Meta Description: Prepare for the DORA 2026 reporting deadlines. Learn the exact timelines for major ICT incidents and Register of Information submissions under EU 2022/2554.
DORA Reporting Deadlines: Compliance Guide for Financial Entities in 2026
Last updated: October 2026 | Author: Gerard Maymó, Founder | Reviewed by: Dr. Elena Vancea, Head of RegTech Compliance | Sources: European Supervisory Authorities (ESAs) Joint Committee, Regulation (EU) 2022/2554
Direct answer: Under the Digital Operational Resilience Act (DORA), financial entities must submit their first official Register of Information on third-party ICT providers by 17 January 2025, with the first continuous reporting cycle for major ICT incidents and threat-led penetration testing (TLPT) fully operational throughout 2026. In this article, we break down the critical regulatory deadlines, technical standards, and compliance milestones that banks, investment firms, and insurance undertakings must meet to avoid severe administrative penalties.
The transition from implementation to active enforcement marks 2026 as the most critical year for operational resilience in the European financial sector. Regulatory bodies are moving away from grace periods, meaning that compliance officers must establish bulletproof, repeatable reporting pipelines. For organisations operating across borders, understanding the precise timelines mandated by the European Supervisory Authorities (ESAs)—consisting of EBA, EIOPA, and ESMA—is no longer a theoretical exercise; it is an active operational necessity.
The Regulatory Landscape: DORA Article 20 and Article 28
The Digital Operational Resilience Act (Regulation (EU) 2022/2554) restructures how the financial sector manages Information and Communication Technology (ICT) risk. Specifically, DORA mandates a unified reporting framework for major ICT-related incidents and a structured register for all third-party ICT service contracts.
While the regulation officially entered into force in early 2025, the Regulatory Technical Standards (RTS) finalized by the ESAs dictate the exact reporting cadences for 2026. Financial entities must align their internal risk management systems with two primary pillars:
- Article 20 (Incident Reporting): The obligation to detect, manage, and report major ICT-related incidents to national competent authorities (NCAs) within hours of classification.
- Article 28 (Register of Information): The requirement to maintain and submit an annual registry detailing all contractual arrangements with ICT third-party service providers, distinguishing those supporting critical or important functions (CIFs).
To understand how these requirements fit into your broader compliance architecture, you can review our DORA ICT risk framework analysis, which covers the foundational pillars of risk management under this regulation.
DORA Compliance Calendar: Key Milestones for 2026
The following timeline outlines the mandatory compliance milestones that financial entities must observe throughout 2026. Failure to meet these dates can result in periodic penalty payments of up to 1% of the average daily global turnover of the preceding business year.
| Deadline / Period | Requirement | Scope of Application | Regulatory Reference |
|---|---|---|---|
| Continuous (Daily) | Major ICT Incident Reporting (Initial, Intermediate, Final) | All covered financial entities | DORA Article 20 / RTS JC 2024 33 |
| Q1 2026 | First audited Register of Information submission to NCAs | All entities utilizing third-party ICT services | DORA Article 28(3) / ITS JC 2023 84 |
| Bi-Annual / Annual | Board-level review of ICT risk appetite and vulnerability reports | Board of Directors / Management Body | DORA Article 5 |
| As Designated (3-Year Cycle) | Threat-Led Penetration Testing (TLPT) execution and reporting | Significant financial entities designated by NCAs | DORA Article 26 / RTS JC 2024 29 |
Managing these diverse deadlines requires a systematic approach to regulatory technology. If your organisation is also navigating other European frameworks, understanding the differences between NIS2 and DORA is crucial to avoid redundant reporting structures and overlapping compliance efforts.