DORA is no longer asking whether firms have a plan.
It is exposing whether they can prove the plan works.
DORA is no longer a readiness exercise. It has been ‘live’ since 17 January 2025. The market has moved from interpretation to evidence.
And that changes the conversation.
The pressure is now less about whether firms have a programme, and more about whether they can show it works in practice: incident handling, testing discipline, registers of information, third-party visibility, remediation tracking, and management reporting that stands up under scrutiny.
EIOPA’s 2026 programme makes clear that oversight of critical ICT third-party providers is now part of the live supervisory landscape, not a theoretical future state.
The EBA’s March 2026 joint guidelines on cooperation and information exchange add another layer of operational detail to how oversight and follow-up should function.
This matters for Tungsten because most of this is workflow.
- Evidence requests.
- Document intake.
- Control records.
- Exceptions.
- Escalations.
- Audit trails.
DORA may be framed as a piece of ‘resilience legislation’, but it is more often a test of whether an enterprise can produce evidence at pace when the heat is turned up.
Where are we already seeing clients struggle to evidence resilience operationally, rather than describe it on paper?
Frequently Asked Questions
What is DORA?
The Digital Operational Resilience Act (DORA) is an EU regulation that establishes requirements for ICT risk management, operational resilience, incident reporting, resilience testing, and third-party risk management for financial institutions.
Why is DORA focused on operational evidence?
Now that DORA is in force, regulators increasingly expect organizations to demonstrate that controls, governance, and resilience processes are working in practice, rather than simply documenting policies.
What types of evidence do organizations need under DORA?
Organizations should be able to provide documentation supporting incident management, resilience testing, ICT risk controls, third-party oversight, remediation activities, governance decisions, and audit trails.
How can workflow automation support DORA compliance?
Workflow automation helps standardize evidence collection, document processing, approvals, exception handling, and reporting, making compliance activities more efficient and auditable.
Glossary
| Term |
Definition |
| DORA |
The Digital Operational Resilience Act, an EU regulation designed to strengthen the operational resilience of financial entities. |
| Operational Resilience |
An organization's ability to prevent, withstand, respond to, recover from, and adapt to operational disruptions. |
| ICT Third-Party Provider |
An external technology provider that delivers ICT services supporting regulated financial institutions. |
| Evidence Management |
The process of collecting, organizing, and maintaining documentation that demonstrates compliance with regulatory requirements. |
| Audit Trail |
A chronological record of system activities, approvals, and user actions that provides accountability and supports regulatory reviews. |