{"schema_version":"3.2.0","engine_version":"2.5.7","iso_timestamp":"2026-10-10T14:02:48.994402+00:00","track_key":"dora-fintech-resilience","track_name":"Digital Operational Resilience Act (DORA)","short_title":"DORA Fintech Resilience","risk_posture":"HIGH","headline":"DORA Operational Supervision: Competent Authorities Audit ICT Vendor Contracts, Registers, and Incident Response","primary_liability_driver":"National competent authorities supervise Article 28(3) Registers of Information and Article 30 mandatory contractual provisions, utilizing administrative sanction powers under Article 50 for governance deficiencies.","executive_summary":"Regulation (EU) 2022/2554 (DORA) has been directly applicable across all 20 categories of financial entities identified under Article 2(1) since 17 January 2025. Supervision is structured across two distinct frameworks: national competent authorities (NCAs) oversee financial entities' internal ICT governance, vendor contracts under Article 30, and Registers of Information under Article 28(3), while the European Supervisory Authorities (EBA, EIOPA, ESMA) operate the Joint Oversight Framework directly over designated Critical ICT Third-Party Providers (CTPPs) pursuant to Article 31.\n\nUnder Commission Delegated Regulation (EU) 2025/301, major ICT incident reporting requires strict adherence to statutory timelines set out in Article 5: an initial notification within 4 hours of classification (and no later than 24 hours from awareness) pursuant to Article 5(1)(a), an intermediate report within 72 hours of the initial notification pursuant to Article 5(1)(b), and a final report within 1 month pursuant to Article 5(1)(c). Non-compliant legacy contracts supporting critical or important functions are not void per se, but expose entities to binding supervisory remediation orders, public administrative censures, and national penalties under Article 50. Concurrently, Article 26 mandates advanced Threat-Led Penetration Testing (TLPT) at least every three years, but strictly for financial entities formally identified by competent authorities based on systemic significance and ICT risk profile. Lead Overseers possess statutory powers under Article 35(4)-(6) to impose periodic penalty payments (up to 1% of average daily worldwide turnover) strictly against designated CTPPs for persistent failure to comply with oversight recommendations.","milestones":[{"status":"ENACTED / IN FORCE","citation":"Regulation (EU) 2022/2554, Article 2(1) & Article 64(1)","gate":"2025-01-17","link":"https://eur-lex.europa.eu/eli/reg/2022/2554/oj","impact":"Direct application across 20 categories of financial entities, establishing statutory duties for ICT risk management, operational resilience governance, and digital testing."},{"status":"ENACTED / IN FORCE","citation":"Commission Delegated Regulation (EU) 2025/301, Article 5(1)(a)-(c)","gate":"2025-01-17","link":"https://eur-lex.europa.eu/eli/reg_del/2025/301/oj","impact":"Mandatory reporting cadence for major ICT incidents: initial notification within 4 hours of classification (and within 24 hours of awareness), intermediate report within 72 hours of initial notification, and final report within 1 month."},{"status":"ENACTED / IN FORCE","citation":"Regulation (EU) 2022/2554, Article 28(3) & Article 30","gate":"2025-01-17","link":"https://eur-lex.europa.eu/eli/reg/2022/2554/oj","impact":"Duty to maintain updated Registers of Information distinguishing contracts supporting critical or important functions, and mandating statutory audit, inspection, access, and exit rights in vendor agreements."},{"status":"ENACTED / SUPERVISORY SELECTION","citation":"Regulation (EU) 2022/2554, Articles 26 and 27","gate":"2025-01-17","link":"https://eur-lex.europa.eu/eli/reg/2022/2554/oj","impact":"Mandatory triennial Threat-Led Penetration Testing (TLPT) covering production systems, applicable exclusively to financial entities formally designated by competent authorities under Article 26(8) criteria."},{"status":"ENACTED / CTPP OVERSIGHT ONLY","citation":"Regulation (EU) 2022/2554, Article 35(4)-(6)","gate":"2025-01-17","link":"https://eur-lex.europa.eu/eli/reg/2022/2554/oj","impact":"Lead Overseers authorized to impose periodic penalty payments of up to 1% of average daily worldwide turnover exclusively on designated Critical ICT Third-Party Providers (CTPPs) for persistent oversight failures."}],"actions":[{"priority":"CRITICAL","requirement_type":"LEGAL REQUIREMENT","title":"Remediate ICT supplier contracts supporting critical or important functions to incorporate mandatory Article 30 access, audit, sub-outsourcing termination, and data security clauses.","owner":"General Counsel","gate":"2026-11-30","anchor":"Regulation (EU) 2022/2554, Article 30"},{"priority":"HIGH","requirement_type":"LEGAL REQUIREMENT","title":"Audit and reconcile the Article 28(3) Register of Information against live vendor service delivery chains and sub-contractor hierarchies.","owner":"Chief Information Security Officer","gate":"2026-12-15","anchor":"Regulation (EU) 2022/2554, Article 28(3)"},{"priority":"CRITICAL","requirement_type":"LEGAL REQUIREMENT","title":"Calibrate Security Operations Center (SOC) playbooks to ensure major ICT incidents are escalated and notified within 4 hours of classification under Delegated Regulation (EU) 2025/301 Article 5.","owner":"Chief Information Security Officer","gate":"2026-11-15","anchor":"Delegated Regulation (EU) 2025/301, Article 5"},{"priority":"MEDIUM","requirement_type":"REGULATORY EXPECTATION","title":"Review competent authority supervisory communications to verify whether entity meets Article 26 TLPT criteria, and engage qualified external testers if designated.","owner":"Chief Risk Officer","gate":"2027-01-31","anchor":"Regulation (EU) 2022/2554, Articles 26 and 27"}],"budget":{"range":"€380,000 - €720,000","methodology":"Illustrative enterprise scenario: assumes tier-1 financial entity renegotiating 35 critical ICT arrangements, enterprise Register of Information automation, and supervisory TLPT gap assessments.","breakdown":[{"item":"Critical ICT vendor contract legal renegotiation (Article 30)","amount":"€175,000"},{"item":"Register of Information (RoI) automated mapping software","amount":"€135,000"},{"item":"Incident reporting automation & SOC playbook calibration","amount":"€115,000"},{"item":"Accredited TIBER-EU/TLPT threat testing preparation retainers","amount":"€140,000"},{"item":"Supervisory audit defense contingency buffer","amount":"€55,000"}],"total_calculated":"€620,000"},"board_decisions":["DECISION: Authorize legal renegotiation budget (modeled at €175,000) for critical ICT supplier master services agreements under Article 30, closed upon execution of compliant addenda.","DECISION: Management body approval of the 2026 Register of Information prior to formal demand by National Competent Authorities, closed upon board minute entry.","DECISION: Instruct Chief Information Security Officer to conduct simulated 4-hour incident notification drill under Delegated Regulation 2025/301 Article 5, closed upon drill report sign-off."],"liability_vector":"National competent authority supervisory remediation notices, administrative sanctions, and public disclosures under Article 50 of Regulation (EU) 2022/2554, accompanied by potential operational restrictions on non-compliant ICT vendor engagements.","affected_population":"Credit institutions, investment firms, payment institutions, e-money institutions, insurance undertakings, and designated critical ICT third-party service providers (CTPPs) operating in the EU financial sector.","telemetry_hash":"c1d5e366d5ad3e419164fd5cec4eac0d9ce7b969c57f0de1e23422041c9fc759","formatted_timestamp":"2026-10-10_1402 UTC"}