August 19, 2026
We wrote about the Digital Operational Resilience Act back when it was still a looming deadline. It's now been in force long enough for the real lessons to surface — and they're not quite what most compliance teams expected going in.
DORA was widely treated as a third-party risk management exercise: map your ICT vendors, get contractual clauses updated, tick the register. That part was manageable. What caught organisations out was resilience testing — specifically, proving operational continuity on the systems that are hardest to test without disrupting live service. For most financial institutions, that means the mainframe.
Supervisory attention is shifting from "have you done the mapping" to "can you prove it under stress." That's a harder bar, and it rewards organisations that treated DORA as an operational capability question rather than a documentation exercise from the start. If your resilience testing programme still leans more on paperwork than proof, it's worth a second look before the next supervisory cycle.