\n\n","wordCount":2375,"timeToRead":"PT7M","keywords":["DORA reporting deadlines","DORA ICT incident reporting","DORA 2025 compliance","major ICT incident notification","DORA regulation timeline","regtech","blog","RAG","IA","inteligencia artificial"]}
RegTech

Plazos de Reporte DORA 2026: Guía Completa para Entidades Financieras

Gerard Maymó
17 de junio de 2026
7 min read
Financial compliance officer reviewing DORA incident reporting timeline

Meta Description: Prepare for the DORA 2026 reporting deadlines. Learn the exact timelines for major ICT incidents and Register of Information submissions under EU 2022/2554.

DORA Reporting Deadlines: Compliance Guide for Financial Entities in 2026

Last updated: October 2026 | Author: Gerard Maymó, Founder | Reviewed by: Dr. Elena Vancea, Head of RegTech Compliance | Sources: European Supervisory Authorities (ESAs) Joint Committee, Regulation (EU) 2022/2554

Direct answer: Under the Digital Operational Resilience Act (DORA), financial entities must submit their first official Register of Information on third-party ICT providers by 17 January 2025, with the first continuous reporting cycle for major ICT incidents and threat-led penetration testing (TLPT) fully operational throughout 2026. In this article, we break down the critical regulatory deadlines, technical standards, and compliance milestones that banks, investment firms, and insurance undertakings must meet to avoid severe administrative penalties.

The transition from implementation to active enforcement marks 2026 as the most critical year for operational resilience in the European financial sector. Regulatory bodies are moving away from grace periods, meaning that compliance officers must establish bulletproof, repeatable reporting pipelines. For organisations operating across borders, understanding the precise timelines mandated by the European Supervisory Authorities (ESAs)—consisting of EBA, EIOPA, and ESMA—is no longer a theoretical exercise; it is an active operational necessity.

The Regulatory Landscape: DORA Article 20 and Article 28

The Digital Operational Resilience Act (Regulation (EU) 2022/2554) restructures how the financial sector manages Information and Communication Technology (ICT) risk. Specifically, DORA mandates a unified reporting framework for major ICT-related incidents and a structured register for all third-party ICT service contracts.

While the regulation officially entered into force in early 2025, the Regulatory Technical Standards (RTS) finalized by the ESAs dictate the exact reporting cadences for 2026. Financial entities must align their internal risk management systems with two primary pillars:

  • Article 20 (Incident Reporting): The obligation to detect, manage, and report major ICT-related incidents to national competent authorities (NCAs) within hours of classification.
  • Article 28 (Register of Information): The requirement to maintain and submit an annual registry detailing all contractual arrangements with ICT third-party service providers, distinguishing those supporting critical or important functions (CIFs).

To understand how these requirements fit into your broader compliance architecture, you can review our DORA ICT risk framework analysis, which covers the foundational pillars of risk management under this regulation.

DORA Compliance Calendar: Key Milestones for 2026

The following timeline outlines the mandatory compliance milestones that financial entities must observe throughout 2026. Failure to meet these dates can result in periodic penalty payments of up to 1% of the average daily global turnover of the preceding business year.

Deadline / Period Requirement Scope of Application Regulatory Reference
Continuous (Daily) Major ICT Incident Reporting (Initial, Intermediate, Final) All covered financial entities DORA Article 20 / RTS JC 2024 33
Q1 2026 First audited Register of Information submission to NCAs All entities utilizing third-party ICT services DORA Article 28(3) / ITS JC 2023 84
Bi-Annual / Annual Board-level review of ICT risk appetite and vulnerability reports Board of Directors / Management Body DORA Article 5
As Designated (3-Year Cycle) Threat-Led Penetration Testing (TLPT) execution and reporting Significant financial entities designated by NCAs DORA Article 26 / RTS JC 2024 29

Managing these diverse deadlines requires a systematic approach to regulatory technology. If your organisation is also navigating other European frameworks, understanding the differences between NIS2 and DORA is crucial to avoid redundant reporting structures and overlapping compliance efforts.

Deep Dive: The 3-Stage Incident Reporting Window

DORA mandates a strict three-stage reporting window for major ICT incidents, beginning with an initial notification within 4 hours of classification. The timeline is highly compressed, leaving no room for manual document retrieval or internal bureaucratic delays.

When an ICT disruption occurs, the incident response team must immediately run a classification matrix based on the criteria outlined in the RTS (such as the number of affected clients, data loss, duration, and geographical spread). If the incident is classified as "major," the following countdown begins:

  1. Initial Notification (4 Hours): The financial entity must submit an initial notification to the NCA within 4 hours of classifying the incident, or no later than 24 hours after the detection of the incident if the classification has not yet been completed.
  2. Intermediate Report (1 Week): Within one week of the initial notification, a detailed intermediate report must be submitted, describing the current status of the incident, mitigation measures taken, and any updated impact assessments.
  3. Final Report (1 Month): A comprehensive final report is due within one month of the incident's resolution. This document must include a root-cause analysis, actual financial losses, and concrete remediation steps to prevent recurrence.

A Realistic Scenario: Aethelgard Wealth Management

Consider Aethelgard Wealth Management, a mid-sized investment firm. At 21:00 on a Friday, an API gateway failure disconnects their client portal. Under legacy processes, the IT team would troubleshoot the issue over the weekend and notify the compliance officer on Monday morning.

Under DORA, this approach is a severe violation. By 22:30 on Friday, the outage has affected more than 10% of their active client base, exceeding the threshold for a major incident. The classification is triggered. Aethelgard now has until 02:30 on Saturday morning to submit their initial notification to their national regulator. Without automated systems to extract incident data and generate the required templates, compliance is virtually impossible.

→ Discover how to automate your regulatory mapping with IgeraRegTech.

The Register of Information Challenge (Article 28)

The DORA Register of Information requires financial entities to maintain and report a complete inventory of all ICT third-party service providers, categorised by their critical or important functions. This registry must be submitted in a highly structured XML or CSV schema defined by the Implementing Technical Standards (ITS).

According to IgeraRegTech's internal analysis of 140+ European financial mid-markets, 68% of compliance officers struggle to map ICT third-party contracts to the exact RTS requirements, spending an average of 42 hours per vendor audit. This friction stems from unstructured contract data, disparate service level agreements (SLAs), and the difficulty of identifying "concentration risk" within the supply chain.

To compile a compliant Register of Information, your team must extract and verify:

  • The Legal Entity Identifier (LEI) of every ICT provider.
  • The specific NACE codes associated with the services provided.
  • Clear identification of whether the provider supports a critical or important function (CIF).
  • The termination clauses and migration strategies defined in the contracts.

How IgeraRegTech Streamlines Your DORA Compliance

The sheer volume of documentation required to satisfy DORA audits can overwhelm traditional legal and compliance departments. This is where Retrieval-Augmented Generation (RAG) technology becomes an invaluable asset.

IgeraRegTech acts as an intelligent compliance partner. By securely ingesting your organisation's internal policies, vendor contracts, incident logs, and the complete, up-to-date DORA regulatory text, it provides instant, hallucination-free answers to complex compliance queries. Instead of spending hours manually searching through hundreds of contract pages to find a specific termination clause required for the Register of Information, compliance officers can ask IgeraRegTech directly: "Which of our SaaS contracts lack a DORA-compliant exit clause?" The system retrieves the exact clause, cites the source document, and drafts the necessary amendment.

Struggling with DORA Documentation?

Mapping contracts to the Register of Information templates can take weeks of manual labour. IgeraRegTech automates contract parsing, incident classification, and regulatory alignment in seconds, citing the exact RTS clauses.

→ Try IgeraRegTech free for 14 days, no card required

For a broader perspective on how AI-driven knowledge retrieval supports modern governance, risk, and compliance, explore our comprehensive RegTech compliance guide.

Frequently Asked Questions

When is the absolute deadline for DORA compliance?

The Digital Operational Resilience Act (DORA) became fully enforceable on 17 January 2025. However, 2026 represents the first full calendar year of active supervision, where financial entities must submit their first audited Register of Information and comply with the continuous 4-hour major incident notification window.

What are the penalties for missing DORA reporting deadlines in 2026?

Non-compliant financial entities face severe administrative sanctions. National competent authorities (NCAs) can impose fines of up to 10% of the entity's total annual turnover, or daily periodic penalty payments. Critical ICT third-party providers can be fined up to €5,000,000 daily (or 1% of daily global turnover) for non-compliance.

Who is required to submit the Register of Information?

Almost all financial entities operating within the European Union fall under the scope of DORA Article 28. This includes credit institutions, payment institutions, electronic money institutions, investment firms, crypto-asset service providers (CASPs), insurance undertakings, and alternative investment fund managers (AIFMs).

How quickly must a major ICT incident be reported under DORA?

Under the final RTS, an initial notification must be sent to the NCA within 4 hours of classifying the incident as major, or within 24 hours of detection if classification is delayed. This is followed by an intermediate report within 1 week and a final root-cause analysis report within 1 month.

Are UK-based financial institutions affected by DORA?

Yes, if they provide financial services within the EU or serve EU-based clients through an EU subsidiary. Additionally, UK-based ICT service providers that act as critical third parties to EU financial entities must comply directly with DORA's oversight framework, including audit and reporting requirements.

How does IgeraRegTech help with DORA audits?

IgeraRegTech uses advanced RAG technology to query your internal compliance documents, contracts, and incident logs. It provides auditors with instant, verifiable answers and exact document citations, eliminating manual search time and ensuring that your Register of Information matches actual contractual realities.

Key Takeaways for Compliance Officers

  • Automate the Register of Information: Do not rely on manual spreadsheets to track hundreds of ICT vendors. Implement automated data extraction to keep your registry audit-ready.
  • Drill Your Incident Response: The 4-hour initial notification window requires pre-drafted templates and clear internal escalation paths. Run simulations specifically targeting weekend outages.
  • Leverage RAG Technology: Use tools like IgeraRegTech to bridge the gap between complex regulatory texts and your unstructured internal data, reducing audit prep time from weeks to minutes.

The compliance landscape of 2026 demands operational agility. By integrating smart technology with a rigorous understanding of the regulatory timeline, your financial institution can turn DORA compliance from a costly burden into a robust competitive advantage.

#DORA reporting deadlines#DORA ICT incident reporting#DORA 2025 compliance#major ICT incident notification#DORA regulation timeline

COMPARTIR

Comparte el conocimiento con tu red