Financial services resilience
What Irish Financial Firms Need to Know About DORA Compliance
DORA compliance has been a binding legal obligation for Irish financial firms since 17 January 2025, and the Central Bank of Ireland supervises it directly. Supervisors no longer just want frameworks and policies. They want evidence that those frameworks actually work when a supplier goes down at 3am on a Friday.
The clock starts at classification. The initial notification of a major ICT incident is due within 4 hours, capped at 24 hours from awareness.
In short
Overview
DORA compliance has been a binding legal obligation for Irish financial firms since 17 January 2025, and the Central Bank of Ireland supervises it directly. The Digital Operational Resilience Act sets out one EU-wide rulebook covering ICT risk management, incident reporting, resilience testing, third-party risk and information sharing.
What has changed since then is the nature of the question being asked. In the first year, supervisors wanted to see frameworks, policies and a completed gap analysis. Now they want evidence that those frameworks actually work when a supplier goes down at 3am on a Friday.
This guide covers who the regulation captures, the two reporting obligations that generate the most findings, where the Central Bank says Irish firms are still weak, and what to fix before the next supervisory engagement.
Scope
Which Irish Firms Fall Under DORA Compliance?
DORA applies to almost every regulated financial entity in Ireland. That includes banks, payment and e-money institutions, investment firms, fund managers and administrators, insurers and reinsurers, crypto-asset service providers and credit rating agencies.
The Central Bank is the competent authority for in-scope entities, with institutions for occupational retirement provision supervised separately by the Pensions Authority. You can confirm your own position against the Central Bank's DORA regulatory hub before assuming any exemption applies.
Scale changes the weight of the obligations, not whether they exist:
- Microenterprises and certain smaller entities can apply a simplified ICT risk management framework under Article 16.
- Every in-scope entity, regardless of size, must maintain a Register of Information and report major incidents.
- Only entities identified by the Central Bank carry out advanced threat-led penetration testing, and that identification exercise runs annually.
- Group membership does not remove entity-level obligations. Each authorised entity answers for itself.
The framework
What DORA Requires Across Its Five Pillars
DORA builds on five pillars, each with its own articles and its own supporting technical standards. Most of those standards have applied since January 2025, with the RTS on subcontracting of critical or important functions finalised in July 2025.
| Pillar | Articles | What a supervisor expects to see |
|---|---|---|
| ICT risk management | 5 to 16 | An approved framework, a digital operational resilience strategy, named senior ownership |
| Incident management and reporting | 17 to 23 | Classification thresholds defined, triage that runs to the clock, reports filed on time |
| Resilience testing | 24 to 27 | A testing programme tied to critical or important functions, remediation tracked to closure |
| ICT third-party risk | 28 to 30 | A complete register, criticality rationale, DORA clauses in contracts, exit plans |
| Information sharing | 45 | Arrangements documented where the firm participates |
The testing and third-party pillars are where paper and practice diverge most often. A recovery time objective written into a policy means little if nobody has tested a restore against it, which is why evidence of managed backup and recovery testing tends to be requested early in supervisory engagement.
Reporting clocks
How Major ICT Incidents Must Be Reported to the Central Bank
The clock starts when you classify an incident as major, not when you finish investigating it. The initial notification is due within 4 hours of that classification, and in any case no later than 24 hours after the firm became aware of the incident.
| Report | Deadline | Clock starts from |
|---|---|---|
| Initial notification | 4 hours | Classification as major, capped at 24 hours from awareness |
| Intermediate report | 72 hours | Submission of the initial notification |
| Final report | One month | The latest intermediate report |
Classification itself follows the materiality criteria in Delegated Regulation (EU) 2024/1772, covering clients affected, data losses, service downtime, geographic spread, economic impact and the criticality of the services hit.
Reports go through the Central Bank Portal using the ESA templates, so the practical constraint is triage speed rather than form-filling.
Annual submission
What the Register of Information Requires Every Year
The Register of Information is an annual submission documenting every contractual arrangement for ICT services, filed in xBRL-CSV format through the Central Bank Portal. For the 2026 cycle, the window ran from 2 March to 31 March 2026, with a reporting date of 31 December 2025.
It is the single most scrutinised artefact under the regulation, and the most common source of resubmission requests. The recurring problems are structural rather than cosmetic:
- Sub-outsourcing chains stopping at tier one, so the provider behind the provider is invisible.
- Arrangements classified as non-critical with no documented rationale.
- Missing or placeholder identifiers where a valid LEI or EU-ID is required.
- Free-text entries where the EBA data point model expects a defined code.
- Registers maintained in spreadsheets that cannot produce a valid regulatory filing.
Treat it as a data quality exercise with a hard deadline. The register is also the dataset the European Supervisory Authorities mine to decide which providers get designated as critical, so its accuracy has consequences well beyond your own filing.
The downside
What Happens If a Firm Fails to Meet DORA Compliance
Ireland gave the regulation teeth through S.I. No. 20 of 2025, which allows the Central Bank to apply its administrative sanctions regime under the Central Bank Act 1942 to breaches. Reported caps run to €10 million or 10% of annual turnover for a firm, whichever is higher, and up to €1 million for an individual in a controlled function.
Fines are the far end of the scale and not the realistic near-term risk. What arrives first is supervisory pressure, which costs time and credibility rather than cash:
- Findings letters with fixed remediation deadlines.
- Risk mitigation programmes that pull senior people off revenue work.
- Requests for evidence at a level of detail most firms cannot produce quickly.
- Escalated scrutiny of authorisation applications and change requests.
Practical steps
How to Close DORA Gaps Before the Next Supervisory Review
Start from evidence rather than documentation. If you cannot produce the artefact a supervisor would ask for, the gap is real regardless of what the framework says.
- Identify your critical or important business services and map every system and supplier behind each one.
- Run a real incident drill against the 4-hour clock, including out-of-hours classification authority.
- Re-test the register for sub-outsourcing depth, identifiers and criticality rationale well before the next submission window.
- Test a restore against your stated recovery objectives and keep the output.
- Put ICT risk on the board agenda as a standing item with named ownership.
- Reassess concentration risk across designated critical providers and document the conclusion.
Most of the remaining work is operational rather than legal, and it needs people who understand both the regulation and the estate it applies to. We work with regulated Irish firms on DORA, NIS2 and Central Bank ICT risk expectations, alongside day-to-day IT support for financial services firms.
Frequently asked questions
DORA compliance questions from Irish firms.
When did DORA start applying to Irish financial firms?
DORA has applied since 17 January 2025, with no transitional period. The majority of supporting technical standards took effect on the same date, and the RTS on subcontracting of critical or important functions was finalised in July 2025.
Does DORA apply to small financial firms in Ireland?
Yes. Size affects how obligations are applied, not whether they apply. Microenterprises and certain smaller entities can use a simplified ICT risk management framework, but every in-scope entity must still maintain a Register of Information and report major incidents.
How quickly must a major ICT incident be reported?
The initial notification is due within 4 hours of classifying the incident as major, and no later than 24 hours after becoming aware of it. An intermediate report follows within 72 hours, and a final report within one month of the latest intermediate report.
What is the Register of Information?
It is an annual submission listing every contractual arrangement for ICT services, including criticality, the functions supported and the sub-outsourcing chain. It is filed in xBRL-CSV format through the Central Bank Portal during a set window each year.
Is DORA the same as NIS2?
No. They are separate regimes with different scopes. For financial entities inside DORA's scope, DORA takes precedence on ICT risk and incident reporting, though group companies outside that scope may still fall under NIS2 obligations.
Can an IT provider make a firm compliant on its own?
No. Responsibility sits with the regulated entity and its management body, and it cannot be outsourced. A provider can build and evidence the technical controls, run testing and maintain register data, but accountability for the framework stays with the firm.