DORA Compliance Checklist for UK & Poland Financial Firms: Your 2025 Survival Guide
First published by Metaluxo — cybersecurity and compliance insights for businesses on both sides of the Channel.
Introduction — Why DORA Suddenly Matters in London and Warsaw
On 16 January 2025, the EU’s Digital Operational Resilience Act (DORA) entered into force across all member states — and for UK and Polish financial firms alike, the ground has shifted underneath their feet.
The headlines read like a threat-intelligence briefing. AI agents are weaponising zero-days within five days of discovery1. The median company still takes 43 days to patch them1. Meanwhile, CISOs are racing not just against hackers but against regulators who now demand proof — not promises — that your digital infrastructure can survive a cyber storm.
This isn’t abstract risk. Financial institutions have been under siege for years — as we explored in our deep-dive on Is the global banking system being hacked? — and just last month, Spain’s data protection authority logged its first reported AI-powered data breach2, and the Internet Systems Consortium patched fourteen critical DNS vulnerabilities in a single BIND 9 update3. Every day you delay, the landscape grows more hostile.
DORA changes everything: instead of hoping your security posture is “good enough,” you must now demonstrate it with documented policies, tested incident-response playbooks, and continuous monitoring — or face fines of up to €15 million (or 10 % of global turnover).
This post gives you the practical roadmap. Below you’ll find:
✅ The DORA compliance checklist every UK and Poland firm should own by Q2 2025
✅ The seven core DORA requirements translated from legalese into actions you can take today
✅ A ready-to-use FAQ answering the questions your board — and your regulator — are already asking
🚀 Quick-win recommendation: If you’re short on time, jump straight to the checklist section or skim the FAQ.
DORA at a Glance — Who Does It Apply To?
DORA (Regulation (EU) 2022/2553) is the EU’s comprehensive framework for digital resilience in the financial sector. It applies to:
| Entity Type | Examples |
|---|---|
| Credit institutions | Banks, building societies (UK subsidiaries) |
| Investment firms | Asset managers, investment banks |
| Insurance & reinsurers | Life insurers, non-life insurers |
| ICT third-party service providers | Cloud providers, MSPs servicing the above |
Key dates:
| Date | Milestone |
|---|---|
| 16 Jan 2023 | DORA adopted (text published) |
| 16 Jan 2024 | Final technical standards published |
| 16 Jan 2025 | DORA fully applicable — compliance deadline |
| 17 Jan 2025 | First 12-month supervisory review cycle begins |
Polish financial firms fall under the Polish Financial Supervision Authority (KNF), which has signalled it will align supervisory expectations with the EBA’s final draft guidelines. UK firms operating in the EU (or serving EU clients) must comply through their EU branches or subsidiaries.
The Five Pillars of DORA (and How They Map to Actionable Requirements)
DORA is built around five pillars. But what matters to your compliance team is not the theory — it’s what you must do.
Below, we translate each pillar into concrete requirements, then give you the checklist that turns them into week-by-week tasks.
| DORA Pillar | What It Means in Practice | Maps to Requirement |
|---|---|---|
| ICT Risk Management | Identify, classify, and mitigate risks to your digital infrastructure | Requirement 1 |
| Incident Reporting | Detect, classify, and report major incidents within strict timeframes | Requirement 2 |
| Digital Operational Resilience Testing | Regular testing (including penetration testing) to prove your controls work | Requirement 3 |
| Third-Party Risk Management | Vetting, contracting, and monitoring all ICT service providers | Requirement 4 |
| Information & Intelligence Sharing | Sharing threat intelligence with peers and regulators | Requirement 5 |
| Additional cross-cutting duties | Governance, oversight of critical providers, and simplified regimes for smaller firms | Requirements 6–7 |
💡 For readers who prefer a quick scan: If you want the bare minimum of what DORA demands, jump to the checklist section. The rest of this post explains why each item exists so you can defend your program to auditors and the board.
With this framework in mind, let’s translate each requirement into plain English and actionable steps.
The Seven Core DORA Requirements (Translated)
DORA organises its obligations around nine chapters, but in practice they boil down to seven operational imperatives. Here’s each requirement in plain language, followed by what you need to do.
1. ICT Risk Management
What it says (legalese): “Financial entities shall have in place a comprehensive management framework for ICT risk.”
What it means: You need a formal, board-approved ICT risk management framework that includes risk assessment, proportionality, and continuous monitoring.
Action items:
- Appoint an ICT Risk Committee with clear reporting lines to the board.
- Implement a risk register that covers all ICT assets, threats, and vulnerabilities.
- Conduct quarterly risk assessments using a standard methodology (ISO 27005 or NIST RMF recommended).
- Ensure your framework scales with your size — DORA explicitly allows proportionality for smaller firms.
2. Incident Reporting & Classification
What it says: “Major ICT-related incidents shall be classified, documented, and reported to the relevant competent authority.”
What it means: You need a formal incident-management process with strict reporting deadlines (often as short as 4 hours for major incidents). You’ll also need to classify incidents by severity and impact.
Action items:
- Define “major incident” thresholds (availability loss, data breach scope, financial impact).
- Create an incident-response playbook with escalation trees and communication templates.
- Set up automated alerting and log collection to support rapid classification.
- Train your team on the 4-hour reporting window — most firms underestimate the operational pressure this creates.
3. Digital Operational Resilience Testing (DORT)
What it says: “Financial entities shall test their ICT systems and tools used to support critical functions.”
What it means: You’re required to run regular resilience tests — including penetration testing, vulnerability assessments, and scenario-based exercises. Large firms must undergo advanced testing (TLPT — Threat-Led Penetration Testing) every three years.
Action items:
- Conduct annual vulnerability assessments and penetration tests.
- Run quarterly tabletop exercises for incident response.
- If you’re a large firm, schedule your first TLPT and budget for external testers.
- Document all findings and remediation actions in a central register.
4. Third-Party Risk Management (TPRM)
What it says: “Financial entities shall manage risks stemming from ICT third-party service providers.”
What it means: Every ICT provider you use — from cloud hosting to SaaS tools to MSPs — must be vetted, contracted with DORA-aligned clauses, and continuously monitored.
Action items:
- Build an ICT vendor inventory with risk ratings (critical, important, standard).
- Include DORA-specific contractual clauses: right to audit, incident reporting obligations, data location, exit strategy.
- Review third-party security certifications (ISO 27001, SOC 2) annually.
- Map concentration risk — are you overly dependent on a single cloud provider?
5. Information & Intelligence Sharing
What it says: “Financial entities shall share cyber threat information and intelligence.”
What it means: DORA encourages (and in some cases mandates) sharing threat intelligence with industry peers and regulators. This is not about sharing customer data — it’s about sharing IOCs, attack patterns, and mitigation strategies.
Action items:
- Join an industry threat-sharing group (e.g., FS-ISAC for financial services).
- Nominate a threat-intelligence liaison within your security team.
- Establish a process for sanitising and sharing IOCs without exposing sensitive data.
- Feed threat intelligence back into your risk register and testing scenarios.
6. Oversight of Critical Third Parties (CTPPs)
What it says: “Critical ICT third-party providers shall be subject to direct oversight by EU regulators.”
What it means: If you rely on a “critical” provider (e.g., a major cloud provider or SWIFT), that provider may be designated as a Critical Third Party (CTP) by EU regulators. You must still manage your own exit strategy and resilience even when the CTP is under regulatory oversight.
Action items:
- Identify which of your providers might be designated as CTPs.
- Ensure your contracts include exit clauses and data portability provisions.
- Maintain business-continuity plans that don’t rely solely on any single CTP.
- Monitor regulatory announcements for new CTP designations.
7. Governance, Simplified Regimes & Reporting
What it says: “Financial entities shall ensure effective governance arrangements and internal control mechanisms.”
What it means: Your board and senior management are accountable for DORA compliance. Smaller firms may qualify for a simplified regime, but you must document why you qualify and what you’ve simplified.
Action items:
- Assign a board-level owner for DORA compliance (usually the CISO or Risk Director).
- Submit annual compliance reports to your national competent authority (e.g., KNF in Poland, FCA/PRA for UK firms with EU presence).
- If you’re a smaller firm, document your proportionality assessment and simplified regime election.
- Maintain a compliance calendar with submission deadlines and review cycles.
DORA Compliance Checklist: The Actionable Items
Use this checklist as your working document. Assign owners, set deadlines, and tick off items as you go.
| # | Action Item | Owner | Deadline | Status |
|---|---|---|---|---|
| 1 | Appoint board-level DORA owner (CISO/Risk Director) | CEO / Board | Week 1 | ☐ |
| 2 | Form cross-functional DORA working group | DORA Owner | Week 2 | ☐ |
| 3 | Conduct ICT asset inventory and risk assessment | Risk / IT | Week 4 | ☐ |
| 4 | Draft board-approved ICT risk management framework | Risk / Legal | Week 6 | ☐ |
| 5 | Build incident-response playbook with 4-hour reporting workflow | Security | Week 8 | ☐ |
| 6 | Classify and document “major incident” thresholds | Risk / Security | Week 8 | ☐ |
| 7 | Schedule annual penetration test and quarterly tabletop exercises | Security | Ongoing | ☐ |
| 8 | Build ICT third-party inventory with risk ratings | Procurement / IT | Week 5 | ☐ |
| 9 | Audit all vendor contracts for DORA-aligned clauses | Legal / Procurement | Week 10 | ☐ |
| 10 | Join industry threat-sharing group (e.g., FS-ISAC) | Security | Week 6 | ☐ |
| 11 | Identify potential Critical Third Parties (CTPs) in your supply chain | Risk | Week 7 | ☐ |
| 12 | Document exit strategies and data portability for all CTPs | IT / Legal | Week 12 | ☐ |
| 13 | Submit proportionality assessment (if claiming simplified regime) | Risk / Compliance | Week 8 | ☐ |
| 14 | Set up compliance calendar with annual reporting deadlines | Compliance | Week 4 | ☐ |
| 15 | Run first full DORA gap assessment and present to board | DORA Owner | Week 12 | ☐ |
💡 Pro tip: For firms under €100M in assets, DORA allows a simplified regime. But don’t assume you’re exempt — use this checklist flexibly and document your proportionality rationale. As cybersecurity spending has grown by 39% across the sector (as we tracked in our 2020 spending analysis), every pound invested in resilience is a pound saved in potential fines. Smaller firms should also review our free Cyber-essentials for SMEs guide.
Frequently Asked Questions About DORA Compliance
These are the questions that come up most often in conversations with compliance officers across London and Warsaw — plus the ones boards typically ask once the conversation reaches the C-suite.
What are compliance checklists?
A compliance checklist is a structured, itemised list of actions that organisations use to verify they’ve met every regulatory requirement. For DORA, a compliance checklist should cover all five pillars — risk management, incident reporting, resilience testing, third-party oversight, and governance — with clear ownership, deadlines, and evidence trails. See our full DORA Compliance Checklist above for a ready-to-use template.
What companies have to comply with DORA?
DORA applies to banks, investment firms, insurers, payment institutions, crypto-asset service providers, and ICT third-party service providers that support them. If you’re a financial entity operating in the EU — or a UK firm with EU branches or clients — you’re in scope.
What does DORA stand for in compliance?
DORA stands for the Digital Operational Resilience Act — Regulation (EU) 2022/2554. It’s an EU regulation designed to ensure that financial institutions can withstand, respond to, and recover from ICT-related disruptions and cyberattacks.
What are the five pillars of the DORA regulation?
The five pillars are:
- ICT Risk Management — Identifying and mitigating digital risks.
- Incident Reporting — Detecting, classifying, and reporting major ICT incidents.
- Digital Operational Resilience Testing — Regular testing to prove your controls work.
- Third-Party Risk Management — Vetting and monitoring all ICT service providers.
- Information & Intelligence Sharing — Sharing threat intelligence with peers and regulators.
These are supplemented by additional cross-cutting duties around governance, oversight of critical third parties, and simplified regimes for smaller firms.
When does DORA take effect and when must I be compliant?
DORA entered into force on 16 January 2025. The final technical standards were published on 16 January 2024. There is no grace period — compliance was required from day one. The first supervisory review cycle runs from 17 January 2025.
What are the key requirements of DORA?
DORA boils down to seven operational requirements:
- ICT Risk Management Framework
- Incident Reporting & Classification (4-hour reporting for major incidents)
- Digital Operational Resilience Testing (annual pen tests, quarterly exercises, TLPT every 3 years for large firms)
- Third-Party Risk Management (vendor vetting, DORA-aligned contracts)
- Information & Intelligence Sharing (threat intelligence with peers)
- Oversight of Critical Third Parties (exit strategies, regulatory designation)
- Governance, Simplified Regimes & Annual Reporting (board accountability, proportionality)
What are the penalties for non-compliance with DORA?
Non-compliance can result in fines of up to €15 million or 10% of global annual turnover (whichever is higher). National competent authorities (e.g., KNF in Poland) also have powers to issue public reprimands, suspend operations, and revoke licences.
How to prepare for DORA compliance?
Start with our 15-item checklist above. The most critical early steps are:
- Assign a board-level owner.
- Run a gap assessment against the seven requirements.
- Lock down your incident-response playbook (the 4-hour window is the most common failure point).
- Map your third-party ICT providers.
- Schedule your first resilience test — even a tabletop exercise counts.
What is the difference between DORA and GDPR?
GDPR protects personal data — it tells you how to collect, store, and share customer data. DORA protects digital operational resilience — it tells you how to ensure your ICT systems can survive attacks and disruptions. They overlap (e.g., a data breach is both a GDPR incident and a DORA incident), but they serve different purposes. You need to comply with both.
What are the DORA ICT risk management requirements?
You need a formal, board-approved ICT risk management framework that includes:
- A risk register covering all ICT assets, threats, and vulnerabilities.
- Quarterly risk assessments using a standard methodology.
- Continuous monitoring and reporting.
- Proportionality — the framework must scale with your firm’s size and complexity.
How much does DORA compliance cost?
Costs vary significantly by firm size and maturity. As cyber-insurance premiums rise, the regulatory fine for non-compliance far outweighs the cost of getting compliant. A basic compliance program for a small firm may cost €50K–€150K annually, though SMEs can start with the free Cyber-essentials for SMEs booklet we published for smaller businesses. Large institutions may invest €1M–€3M+ across technology, consulting, testing, and staffing.
Does DORA apply to UK financial firms?
UK firms are not directly subject to DORA unless they operate within the EU (branch or subsidiary). However, UK-regulated firms that serve EU clients or rely on EU-based third-party providers may need to comply through their EU presence. The UK’s own financial regulators are also incorporating DORA-style resilience expectations into their supervisory framework — building on themes we first explored in Brexit and the impact on Data Security and Privacy.
How often should I test for DORA resilience?
DORA requires at least one advanced resilience test per year (TIA or TLPT). Smaller firms can use a simplified threat-led impact assessment. Additionally, you should conduct quarterly incident-response tabletop exercises to validate your 4-hour reporting workflow.
What the News Tells Us — and Why It Matters for Your DORA Journey
The latest cybersecurity headlines reinforce why DORA’s rigorous approach is necessary — and why delaying is dangerous:
- AI agents are accelerating the attack cycle. Attackers now weaponise vulnerabilities in ~5 days, while the average organisation takes 43 days to patch. Your DORA testing must now include AI-driven threat scenarios — a point we explored in our analysis of AI tools and cybersecurity.
- Model misalignment incidents are rising. OpenAI recently disclosed six instances of unexpected AI model behaviour, underscoring the need for AI risk governance — a requirement that’s moving from “best practice” to “regulatory expectation.”
- Infrastructure vulnerabilities persist. The BIND 9 update fixing 14 DNS flaws reminds us that even foundational infrastructure can’t be trusted without continuous patching and monitoring — core tenets of DORA’s risk management chapter and the same principle behind protecting your DNS from spoofing attacks, as we detailed in Protecting your domain from DNS spoofing.
- AI-powered breaches are here. Spain’s data agency just received its first AI-powered breach report, signalling that cyber-criminals are weaponising the same AI tools firms use for defence.
📰 Bottom line: DORA isn’t preparing you for a static threat landscape. It’s forcing you to build an organisation that can adapt as fast as the threats evolve.
Getting Started — Your First 30 Days
If you’ve read this far, you’re already ahead of most firms. Here’s how to turn this checklist into action:
- Assign ownership. Designate a DORA project lead (CISO or equivalent) and form a cross-functional working group (Risk, IT, Legal, Compliance, Procurement).
- Run a gap assessment. Use the checklist above to score your current state against each requirement. Flag red/amber items.
- Prioritise incident response. The 4-hour reporting window is the most commonly failed requirement. Get your playbook, templates, and escalation contacts locked down first.
- Map your third parties. Inventory every ICT provider — including SaaS tools your marketing team signed up for. You’ll be surprised how many “small” providers aggregate into significant risk.
- Schedule your first test. Even a tabletop exercise counts. DORA rewards progress, not perfection — but you must show you’re moving.
Need Help? Metaluxo Can Help You Navigate DORA
At Metaluxo, we’ve been tracking the evolution of cybersecurity regulation since 2015 — from early GDPR preparations through today’s AI-powered threat landscape. Our team blends hands-on security engineering with practical compliance frameworks to help UK and Poland firms navigate DORA without drowning in bureaucracy.
Whether you need a gap assessment, a full compliance program, or just a second opinion on your third-party risk register, we’re here to help.
📧 Reach out: Get in touch for a free 30-minute DORA readiness consultation.
Footnotes:
Footnotes
-
The Hacker News, “CISO’s Expert Guide to Agentic Pentesting for Websites” (17 Sep 2026). Attackers weaponise new vulnerabilities within five days; median patch time: 43 days (Verizon DBIR 2026). ↩ ↩2
-
BleepingComputer, “Spain’s data agency gets first report of AI-powered data breach” (16 Sep 2026). ↩
-
The Hacker News, “BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS” (17 Sep 2026). ↩