Skip to content

DORA Enforcement: Known Compliance Gaps Are Now Triggering Penalties

July 22, 20262 minute read

Nearly half of regulated financial entities entered DORA’s active enforcement phase with known compliance gaps. The first compulsion payments have been issued.

The informal tolerance period that characterised 2025 DORA supervision is over. National competent authorities — BaFin, AFM, DNB, ACPR, AMF — have shifted from guidance to active supervisory reviews. Register of Information data is being cross-checked automatically. Gaps are being flagged. And recurring daily penalty notices have landed.

Deloitte research found that only 50% of institutions expected full compliance by end of 2025. Thirty-eight per cent pushed their target into 2026 — meaning they entered the enforcement phase with gaps they already knew about. The single most challenging requirement: the Register of Information, DORA’s mandatory inventory of all ICT third-party contracts. Forty-six per cent of regulated entities identified it as their biggest compliance obstacle.

The penalty framework matches the scale. Financial entities face fines up to 2% of global annual turnover or €10 million. Critical ICT third-party providers — the cloud platforms and infrastructure vendors financial services depend on — face €5 million plus 1% of average daily global turnover for each day of continued non-compliance. Compulsion payments add a separate enforcement layer: up to 1% of daily turnover per day until a specific deficiency is remediated.

What this means for your compliance team:
→ If your Register of Information is incomplete, it is the first thing supervisors will flag. Map every ICT third-party contract, subcontracting arrangement, and service dependency — including the ones procurement owns but IT manages.
→ Many organisations built compliance documentation without changing operational processes. Supervisors are now testing whether documented controls actually function.
→ Critical ICT third-party providers face direct regulatory oversight for the first time. If your cloud vendor serves financial clients, ask whether they have completed their own DORA obligations — your compliance depends on theirs.
→ Compulsion payments are immediate and ongoing. A single deficiency can cost 1% of daily turnover every day until remediated.

At S8fe.ai, we help organisations build ICT risk management frameworks that meet DORA’s operational requirements — not just its documentation requirements. The gap between a compliant register and a compliant operation is where enforcement lands.

Documentation proves you planned. Operations prove you complied. Regulators are now testing the second.

Sources:
• https://www.regulation-dora.eu/blog/dora-2026-enforcement-what-changes
• https://digital.nemko.com/regulations/digital-operational-resilience-act
• https://www.advisori.de/en/blog/dora-2026-why-44-of-financial-companies-are-not-compliant-and-what-to-do-now

Share this article

Back To Top