# DORA Enforcement in 2025: What EU Fintechs Are Learning

Source: https://www.cyadviso.com/dora-enforcement-2025
Last reviewed: 2026-08-11
Tags: DORA, Enforcement, Supervisory Review

DORA enforcement by EU NCAs is no longer theoretical. What EU-licensed fintechs are learning about supervisory patterns and regulatory consequences in 2025.

---

**Last reviewed: 11 August 2026**

**Key takeaways**

- DORA has been in application since 17 January 2025; EU National Competent Authorities are running supervisory reviews now, and Article 50 administrative sanctions are available from that date.
- Supervision examines whether the ICT risk framework operates, not whether documents exist — the most common tool is the supervisory questionnaire, with on-site inspection powers exercised by competent authorities under DORA and their sectoral supervisory mandates.
- Three failure patterns recur in early reviews: nominal ICT risk ownership, third-party register gaps (Article 28), and management body accountability gaps (Article 5).
- A remediation order to a peer in the same regulatory perimeter is a direct activation signal — DORA enforcement is not a future risk category.

---

DORA entered into application on 17 January 2025. EU National Competent Authorities have been conducting supervisory reviews since then, and the pattern from early supervisory activity is consistent: NCAs examine whether the ICT risk management framework operates, not merely whether documents exist. For EU-licensed fintechs that approached DORA readiness as a documentation project, the supervisory experience of peers is becoming a direct activation signal.

This article covers the legal basis for DORA enforcement, what enforcement powers NCAs hold, what patterns are emerging from early supervisory reviews across EU-licensed fintechs, and what the enforcement picture means for EMIs, Payment Institutions, and CASPs planning their ICT risk programmes in 2025 and 2026.

The peer enforcement signal carries weight beyond its immediate regulatory context. When a National Competent Authority issues a remediation order to a licensed fintech in the same regulatory perimeter, boards and compliance functions at comparable entities re-examine their own ICT risk programmes. That reexamination is appropriate. DORA enforcement is not a future risk category.

{/* [HUMAN-FILL: anonymized peer-enforcement vignette — category (EMI/PI/CASP) + regulator-as-subject + outcome, C-1 name-scan before publish. Natural slot: one anonymized case of a remediation order or supervisory finding at a comparable entity and how a peer in the same perimeter responded. Reinforces the peer-awareness angle. No client name, no fabricated numbers/sanctions ([live-check]). */}

---

## The legal basis for DORA enforcement

DORA Chapter VII (Articles 46-56) establishes the supervisory and enforcement framework. Article 46 requires each EU member state to designate one or more National Competent Authorities responsible for DORA supervision. For most EU-licensed fintechs, the NCA is the financial regulator that issued the licence: Latvijas Banka for Latvia-licensed entities, Lietuvos bankas for Lithuania-licensed EMIs and PIs, the Central Bank of Cyprus for Cyprus-licensed EMIs and payment institutions (and CySEC for CASPs), the Central Bank of Ireland for Ireland-based entities.

DORA Article 50 sets out the administrative sanctions available to NCAs. These include supervisory letters requiring remediation of specific deficiencies, orders to cease non-compliant conduct, mandatory measures to bring the ICT risk management framework into compliance, and financial sanctions for persistent or serious breaches.

DORA proportionality provisions (Article 4) mean that microenterprises face a different supervisory threshold than larger financial entities, but no licence category is outside the supervisory perimeter for DORA ICT risk obligations. Proportionality affects how requirements are calibrated; it does not suspend the core obligations of DORA Title II.

---

## What enforcement powers NCAs hold under DORA

Beyond the formal sanctions framework, DORA gives NCAs a range of supervisory tools that carry significant operational weight without reaching formal enforcement.

The most commonly deployed tool in early DORA supervisory activity is the supervisory questionnaire: a structured document request under which the NCA asks the entity to demonstrate the operational state of its ICT risk management framework against specific DORA articles. A questionnaire response that reveals gaps typically triggers a follow-up: a remediation request, a supervisory meeting, or in more serious cases a formal supervisory examination.

Competent authorities exercise on-site inspection powers under DORA Chapter VII and their sectoral supervisory mandates. For EU-licensed fintechs that have not structured their ICT risk evidence package for supervisory presentation, an on-site inspection carries significant preparation burden. The inspection covers the same areas as a structured questionnaire but with direct review of systems, records, and management body documentation.

Article 48 establishes cooperation between competent authorities, including the exchange of supervisory information; DORA also provides for cooperation with the European Supervisory Authorities (EBA, ESMA, EIOPA) and, under Article 47, with the structures established by the NIS2 Directive. For fintechs operating across multiple EU jurisdictions, a finding in one jurisdiction can inform supervisory attention in another. The coordination architecture is designed for this.

---

## Patterns in early DORA supervisory activity

The EBA's supervisory convergence program under DORA has produced published guidance on supervisory expectations across member states. This convergence effort means that NCAs are examining similar areas with comparable frameworks, even where their specific questionnaire formats differ. The pattern from early DORA supervisory reviews across EU-licensed fintechs points to three recurring areas where ICT risk frameworks fail under scrutiny. The canonical catalogue of what NCAs examine and the findings they issue is set out in the [DORA supervisory review guide →](/dora-supervisory-review); the focus here is narrower — how the enforcement experience of peers in the same regulatory perimeter becomes the activation signal that moves these patterns up a board's agenda.

**Nominal ICT risk ownership.** The ICT risk management framework exists on paper. The function is assigned to a title in the organisation chart. Under supervisory questioning, the entity cannot demonstrate who performed the Article 8 asset identification review in the past quarter, when the ICT risk register was last updated, or who classified the last ICT incident against the DORA classification criteria (Article 18). The function is designated but not operating.

This is the pattern covered in detail in [DORA ICT risk ownership: why compliance alone falls short →](/dora-ict-risk-ownership). It is also the most common source of supervisory findings in early DORA reviews: not missing documentation, but documentation that cannot be connected to an active, ongoing function.

**Third-party register gaps.** DORA Article 28(3) requires a register of all third-party ICT providers; Article 29 requires concentration risk to be assessed. Many entities that completed a DORA gap assessment in 2024 built this register at the time of the advisory engagement. When the NCA examines the register in 2025, it reflects the vendor landscape as it was at the point of the engagement. New cloud services, SaaS tools, and outsourced technical functions adopted since then are absent from the register. Concentration risk was assessed once, not maintained as the vendor landscape evolved.

The register maintenance obligation is continuous under Article 28(3). Supervisors examine not only whether the register exists but whether it reflects the current state of ICT dependencies, including subcontractor chains.

**Management body accountability gaps.** DORA Article 5(2) requires the management body to approve the ICT risk management framework. Article 5(4) requires management body members to maintain updated knowledge of ICT risks. NCAs examine board minutes, management reporting records, and evidence of ICT risk training. Entities that cannot show ongoing management body engagement with ICT risk matters, beyond an annual policy sign-off, generate findings under Article 5.

These three patterns share a common root: the DORA programme was designed as a compliance exercise, completed at a point in time, and not transitioned to a continuously operating function. A gap assessment is a starting point. Under DORA Title II, the function must remain active between assessments, not re-engage when the next advisory engagement or supervisory notice arrives.

---

## What the enforcement picture means for EU-licensed fintechs

DORA enforcement is in its early phase, and the full scope of supervisory actions across the EU will become clearer as NCAs publish annual supervisory reports and the EBA releases supervisory convergence assessments. What is already evident from early supervisory activity is that the attention is real, active, and focused on operational substance.

For EU-licensed fintechs that have not yet completed a DORA gap assessment, the enforcement picture adds urgency. NCAs are examining ICT risk frameworks under active supervisory programmes, and entities without evidence of a functional ICT risk programme face direct exposure if a supervisory questionnaire arrives.

For fintechs that completed a gap assessment but have not transitioned to ongoing ICT risk governance, the three patterns above are directly relevant. Nominal ownership, third-party register gaps, and management accountability gaps are identifiable and remediable without waiting for an NCA notice. The enforcement experience of peers in the same regulatory perimeter is the clearest signal that the transition from compliance project to operating function cannot wait.

For fintechs with a functional ICT risk programme in place, the enforcement context underlines the value of maintaining the evidence package for supervisory presentation. A current ICT risk register, documented management body engagement with ICT risk decisions, an updated third-party register with concentration risk assessment, and classification records for ICT incidents are the four evidence categories NCAs focus on in early reviews.

---

## What to do before a DORA supervisory questionnaire arrives

The most effective preparation for DORA supervisory scrutiny is not additional documentation. It is a functional ICT risk programme with evidence of continuous operation.

The three areas generating findings in early DORA supervisory reviews correspond to three specific preparatory actions:

- On nominal ownership: confirm that the person or team responsible for the ICT risk function has performed the Article 8 asset identification review in the past quarter, that the ICT risk register has been updated with changes in the entity's ICT environment, and that a documented ICT risk report has been delivered to the management body in the past reporting period.

- On third-party register gaps: review the register of ICT providers against the current vendor landscape. Add any services adopted since the last advisory engagement. Assess concentration risk against the updated register, not the register as it was at gap assessment time.

- On management body accountability: confirm that board minutes or equivalent documentation record management body review of ICT risk reports and decisions on material ICT risks. Confirm that management body members can attest to having received ICT risk training or updates within the past year.

The [DORA supervisory review guide →](/dora-supervisory-review) covers what NCAs examine in detail. For the obligations baseline, see [DORA requirements overview →](/dora-requirements-2025). For the most common patterns that generate findings, see [common DORA compliance mistakes →](/mistakes-in-dora-compliance).

For jurisdiction-specific supervisory expectations from [Latvijas Banka, the Latvian National Competent Authority](/dora-bank-of-latvia), and [Lietuvos bankas, the Lithuanian National Competent Authority](/dora-bank-of-lithuania): both NCAs are actively supervising DORA ICT risk programmes at EU-licensed fintechs and their expectations are consistent with DORA Title II requirements and EBA supervisory convergence guidance.

---

## Frequently asked questions

### Has DORA enforcement started in the EU?

DORA entered into application on 17 January 2025. EU NCAs have been conducting supervisory questionnaires and reviews since then. While formal enforcement actions with published sanctions are still emerging in the public record, supervisory reviews are active across multiple EU member states. EU-licensed fintechs should treat DORA compliance as an active regulatory obligation, not a future commitment.

### What can an NCA do under DORA if a fintech is not compliant?

Under DORA Article 50, NCAs can issue supervisory letters requiring remediation, orders to cease non-compliant conduct, mandatory measures to bring the ICT risk framework into compliance, and financial sanctions for serious or persistent breaches. Before reaching formal sanctions, NCAs typically issue supervisory questionnaires and remediation requests. The escalation path from questionnaire to formal sanction can move quickly when the entity cannot demonstrate a responsive and functional programme.

### What are the most common findings in early DORA supervisory reviews?

Early DORA supervisory activity across EU-licensed fintechs points to three recurring areas: ICT risk functions designated in name only without evidence of continuous operation; third-party ICT provider registers that reflect the state at the last advisory engagement rather than the current vendor landscape; and management body accountability gaps where boards cannot demonstrate ongoing engagement with ICT risk matters beyond annual policy approvals.

### Does DORA enforcement apply to small fintechs?

DORA proportionality provisions (Article 4) allow microenterprises to apply certain requirements in a simplified manner. Proportionality does not exempt any entity from the obligation to maintain a functional ICT risk management framework, manage ICT incidents, or oversee third-party ICT dependencies. NCAs apply proportionality in calibrating their supervisory approach, not in removing the core obligations of DORA Title II.

### When are DORA fines and sanctions expected?

DORA Article 50 sanctions are available to NCAs from the date of application (17 January 2025). Formal public enforcement actions with published sanctions typically follow an initial supervisory engagement period during which NCAs issue remediation requests and assess entity responses. Fintechs that engage constructively with supervisory requests and demonstrate a functioning ICT risk programme reduce their exposure to escalation toward formal sanctions.

---

## Preparing for DORA supervisory scrutiny

CyAdviso works with EU-licensed fintechs, including EMIs, Payment Institutions, and CASPs, to structure and operate the ICT risk management function under DORA. Based on engagements under EU financial-sector supervision, the most effective preparation for NCA scrutiny is a functional programme with evidence of continuous operation: current registers, documented management body engagement, and an evidence package structured for supervisory presentation.

Our work covers ICT risk function design, management body reporting structures, third-party register maintenance, and supervisory evidence package preparation.

To discuss your DORA ICT risk programme before a supervisory questionnaire arrives, [schedule a consultation with CyAdviso](https://cal.com/andrey-gubarev/15min) or contact us at info@cyadviso.com.

---

Authored by Andrey Gubarev — CISO for EU fintechs (CISM, CDPSE, SABSA).
CyAdviso · DORA / ICT risk / vCISO programmes for EU-licensed fintechs.
Canonical HTML: https://www.cyadviso.com/dora-enforcement-2025
