Expert Insights

DORA Blog

Expert insights, compliance guides, and the latest updates on digital operational resilience

Get every new article in your inbox

2 issues a month. RTS releases, ESA Q&As, real cases. 3,000+ EU compliance professionals already subscribed.

No spam. Unsubscribe in 1 click. RGPD-compliant.

SBOM vs AI-Discovered Zero-Days: Your Fastest DORA Defence Third-Party Risk
June 8, 2026 9 min read

SBOM vs AI-Discovered Zero-Days: Your Fastest DORA Defence

When an AI can surface a 27-year-old vulnerability in hardened software, the question stops being “is our code secure?” and becomes “do we even know what is in it?” A Software Bill of Materials is now a frontline DORA control — here is how to operationalise it.

Software Supply Chain Security & SBOM Under DORA (2026) Third-Party Risk
June 8, 2026 8 min read

Software Supply Chain Security & SBOM Under DORA (2026)

Your fourth parties are now in scope. DORA pushes ICT risk down the subcontracting chain, and a Software Bill of Materials (SBOM) is how engineering teams make that chain visible. Here is how supply-chain security maps to DORA third-party obligations.

Chaos Engineering & Resilience Testing Under DORA (2026) Testing & Resilience
June 8, 2026 8 min read

Chaos Engineering & Resilience Testing Under DORA (2026)

DORA requires you to test resilience on critical systems — not assume it. Chaos engineering turns that obligation into evidence: deliberately injecting failure to prove your systems degrade and recover as designed. Here is how it maps to DORA Pillar 3.

Software Architecture Choices That Reduce ICT Risk Under DORA (2026) Risk Management
June 8, 2026 8 min read

Software Architecture Choices That Reduce ICT Risk Under DORA (2026)

Resilience is an architecture decision long before it is a compliance one. Here are the design patterns — redundancy, isolation, graceful degradation, immutable backups, observability — that lower ICT risk and map directly onto DORA Articles 9 to 12.

ISO 27001 to DORA: The Complete Mapping Guide (2026) Methodology
June 7, 2026 11 min read

ISO 27001 to DORA: The Complete Mapping Guide (2026)

If you already run an ISO 27001 ISMS, it is the fastest roadmap to DORA. This guide maps DORA to ISO 27001:2022 control-by-control, shows exactly what the standard does not cover, and gives the priorities and quick wins to close the gap.

Critical or Important Functions under DORA: the Term That Runs Everything (2026 Guide) Compliance
May 27, 2026 13 min read

Critical or Important Functions under DORA: the Term That Runs Everything (2026 Guide)

Almost every demanding obligation in DORA — TLPT scope, Article 30 contracts, the Register of Information, business continuity — keys off one defined term: the Critical or Important Function. Here is what Article 3(22) actually says, why CIF is the master switch, and a 5-step method to classify your functions defensibly.

DORA Register of Information: Your Q1 2026 Submission Guide Third-Party Risk
April 1, 2026 12 min read

DORA Register of Information: Your Q1 2026 Submission Guide

The Q1 2026 Register of Information submission is the most data-intensive compliance obligation under DORA — and the one regulators are scrutinising most closely. This guide covers the 15 templates, xBRL-CSV format requirements, country-specific deadlines, the most common errors from the 2025 first collection, and how to maintain a living register year-round.

DORA Enforcement 2026: The Grace Period Is Over Regulatory Updates
April 1, 2026 10 min read

DORA Enforcement 2026: The Grace Period Is Over

The informal tolerance period that characterised 2025 DORA supervision is finished. National competent authorities are now conducting active enforcement reviews, cross-checking Register of Information data automatically, and issuing the first compulsion payments. Here is what changed, what regulators are prioritising, and what your institution needs to do now.

Need Expert Guidance?

Download our comprehensive DORA compliance guide

Download PDF Guide

How Compliant Is Your Institution?

Take our free 5-minute assessment and get an instant DORA compliance score with personalised recommendations.

Get Your Free DORA Score Join Free Monthly Webinar