they were too small, too downstream, or too non-financial to be touched.
DORA in 60 seconds
DORA is the EU’s regulation on digital operational resilience for the financial sector. It harmonises ICT risk management, incident reporting, resilience testing, and third-party risk requirements across more than 22,000 financial entities operating in the Union. It became binding directly in every Member State on 17 January 2025 — the same day NIS2 was supposed to be transposed nationally, which is why the two regimes are easy to confuse.
DORA is not a directive. There is no national transposition window to hide behind. The Regulation, the five Regulatory Technical Standards adopted in 2024 and the second batch published on 20 February 2025 are all live. As of 2026, supervisors are no longer asking firms to prepare. They are asking firms to prove.
Who is actually in scope
The scope is broader than most market participants assume. DORA reaches beyond credit institutions to cover payment institutions, e-money institutions, investment firms, asset managers including AIFMs and UCITS managers, trading venues, central counterparties, central securities depositories, MiCA-authorised crypto-asset service providers, crowdfunding service providers, credit rating agencies, and several other categories listed in Article 2.
In practice, this means a French payment fintech, a Luxembourg crypto custodian, a Belgian crowdfunding platform, and a Swiss-headquartered asset manager with EU-licensed entities all share the same regulation as BNP Paribas. The proportionality principle in Article 4 calibrates how obligations are met — not whether they apply.
DORA’s scope reaches beyond banks: in-scope financial entities, indirect ICT suppliers, and the new CTPP tier.
The “I’m too small” trap
Microenterprise status is a calibration, not an exemption. The ACPR-AMF Fintech Forum noted in October 2025 that 60% of French payment service providers — 36 firms out of 60 — qualify as microenterprises under DORA’s definition: fewer than ten staff and revenue or assets under €2M. They still fall under the Regulation. They benefit from a lighter ICT risk-management framework under Article 16, but they remain subject to incident reporting, third-party risk obligations, and the Register of Information.
If your fintech has half a dozen people, a Series A round, and a partner bank doing the heavy compliance lifting on paper — your DORA file is yours, not your partner’s. Our DORA readiness services consistently see this assumption fail in scoping interviews.
When DORA reaches the IT supplier next door
The second trap is structural. Even if you are not a financial entity, DORA reaches you contractually if you sell ICT services to one. Articles 28 to 30 require financial entities to embed specific clauses into every ICT contract — service-level definitions, audit rights, sub-contracting controls, exit strategies, security obligations — and to maintain a Register of Information listing every contractual arrangement. That cascade lands directly on the supplier’s renewal cycle.
If your IT, cloud, SaaS, payments-platform, or KYC-vendor business has financial-entity customers in the EU, you have already received, or are about to receive, a re-papering request. Refusing to comply is not a viable position: the financial entity has no choice.
A smaller group of providers crossed a different threshold. On 18 November 2025, the European Supervisory Authorities published the first list of 19 Critical ICT Third-Party Providers (CTPPs) — including the major hyperscale cloud, infrastructure, and financial-technology vendors. CTPPs are now under direct EU oversight by the ESAs, must designate an EU-resident coordinating entity, pay annual oversight fees, and face periodic penalty payments of up to 1% of average daily worldwide turnover per day of non-compliance under Article 35(6).
What 2026 actually looks like
The ACPR has confirmed it is supervising DORA across the same population it already prudentially supervises — credit institutions, payment institutions, e-money institutions, insurers, reinsurers. The AMF supervises investment firms, asset managers, and market infrastructures. Both authorities have stated their first thematic DORA inspections will run through 2025–2026 on a risk-based basis, with formal sanctions expected from 2026 onward.
The first hard wall came earlier this year: financial entities had to submit their Register of Information to their national competent authority — the ACPR or AMF in France — by mid-March 2026, with national authorities consolidating registers to the ESAs by 31 March 2026. Firms that filed thin or inaccurate registers have already exposed their third-party portfolio to the ESAs. That is now what supervisors prioritise inspections from.
In France, the penalty framework for legal entities runs to €10M or 5% of annual revenue, with €5M personal fines for the responsible individuals — directors and senior managers personally, not the legal entity. This is closely related to a point we made in our reference piece, NIS2 Enforcement Has Started. 8 Questions Your Board Must Answer in the First 30 Days.: the EU’s new generation of cyber regulations is built around personal accountability, not corporate excuses.
The five obligation clusters
DORA’s substance breaks into five operational clusters: an ICT risk-management framework owned at board level (Articles 5–16); an incident classification and reporting pipeline with 4-hour, 72-hour, and 1-month deadlines for major incidents (Articles 17–23); digital operational resilience testing including, for significant entities, threat-led penetration testing aligned to TIBER-EU before 17 January 2028 (Articles 24–27); ICT third-party risk management with the contract clauses, the Register of Information, and the CTPP regime (Articles 28–44); and information-sharing arrangements (Article 45). A board-led Virtual CISO engagement is the most efficient way to instrument these five clusters at SMB scale.
The next 90 days
A 30/60/90-day plan for non-banks reading DORA for the first time.
Three calendar quarters into the 2026 supervisory cycle, the firms that started DORA work in 2024 are not the ones we are worried about. The firms that thought DORA was a banking topic, a problem for the legal team, or a vendor’s responsibility are the ones now scrambling. If you are reading this and the previous sentence describes you, the next 30 days matter more than the previous 16 months.
Take the next step
Talk to a security practitioner, not a salesperson.
Twenty-five minutes, no slide deck, no follow-up sequence. We'll talk through where you are, what's coming up next on your regulatory horizon, and whether we can help.


