Yiannis Tsoutsoukis is a CySEC Advanced Certified regulatory and corporate strategy professional based in Nicosia, Cyprus. He has been published in the Cyprus Mail and News In Cyprus on EU regulatory strategy.

January 17, 2025 came and went. Most firms exhaled.

They shouldn't have.

On June 3, 2026, the European Supervisory Authorities published their first DORA incident overview. An oversight document based on actual incident data from regulated entities across the EU. That's the moment the enforcement era became real.

National competent authorities are now cross-checking Register of Information data automatically and issuing the first compulsion payments. The informal tolerance that characterised 2025 supervision is finished.

Here's what makes this uncomfortable: according to Deloitte research, only 50% of institutions expected to reach full compliance by end of 2025. A further 38% pushed their target into 2026. That means somewhere between a third and half of all regulated entities are entering active enforcement with documented gaps. And 60 to 70% of EU financial institutions described their Register of Information as a 'work in progress' at the January 2025 deadline.

Work in progress doesn't cut it when supervisors are cross-checking your submissions automatically.

What the penalties actually look like?

The penalty framework varies by member state, which is itself part of the problem. Belgium allows fines up to 5 million euros or 10% of annual turnover. Italy up to 20 million euros or 10%. Ireland up to 10 million euros. Germany and the Netherlands up to 5 million euros. The Czech Republic sits at the lower end with a 2 million euro ceiling. Croatia has taken a different approach, capping penalties at 3% of total annual income.

And then there are the laggards. In March 2025, the European Commission opened infringement procedures against Poland and Bulgaria, alongside 11 other member states, for failing to fully transpose DORA into national law. Both countries are still completing their legislative alignment.

The irony is pointed: DORA's enforcement era has begun, but some of the regulators responsible for enforcing it are themselves still catching up.
Individual executives face personal fines of up to 1 million euros in most jurisdictions, and in Germany and Italy up to 5 million euros.

For critical ICT third-party providers, all of which were formally designated under DORA oversight in November 2025, including AWS, Azure, and Google Cloud, the daily penalty structure is the most aggressive: up to 1% of average daily worldwide turnover for each day of continued non-compliance, for up to six months. For a firm the size of Amazon or Microsoft, that is not a rounding error.

Beyond the fines: regulators can suspend or prohibit specific ICT services, require the appointment of a special manager, temporarily ban senior managers from exercising management functions, and issue public notices of violation.

Reputational damage from a public enforcement notice typically exceeds the direct financial penalty. Rating agencies and institutional investors treat it as a governance signal.

Where most firms are still exposed?

The Register of Information problem is the most widespread and least solved. DORA requires firms to map, monitor, and contractually govern every ICT third-party relationship. Most fintechs built their technology stacks on layers of dependencies, cloud providers, payment processors, fraud detection tools, data vendors, without the governance infrastructure DORA now demands.

The incident reporting timeline is another gap. Major ICT incidents require initial notification within 4 hours, an intermediate report within 72 hours, and a final report within one month. Most firms either don't have tested incident response procedures at all, or have procedures that exist on paper but have never been stress-tested against real timelines.

And then there's the board question. DORA explicitly places responsibility for ICT risk management on the management body. If your board cannot speak to the firm's DORA compliance posture when a supervisor asks, and they are asking, that is a governance failure before it is a technical one.

What comes next?

The enforcement posture in 2026 is risk-based. Supervisors are prioritising institutions with the largest third-party exposures and the most significant gaps first. That means smaller fintechs and payment institutions may have a short window to close their gaps before supervisory attention reaches them.

That window is not indefinite. The firms cross-checking your Register of Information data automatically are not waiting for your remediation plan. They are building their enforcement queue.

The firms that treat this as an operational upgrade, not a compliance exercise, will come through this cycle stronger. Better vendor relationships, cleaner governance, more credible posture with banks and institutional partners. The firms that don't will learn the difference between a deadline and enforcement the hard way.

Share