DORA’s Continuous Monitoring in Practice
Navigating the DORA compliance blockers holding security leaders back
A practical DORA compliance guide for CISOs, GRC leaders, and controls assurance teams on where continuous monitoring stands one year into enforcement.
The DORA Reality Check: Where compliance stands one year into enforcement
As we pass the first anniversary of DORA (Digital Operational Resilience Act) enforcement, the financial services industry faces an uncomfortable compliance truth. Only 32% of regulated financial entities fully comply with all DORA compliance requirements, while 40% are only partially fulfilling their obligations, according to KPMG's analysis of EU financial institutions. More concerning, 43% of UK financial services institutions missed last year's DORA compliance deadline entirely. Yet the European Supervisory Authorities made their expectations clear in December 2024. National authorities across the EU - from Austria's FMA to Ireland's CBI - are already actively conducting supervisory visits and enforcement actions. The countdown is over - the spotlight is now firmly on how well organization’s can evidence DORA compliance. The regulators are no longer watching the clocking, they’re watching your controls, your continuous monitoring approaches and your controls assurance practices. For CISOs and their teams, the realities of DORA represent more than just a compliance checkbox exercise. It’s driving a fundamental redesign of how financial institutions approach risk visibility, control architecture, and operational resilience. It's a structural shift in how you operate. This guide examines the five biggest compliance blockers that security leaders face right now and provides strategic, actionable guidance for overcoming them, with particular focus on Critical or Important Functions (CIFs) and the role of continuous controls monitoring in evidencing ICT control effectiveness.
DORA timeline
16th January 2023
DORA enters into force, kick-starting a two-year implementation period
17th January 2024
Regulatory technical standards (RTS) and Implementing technical standards (ITS) released covering DORA ICT risk management, incident reporting, and testing
17th July 2024
Further standards released, including an oversight framework for Critical ICT Third-Party Providers (CITPPs)
17th January 2025
DORA becomes fully applicable
April 2025
First cases of authorities using on-site inspection and information requests to assess DORA compliance and continuous controls monitoring practices
October 2025
DORA penalty frameworks finalized and fully operational across member states