Skip to content

7 June 2026

DORA in practice: why almost no bank was compliant by the deadline, and what to do now

conformis

The deadline arrived, but most weren't ready

On 17 January 2025, the Digital Operational Resilience Act (DORA) came into full effect. The preparation period was more than two years. Even so: none of the German banks surveyed had fully met the requirements by that date. This isn't a niche phenomenon, it's the normal state of the German financial sector.

Why is that? DORA isn't a classic IT security law. It requires a comprehensive redefinition of operational resilience, from risk architecture to third-party management to complete documentation of every ICT incident. Many institutions underestimated the scope of the framework.

This article explains where the biggest implementation gaps lie, what BaFin will be examining over the coming months, and how your institution can act now in a targeted way.

What DORA really requires: the five core areas

1. ICT risk management

DORA requires a fully documented ICT risk management framework. That means not just a risk list in a spreadsheet, but a traceable process with defined roles, escalation paths, test plans, and governance anchored at board level.

Specifically, institutions must document:

  • All critical ICT systems and their dependencies
  • Scenarios for the failure of these systems
  • Recovery objectives (RTO, RPO) per system
  • Regular testing of resilience measures

Many banks have some of these elements, but not as a coherent, auditable framework. That's the first major gap.

2. Register of information (ICT third-party register)

DORA requires all financial institutions to maintain a complete register of all ICT third-party providers. This register must be submitted to the competent supervisory authority, in Germany to BaFin.

The register must include, among other things:

  • Name and contact details of the service provider
  • Type of service provided
  • Criticality assessment (critical, important, or neither)
  • Contract status and terms
  • Sub-contractors of the service provider

BaFin has again announced workshops for 2026 to support institutions in correctly submitting the register of information. That alone shows: the quality of the data submitted so far has room for improvement.

3. Third-party risk management

DORA goes well beyond the previous outsourcing requirements under BAIT or MaRisk. For critical and important third-party providers, institutions must:

  • Anchor specific resilience requirements contractually
  • Define and test exit strategies
  • Carry out regular provider audits
  • Assess concentration risks, for example when several critical systems rely on the same cloud provider

BaFin classifies concentration risk in particular as a critical examination focus. Anyone who has concentrated their infrastructure heavily on a single hyperscaler must be able to document and justify that.

4. ICT incident management and reporting obligations

DORA introduces a three-stage reporting system for ICT-related incidents:

  • Initial report within four hours of classification as a major incident
  • Intermediate report within 72 hours
  • Final report within one month

The classification criteria are precisely defined. Institutions must ensure internally that every incident is assessed and documented promptly. Missing or late reports are a direct supervisory risk.

5. Resilience testing (DORA TLPT)

For systemically important institutions, DORA mandates Threat-Led Penetration Testing, realistic attack simulations by external specialists based on real threat scenarios. Smaller institutions are exempt from this requirement but must still carry out and document regular ICT testing.

Where German banks most often fall short

Practice shows a clear pattern in the most common implementation weaknesses.

Resource constraints in IT: DORA creates significant additional work in identifying critical and important functions. Many institutions lack this capacity internally and rely on external consultants, an expensive approach that doesn't scale in the long run.

Fragmented documentation: information on ICT systems, contracts, and risks is spread across different departments and systems. A consistent, auditable register doesn't exist.

Missing governance anchoring: DORA isn't an IT topic, it's a board-level topic. In many institutions, awareness at management level still isn't sufficient.

Incomplete third-party inventories: many institutions don't have full visibility into which external service providers deliver critical functions, especially where there are indirect dependencies through sub-contractors.

What BaFin is examining now

BaFin has made clear that it will actively enforce DORA. In its ongoing supervisory practice, it focuses on:

  • Completeness and quality of the registers of information
  • Traceability of the ICT risk management framework
  • Concentration risk with cloud and data center providers
  • Adequacy of internal incident classification processes

Institutions that cannot provide solid evidence in these areas must expect follow-up questions, requests for information, and, in repeated cases, supervisory measures.

The pragmatic path to DORA compliance

Full DORA compliance is achievable, but not overnight and not through simple spreadsheets. The structured approach comprises three phases.

Phase 1: Stocktaking and gap analysis

Systematically identify which DORA requirements you already meet and where gaps exist. The register of information is the first concrete step, it forces completeness in your third-party inventory.

Phase 2: Building the framework

Create a documented ICT risk management framework that covers every DORA chapter. Anchor responsibilities, define escalation paths, set testing cycles.

Phase 3: Continuous monitoring

DORA isn't a one-off project. Regulatory requirements change, third-party landscapes change, new systems get added. Monitoring has to be ongoing and automated.

Conclusion

DORA has fundamentally redefined the operational resilience of financial institutions. The good news: German institutions bring a solid starting point through BAIT and MaRisk. The bad news: the additional requirements, especially around third-party management and the registers of information, are substantial.

Institutions that act now in a structured way will become compliant and build resilience that protects them when it matters. Those who wait risk supervisory action and real operational losses from ICT incidents.

conformis maps every DORA article directly to your existing policies and controls and shows exactly where gaps exist. The gap analysis takes minutes, not months.

Back to overview

See in 15 minutes where you stand.

Live, against your own policies, no obligation.