# DORA Compliance Without a CISO: What Article 5 Requires

Source: https://www.cyadviso.com/dora-compliance-without-ciso
Last reviewed: 2026-08-04
Tags: DORA, ICT Risk, vCISO

DORA requires a documented ICT risk function, not a CISO title. EU-licensed fintechs can fulfil the obligation without a full-time internal hire, here is how.

---

> For a full overview of the vCISO model for EU-licensed fintechs, see [What is a vCISO? A complete guide →](/vciso-everything-you-need-to-know). For vCISO pricing models, see [navigating vCISO pricing →](/navigating-the-world-of-vciso-pricing-a-comprehensive-guide). For the hiring decision framework, see [how to hire a vCISO →](/hiring-a-vciso).

**Last reviewed: 4 August 2026**

**Key takeaways**

- DORA requires an ICT risk management function — assigned, resourced, and continuously operating — not the job title "Chief Information Security Officer".
- Under Article 5(2) the management body holds ultimate accountability for the framework; Articles 8-16 define operating the function as continuous work (asset identification, detection, incident response, third-party register), not a documentation task.
- An external vCISO can own the function when the management body retains accountability and the five operational conditions are met: formal approval, continuous operation, real-time registers, dedicated management body reporting, and a clear escalation path.
- For EU-licensed EMIs, Payment Institutions, and CASPs, a CISO vacancy does not generate supervisory findings — a non-functional ICT risk framework does.

---

DORA does not require you to hire a Chief Information Security Officer. DORA requires an ICT risk management function: assigned, resourced, and continuously operating. Those two things are not the same, and confusing them is one of the most costly misreadings EU-licensed fintechs make when planning their DORA programmes.

For EMIs, Payment Institutions, and CASPs with open CISO positions or limited in-house security capacity, the question is practical: does a vacant CISO role put us outside DORA compliance? The answer depends entirely on whether the ICT risk management function is operating, not on whether a specific job title is occupied.

Under DORA Article 5, the management body bears ultimate accountability for the ICT risk management framework. The framework must be formally approved, adequately resourced, and operated on an ongoing basis. The regulation does not prescribe the delivery model. An external vCISO operating as the ICT risk function owner satisfies Article 5 if the management body retains accountability and the function operates continuously.

Below: what Article 5 actually requires, how the function can be fulfilled without an internal hire, and what supervisors examine when reviewing the ICT risk structure of an EU-licensed fintech.

---

## What DORA Article 5 requires: the management body and the ICT risk function

DORA Article 5(2) places ultimate accountability for the ICT risk management framework on the management body. The board or senior management must approve the framework, define the entity's ICT risk appetite, set clear roles and reporting lines for the ICT risk function, and ensure adequate resourcing.

Article 5(4) adds a specific obligation: management body members must maintain updated knowledge of ICT risks. Updated in supervisory practice means ongoing engagement, not an annual policy review sign-off.

Article 6(1) requires the ICT risk management framework to be "sound, comprehensive and well-documented." Article 6(5) requires regular review: at least yearly, following major ICT-related incidents, after supervisory instructions, or based on conclusions from digital operational resilience testing or audits. There is no stable end-state. The framework must be maintained continuously.

Nowhere in DORA Title II (Articles 5-16) does the text mandate the job title "Chief Information Security Officer" or require the person fulfilling the ICT risk function to be a full-time internal employee. The obligation is functional, not positional.

---

## The operational requirements under Articles 8-16

DORA's obligations for the ICT risk management function extend well beyond approving a policy document. Articles 8-16 define what "operating the function" means in practice.

Article 8 requires ongoing identification and classification of ICT assets and the risks affecting them. This is not a one-off exercise: it requires continuous engagement with the entity's technology architecture, including cloud services, third-party dependencies, and internal systems. Article 9 requires security measures and access controls that must be updated as the threat environment changes.

Article 10 adds detection mechanisms: the entity must maintain systems to identify anomalous activity and potential incidents. These systems must be active and regularly reviewed, not set up and left running without oversight.

Articles 11 and 12 cover business continuity, incident response, and backup: operational plans with tested recovery capabilities. Supervisors request test records. Article 13 requires post-incident review processes that feed findings back into the risk framework, creating a continuous feedback loop.

Articles 28 to 30 require a register of all third-party ICT providers (Article 28(3)), with concentration risk assessed (Article 29) and contractual clauses aligned to DORA requirements (Article 30). That register does not maintain itself. Someone must track new vendors as they are adopted, review contracts at renewal, and assess concentration risk as dependencies shift.

Each of these is an operational activity, not a documentation task. Together they define the minimum operating cadence of the ICT risk management function. Whoever owns the function, whether an internal hire or an external vCISO, must execute this cadence continuously.

---

## How the function can be fulfilled without an in-house CISO

DORA's recitals and EBA technical standards confirm that EU-licensed financial entities can outsource the ICT risk management function to a qualified third party. What they cannot outsource is accountability. The management body retains responsibility for approving the framework, reviewing risk reports, and ensuring the function operates adequately. The person or team running the function can be external.

This is the regulatory basis for the vCISO model under DORA. An external vCISO acting as ICT risk function owner satisfies Article 5 when the following conditions are met:

1. The management body has formally approved the ICT risk management framework and the appointment of the external function owner.
2. The external function operates continuously, not on an ad hoc or project basis.
3. The ICT risk register, incident classification, and third-party oversight under Article 28 are maintained in real time, not at review intervals.
4. The management body receives regular ICT risk reporting, separate from compliance reporting, and management body decisions on material ICT risks are documented.
5. There is a clear escalation path from the external function to the management body for material risks.

An internal CISO hire is one way to fulfil these conditions. An external vCISO on a retainer arrangement is another. What does not fulfil the requirement is nominal designation without operational substance: assigning the function to a title in an org chart while the actual activities under Articles 8-16 go unperformed.

---

## What supervisors examine when the CISO role is vacant

EU NCAs conducting DORA ICT risk reviews do not search for the word "CISO" in an organisation chart. They examine whether the ICT risk management function operates. The review typically covers:

- Is there a named owner for the ICT risk management framework, with a documented reporting line to the management body?
- Is the ICT risk register current? What is the process for maintaining it between supervisory review cycles?
- Does the management body receive dedicated ICT risk reporting, separate from compliance reporting? Are management body decisions on material ICT risks documented?
- How are ICT incidents classified against the DORA classification criteria (Article 18 and Commission Delegated Regulation (EU) 2024/1772)? Who makes that classification decision, and when?
- Is the register of third-party ICT providers maintained per Article 28? Has concentration risk been assessed?

A CISO vacancy does not automatically generate supervisory findings. A non-functional ICT risk management framework does. Fintechs that have outsourced the ICT risk function to an external provider and can demonstrate that the five conditions above are met are in a structurally defensible position. Fintechs with an unfilled CISO role, no external arrangement, and no evidence of ongoing ICT risk activities face direct supervisory exposure regardless of what their job descriptions say.

{/* [HUMAN-FILL: anonymized vignette — category (EMI/PI/CASP) + regulator-as-subject + outcome, C-1 name-scan before publish. Natural slot: one anonymized engagement where a vacant CISO role with no external arrangement produced a specific finding, or where a vCISO arrangement satisfied the NCA despite no in-house CISO. No client name, no fabricated numbers ([live-check]). */}

This article answers one narrow question: whether DORA forces a CISO hire. It does not — DORA requires the function, not the title. For the anatomy of ownership, who is accountable and why a compliance officer cannot absorb the function without dedicated capacity, see the hub article [DORA ICT risk ownership: why compliance alone falls short →](/dora-ict-risk-ownership). For whether the role needs a dedicated job title, see [does DORA require a dedicated ICT risk officer? →](/dora-ict-risk-officer-requirement); for how the ICT risk function differs from the compliance function, see [does a vCISO replace your compliance officer? →](/vciso-vs-compliance-officer). For the full obligations baseline, see [DORA requirements 2025 →](/dora-requirements-2025).

For Baltic-licensed fintechs, supervisory expectations from [Latvijas Banka, the Latvian National Competent Authority](/dora-bank-of-latvia), and [Lietuvos bankas, the Lithuanian National Competent Authority](/dora-bank-of-lithuania), are consistent with DORA Title II requirements and the EBA ICT Risk Guidelines.

---

## Why fintechs assume a full-time CISO is mandatory

The assumption that DORA mandates a CISO typically originates from two sources. First, earlier EU financial regulation, including EBA ICT Risk Guidelines and PSD2 security requirements, emphasised the need for security leadership, which many boards interpreted as a requirement for a dedicated internal officer. Second, industry guidance and advisory reports have used "CISO" as shorthand for the ICT risk function owner without always clarifying that the function is the obligation, not the title.

DORA is more precise. It describes the ICT risk management function, defines its obligations across Articles 5-16, and places accountability at management body level. It does not prescribe whether that function is delivered by an internal hire or an external provider.

For EU-licensed fintechs operating under DORA proportionality (Article 4), the function can be scaled to the entity's size and complexity, but it cannot be absent. Proportionality affects how the function is resourced; it does not reduce the core obligations of Articles 5-16.

---

## Frequently asked questions

### Does DORA require a Chief Information Security Officer?

DORA requires a documented ICT risk management function overseen by the management body under Article 5. DORA does not mandate the job title "Chief Information Security Officer" or a full-time internal hire. The function must be clearly assigned, adequately resourced, and operationally active. An external vCISO can fulfil the requirement when the management body retains formal accountability and the five operational conditions are met.

### Can an EU fintech remain DORA-compliant without an in-house CISO?

Yes, if the ICT risk management function is operating. DORA allows the function to be provided by a qualified external party as long as the management body retains accountability, the function operates continuously, and the operational requirements of Articles 8-16 are met. A CISO vacancy without any alternative arrangement creates supervisory exposure, not a CISO vacancy in itself.

### What does DORA Article 5 actually require?

Article 5(2) requires the management body to approve the ICT risk management framework and ensure it is adequately resourced. Article 5(4) requires management body members to maintain updated knowledge of ICT risks. Article 6(1) requires the framework to be sound, comprehensive, and well-documented. Articles 8-16 set the operational requirements: ongoing asset identification and classification, ICT security measures, incident detection, business continuity planning, post-incident review, and third-party oversight. The obligation is a continuously operating function, not a one-time document.

### How does a vCISO fulfil DORA Article 5?

A vCISO satisfies Article 5 when the management body has formally approved the appointment; the vCISO operates the ICT risk management function continuously; the ICT risk register and third-party register are maintained on an ongoing basis; the management body receives regular ICT risk reporting with documented decision records; and a clear escalation path exists for material risks. The management body cannot delegate its accountability, but it can delegate the operation of the function to a qualified external provider.

---

## Structuring the ICT risk function for supervisory readiness

CyAdviso works with EU-licensed fintechs, including EMIs, Payment Institutions, and CASPs, to structure and operate the ICT risk management function under DORA. Based on engagements under EU financial-sector supervision, the most common gap is not a missing CISO hire: it is a function that exists in name but does not operate with the continuity Articles 8-16 require.

Our work covers formal function design, the operational cadence required by DORA, management body reporting structures, and the evidence package that satisfies NCA supervisory expectations.

To discuss how your fintech can structure the ICT risk function under DORA, [schedule a consultation with CyAdviso](https://cal.com/andrey-gubarev/15min) or contact us at info@cyadviso.com.

---

Authored by Andrey Gubarev — CISO for EU fintechs (CISM, CDPSE, SABSA).
CyAdviso · DORA / ICT risk / vCISO programmes for EU-licensed fintechs.
Canonical HTML: https://www.cyadviso.com/dora-compliance-without-ciso
