> ## Content Index
> Fetch the complete content index at: https://www.therecursive.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# DORA Is No Longer a Deadline
- URL: https://www.therecursive.com/dora-is-no-longer-a-deadline-what-are-the-penalties/
- Published: 2026-08-10T07:19:45.000Z
- Updated: 2026-08-10T12:08:38.000Z
- Description: The EU's grace period for DORA compliance is officially over. As regulators launch automated cross-checks, nearly half of all financial entities face massive penalties, and even tech giants like AWS aren't safe. Are your operations ready for active enforcement?
- Author: Yiannis Tsoutsoukis
- Tags: Guest Articles, Legal, Fintech, Startups, corporates, DORA

January 17, 2025 came and went. Most firms exhaled.

They shouldn't have.

On June 3, 2026, **the European Supervisory Authorities published their first DORA incident overview**. An oversight document based on actual incident data from regulated entities across the EU. That's the moment the enforcement era became real.

National competent authorities are now cross-checking Register of Information data automatically and issuing the first compulsion payments. The **informal tolerance that characterised 2025 supervision is finished**.

Here's what makes this uncomfortable: according to Deloitte research, only 50% of institutions expected to reach full compliance by end of 2025\. A further 38% pushed their target into 2026\. That means somewhere between a third and half of all regulated entities are entering active enforcement with **documented gaps**. And 60 to 70% of EU financial institutions described their Register of Information as a 'work in progress' at the January 2025 deadline.

Work in progress doesn't cut it when supervisors are cross-checking your submissions automatically.

## What the penalties actually look like?

The penalty framework varies by member state, which is itself part of the problem. Belgium allows fines up to 5 million euros or 10% of annual turnover. Italy up to 20 million euros or 10%. Ireland up to 10 million euros. Germany and the Netherlands up to 5 million euros. **The Czech Republic** sits at the lower end with a 2 million euro ceiling. **Croatia** has taken a different approach, capping penalties at 3% of total annual income.

And then there are the laggards. In March 2025, the European Commission opened infringement procedures against **Poland and Bulgaria**, alongside 11 other member states, for failing to fully transpose DORA into national law. Both countries are still completing their legislative alignment. 

The irony is pointed: **DORA's enforcement era has begun**, but some of the regulators responsible for enforcing it are themselves still catching up.  
Individual executives face personal fines of up to 1 million euros in most jurisdictions, and in Germany and Italy up to 5 million euros.

For critical ICT third-party providers, all of which were formally designated under DORA oversight in November 2025, including AWS, Azure, and Google Cloud, the **daily penalty structure is the most aggressive**: up to 1% of average daily worldwide turnover for each day of continued non-compliance, for up to six months. For a firm the size of Amazon or Microsoft, that is not a rounding error.

**Beyond the fines**: regulators can suspend or prohibit specific ICT services, require the appointment of a special manager, temporarily ban senior managers from exercising management functions, and issue public notices of violation. 

**Reputational damage** from a public enforcement notice typically exceeds the direct financial penalty. Rating agencies and institutional investors treat it as a governance signal.

## Where most firms are still exposed?

The Register of Information problem is the most widespread and least solved. DORA requires firms to **map, monitor, and contractually govern every ICT third-party relationship**. Most fintechs built their technology stacks on layers of dependencies, cloud providers, payment processors, fraud detection tools, data vendors, without the governance infrastructure DORA now demands.

**The incident reporting timeline is another gap**. Major ICT incidents require initial notification within 4 hours, an intermediate report within 72 hours, and a final report within one month. Most firms either don't have tested incident response procedures at all, or have procedures that exist on paper but have never been stress-tested against real timelines.

And then there's the board question. DORA explicitly places responsibility for ICT risk management on **the management body**. If your board cannot speak to the firm's DORA compliance posture when a supervisor asks, and they are asking, that is a governance failure before it is a technical one.

## What comes next?

The enforcement posture in 2026 is risk-based. **Supervisors are prioritising institutions with the largest third-party exposures** and the most significant gaps first. That means smaller fintechs and payment institutions may have a short window to close their gaps before supervisory attention reaches them.

That window is not indefinite. The firms cross-checking your Register of Information data automatically are not waiting for your remediation plan. They are building their enforcement queue.

The firms that treat this as an operational upgrade, not a compliance exercise, will come through this cycle stronger. **Better vendor relationships, cleaner governance, more credible posture** with banks and institutional partners. The firms that don't will learn the difference between a deadline and enforcement the hard way.