advanced 3 min answer

The EU's Digital Operational Resilience Act has applied to financial entities since 17 January 2025. It requires a maintained register of every contractual arrangement with an ICT third-party provider, threat-led penetration testing, and brings designated critical providers under direct supervisory oversight. What does an architecture team gain from this, what does it pay, and when does the bill land?

dorathird-party-riskregisterresilience-testingeu
Show the full answer Hide the answer

What is gained, quantified

A regulation of this shape does something architecture functions usually cannot do for themselves: it forces the dependency graph to be written down and kept current. The register of information is an inventory of every ICT contract, at entity, sub-consolidated and consolidated level, including whether the service supports a critical or important function and who the provider's own subcontractors are.

That artefact is worth having regardless of the regulator. Most organisations cannot answer "which of our suppliers, including their suppliers, could stop us processing payments" in less than weeks, and the register turns it into a query. The oversight regime adds something an individual firm cannot buy: designated critical providers — the European Supervisory Authorities published the first designations in November 2025 — are supervised directly, so the largest concentrations are examined by someone with more authority than any single customer.

What is paid

  • A permanent data-maintenance obligation. The register is only useful if it is current, and contracts change constantly. Firms that treat it as an annual spreadsheet exercise produce something that is wrong by March, and wrong in the specific way that matters: a missing subcontractor.
  • Contractual rework across the supplier estate. Audit rights, incident notification windows, exit provisions and subcontracting transparency have to exist in every agreement covering a critical or important function. That is legal and commercial work measured in months, and some smaller suppliers will decline.
  • Testing that touches production. Threat-led penetration testing against live systems is a different proposition from a scoped annual assessment: it needs a safe path to stop, agreed scope with the providers involved, and people who can distinguish the test from an incident.
  • A classification decision with teeth. Deciding which functions are "critical or important" determines how much of this applies, and the temptation to classify narrowly is exactly what a supervisor will examine.

When the cost becomes visible

Not at the point of the register's first submission. It lands at the first architectural change that touches a critical function — a new analytics provider, a new region, a change of subprocessor by an existing supplier — because each of those now has a compliance path attached to a decision that used to be an engineering one.

The second arrival is at exit testing. A documented exit plan is cheap; demonstrating that the plan works is where organisations discover that their data is in a proprietary format, that the runbook depends on the provider's own tooling, and that nobody has tried it.

How to keep the option to reverse

Build the register from systems rather than from a document: generate it from the contract management system, the cloud accounts and the service catalogue, so it is a report rather than a manual artefact. Tag services with their criticality classification at the point of creation, so the boundary of the regime is a property of the estate rather than an annual judgement. And treat the exit-plan test the way you treat a disaster recovery test — scheduled, scoped and measured — rather than as a document review, because the only version of it that provides evidence is the one you ran.

When this is the wrong framing

For a firm outside scope, copying DORA's machinery wholesale is over-investment; the parts worth borrowing are the supplier inventory and the exit rehearsal, which are good practice at any size. And for a small entity within scope, proportionality is written into the regime — treating every obligation as if it applied at the intensity a systemically important bank faces is the most common and most expensive misreading, and it produces a compliance programme that crowds out the resilience work it was meant to cause.