DORA & ransomware: what EU financial firms must prove now
Key takeaways
- DORA shifts the standard from 'have a policy' to 'prove you can withstand and recover,' with specific testing and reporting duties.
- Firms need dated evidence — executed resilience tests, a third-party ICT risk register, and reporting processes that meet the timelines.
- For most mid-sized firms the gap is documentation and rehearsal, not strategy.
From 'have a policy' to 'prove you can recover'
The Digital Operational Resilience Act reshapes how EU financial services firms must approach ransomware readiness — shifting from a 'have a policy' standard to a 'prove you can withstand and recover' standard, with specific testing and reporting obligations. It's less about writing new documents and more about demonstrating, with evidence, that your resilience is real.
What you actually have to demonstrate
In practice, this means firms need documented, regularly executed resilience testing (including scenario-based testing that maps closely to a ransomware event), a formal ICT third-party risk register covering the vendors and providers who could bring an incident to your door, and incident classification and reporting processes that can meet DORA's reporting timelines under real pressure. Each of these has to be evidenced, not asserted.
The gap is evidence, not strategy
For most mid-sized firms, the gap isn't strategy — it's evidence. Regulators want to see tested playbooks and dated records of tabletop exercises, not a resilience policy that has never been rehearsed. If you can produce the incident-response plan but not the record of the last time you exercised it, DORA's standard treats that as the gap it is. The work is to turn intentions into a documented, dated, repeatable trail.