ServiceNow® Partner & first UK VORTIQ-X Implementation PartnerLearn more →
← Back to Insights
Regulation

DORA in 2025: What Financial Firms Must Do Before June

Mar 2026 · 10 min read
DORA in 2025: What Financial Firms Must Do Before June

The Digital Operational Resilience Act (DORA) has been in force since January 2025, yet many firms are still treating it as a compliance checkbox rather than an operating model change. That gap is precisely where regulators are focusing their attention in supervisory reviews.

The requirement causing the most difficulty is the register of information for ICT third-party arrangements. This isn't a simple vendor list — it requires mapping every ICT service to the business function it supports, the criticality of that function, and the sub-outsourcing chain beneath the direct vendor. Firms attempting this in Excel are finding it unmanageable at scale.

ICT risk management is the second major pillar. DORA expects a documented ICT risk management framework covering identification, protection, detection, response, and recovery — mapped explicitly to your critical and important functions. On ServiceNow, this maps naturally onto the IRM and Risk Management applications, using the CMDB as the single source of truth for what's actually in scope.

Incident reporting timelines are strict and unforgiving: major ICT-related incidents must be reported to the relevant competent authority within tight statutory windows. Firms need automated workflows that classify incidents against DORA's severity criteria the moment they're logged, not a manual triage process that risks missing the deadline.

Digital operational resilience testing — including threat-led penetration testing (TLPT) for the most significant entities — needs to be tracked, evidenced, and linked back to the risks it's testing. Treating testing as a standalone exercise, disconnected from the risk register, is a common gap we see in maturity assessments.

If you haven't yet mapped your organisation against these five pillars, our free Regulatory Scoping Assessment identifies exactly where DORA applies to you and what a ServiceNow-based remediation plan looks like.

Book a Workflow Review →