DORA Compliance Deadline: What Financial Institutions Must Do Now
DORA Compliance : We’re not fully there yet, but DORA already applies” is a sentence a lot of compliance leads have said out loud in 2026, usually right before a supervisor asks to see evidence rather than intentions. DORA has been fully in force since 17 January 2025 — there is no grace period left to plan around — and yet independent surveys keep landing on the same uncomfortable number: fewer than half of EU financial entities consider themselves genuinely, defensibly compliant. One widely cited 2026 analysis put the figure at 44% of institutions still missing core requirements.
The word “deadline” is slightly misleading here, because DORA isn’t a single finish line — it’s a calendar of recurring obligations, some of which have already passed (and were missed or barely made by a lot of firms), and some of which are still ahead. This guide sorts out exactly where the deadlines actually sit in mid-2026, why so many institutions are behind despite two years of runway, and what to prioritize in the next 30, 60, and 90 days if you’re one of them.
The Deadlines You've Already Passed — Or Barely Made
If any of the rows below feel unfamiliar, that’s the gap regulators are now actively looking for. These aren’t upcoming dates — they’re commitments the market as a whole has already been tested against.
| Deadline | Date | Status | What it required |
|---|---|---|---|
| Full DORA application begins | 17 Jan 2025 | PASSED | ICT risk framework, incident classification process, and Article 30 contract clauses had to already be operational — not just drafted. |
| First Register of Information | 30 Apr 2025 | PASSED | Every in-scope entity had to submit a full inventory of ICT third-party contracts to its national regulator. |
| First CTPP cohort designated | Nov 2025 | PASSED | 19 providers named Critical ICT Third-Party Providers, triggering direct ESA Lead Overseer supervision. |
| Second annual RoI cycle | Reference date 31 Dec 2025; national deadlines Feb–Mar 2026 | PASSED (many, barely) | In at least one major jurisdiction, only around 40% of required entities had submitted with weeks left — a pattern regulators say repeated EU-wide. |
| ESA quality-check remediation window | Closed end of Apr 2026 | PASSED | Registers flagged with data-quality errors had to be corrected and resubmitted before this date or counted as non-compliant. |
Why So Many Institutions Are Still Behind
Two years should have been enough runway. In practice, several forces compounded to leave a large share of the market short of full compliance heading into mid-2026:
- Deloitte’s Wave 3 survey found only 50% of institutions expected full compliance by the end of 2025, with 38% openly pushing their target into 2026.
- A follow-up Deloitte Luxembourg survey found just 25% of institutions confident in their compliance status — a wide gap between stated intent and operational reality.
- 96% of surveyed institutions had estimated their DORA compliance costs, with most landing between €2–5 million — and 39% dedicating five to seven full-time staff to the effort, straining smaller compliance teams.
- The Register of Information was repeatedly named the single hardest requirement to fulfil, largely because of its strict xBRL-CSV format, LEI/EUID validation rules, and mandatory cross-referencing across 15 separate templates.
- TLPT (threat-led penetration testing) projects need six to twelve months of lead time to scope and execute properly, and market capacity for accredited testers is limited — firms that waited are now competing for the same scarce specialist slots.
The Deadlines Still Ahead
The obligations that already passed don’t go away — they become standing, continuous requirements. On top of that continuous baseline, three specific dates are still coming and deserve calendar space now, not later.
| Deadline | Date | Status | What it requires |
|---|---|---|---|
| National legacy ICT circulars sunset | 31 Dec 2026 | UPCOMING | Country-specific supervisory ICT guidance that pre-dates DORA (e.g. Germany's BAIT) is fully retired and replaced by DORA requirements for affected institutions. |
| Ongoing TLPT cycles | Rolling, at least every 3 years for significant entities | ONGOING | Firms in scope must complete a live, adversary-simulation test against production systems, coordinated across relevant national authorities. |
| Third annual RoI cycle | Expected Q1 2027 (reference date 31 Dec 2026) | UPCOMING | Regulators have signaled the review bar rises each cycle — the 2026 round already applied stricter checks to more data fields than 2025. |
What Regulators Are Actually Checking Right Now
If your institution isn’t confident it could pass a supervisor’s request for evidence tomorrow, the following sequence reflects what compliance teams that caught up in 2026 actually did — in roughly this order.
| Priority window | What to do |
|---|---|
| 0–30 days | Reconcile your submitted Register of Information against your actual live contracts (gaps here are the single most common audit finding); confirm whether any critical vendor is among the 19 designated CTPPs and that Article 30 clauses are actually in the signed contract; name in writing the specific person with authority to classify an incident as "major" at any hour — the 4-hour clock cannot wait for a committee. |
| 30–90 days | Close any outstanding Article 30 contract gaps — audit rights, sub-outsourcing notification, and a documented, testable exit plan; if you're a significant entity subject to TLPT and haven't scoped your next test, start now, since accredited tester capacity is booking out six to twelve months ahead; run a formal gap assessment of your ICT risk framework against Article 5–16, specifically the board's ability to explain (not just approve) the framework. |
| Ongoing | Treat the Register of Information as a living document, updated as contracts change rather than reconstructed under deadline pressure each cycle; maintain the annual testing cadence required under Article 24, with results genuinely feeding back into the risk framework; report concentration risk (Article 29) to the board on a fixed schedule, not just when a regulator asks. |
The tone of supervision changed materially between 2025 and 2026. The first year was, by most accounts, characterized by dialogue — regulators explained expectations and gave firms room to close gaps. That phase is over.
- National competent authorities and the ESAs are now cross-checking Register of Information submissions against firms’ own business impact analyses, looking for entities that report a function as “critical” in one document and omit it from their vendor register in another.
- Germany’s BaFin has stated it will run systematic DORA audits through 2026, rather than the more exploratory reviews used in the first year.
- Analysts describe the new posture as “interventionist supervision” — regulators expect real-time, data-driven evidence of resilience, not policy binders alone.
- Where RoI errors are found, the remediation cycle is no longer informal — the ESAs can formally reject a register and require correction on a fixed clock before it counts as accepted.
✓ If you’re already behind, say so internally first – DORA Compliance teams that closed gaps fastest in 2026 didn’t try to quietly catch up before their next supervisory contact — they briefed their board and their national regulator on a remediation timeline proactively. Supervisors have consistently treated a credible, documented remediation plan more favorably than a late discovery that a firm was hiding a gap.
Penalty Exposure If You Wait
| Failure | Who's exposed | Consequence |
|---|---|---|
| General DORA non-compliance | Financial entities | Up to 10% of annual global turnover or €10 million, whichever is larger (exact figure set by national penalty regime) |
| Missed major-incident reporting clock | Financial entities | Sanctionable under Article 19 as a standalone breach, separate from whatever caused the incident |
| Rejected or incomplete Register of Information | Financial entities | Formal remediation order from the NCA; repeated failure escalates to a compliance breach finding |
| Non-cooperation with a Lead Overseer | Designated CTPPs | Periodic penalty payments up to 1% of average daily worldwide turnover, per day, for up to 6 months |
DORA Compliance Resources
For anything that needs to be legally authoritative, go to the primary sources rather than a summary:
EUR-Lex — Full text of Regulation (EU) 2022/2554 (DORA) — https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022R2554
European Banking Authority (EBA) — Register of Information reporting hub — https://www.eba.europa.eu/regulation-and-policy/operational-resilience
EIOPA — DORA Oversight Framework — https://www.eiopa.europa.eu/digital-operational-resilience-act-dora/dora-oversight_en
ESMA — Digital Operational Resilience Act (DORA) hub — https://www.esma.europa.eu/esmas-activities/digital-finance-and-innovation/digital-operational-resilience-act-dora
European Central Bank — TIBER-EU Framework (basis for TLPT testing) — https://www.ecb.europa.eu/paym/cyber-resilience/tiber-eu/html/index.en.html
The Bottom Line
The framing that trips institutions up is treating DORA as a project with an end date. It isn’t — it’s a permanent operating rhythm, and the deadlines that already passed didn’t close the file, they opened a standing obligation to keep proving the same things every year, with regulators now checking more carefully than they did the first time around. The institutions handling 2026 well aren’t the ones who were perfectly ready in January 2025; they’re the ones who treated each missed or barely-made deadline as data about where their next gap will show up, and closed it before a supervisor found it for them.
DORA Compliance Frequently Asked Questions
Q. Is there still time to catch up if we're behind on DORA compliance?
Yes, but the runway is shorter than it was. Since supervision moved from dialogue to active review, the safest path is a documented remediation plan shared proactively with your regulator, prioritized around the Register of Information and incident-classification readiness first — those are the two areas regulators are checking most aggressively in 2026.
Q. We submitted our Register of Information — are we done for the year?
Submission isn’t the finish line. The ESAs run data-quality and consistency checks after national regulators forward the register, and can reject it, triggering a remediation cycle with its own deadline. A register accepted last year can still be rejected this year if validation rules tightened, which they did for the 2026 cycle.
Q. Do smaller financial entities get more time on any of these deadlines?
Proportionality under Article 16 allows micro and small entities to use a simplified ICT risk framework and face lighter testing obligations, but it does not extend submission deadlines for the Register of Information or incident reporting — those apply on the same calendar regardless of size.
Q. What happens if our TLPT testing window slips past the 3-year mark?
A missed TLPT cycle is treated as a testing-programme deficiency under Article 24–26, and given how far in advance accredited testers need to be booked, firms that start scoping only after the deadline has already passed typically compound the delay. Starting the scoping conversation six to twelve months ahead of your due date is the practical safeguard.
Q. Are non-EU companies ever affected by these deadlines?
Yes, indirectly. A non-EU cloud provider, software vendor, or data processor serving EU financial entities is pulled into the same Article 30 contract deadlines by its customers’ compliance calendars, and can be named a Critical ICT Third-Party Provider in a future designation round regardless of where it’s headquartered.