In short
DORA readiness, covering ICT risk management, incident reporting, resilience testing and third-party oversight, is increasingly assessed as part of authorisation. Treating it as a post-launch project risks supervisory questions and delay. Build it into the application from the start.
DORA in the application
Supervisors expect demonstrable ICT governance, a register of information and resilience testing at authorisation.
Third-party risk
Critical ICT providers and outsourcing must be identified and overseen.
Practical approach
Align DORA evidence with the broader application so it is coherent and credible.
Related regime guide: AML & DORA
Official regulatory sources
Verified external references. Always confirm against the current official text.
RenIQ provides regulatory strategy and programme delivery. It is not a law firm and this content is illustrative guidance, not legal advice. Regime details are summaries that may change, so always verify against current rules and official sources, and take formal advice before acting.