DORA compliance cleared the register, not the real test
The Dutch regulator did what regulators rarely do this early: it graded the class before exam season, and DORA compliance in the Netherlands is not the tidy pass rate the headline suggests.
By Katie Delaney · 2026-08-24 · 12 min read
What the AFM's own DORA compliance review actually found#
of firms' DORA information registers were accepted by the European Banking Authority in 2026, up from 40% in 2025
The fox does not applaud the first rustle in the hedgerow. It waits, catches the scent, watches the pattern repeat, then works out whether the sound means safety or a snare, and that patient prowl is exactly the discipline Dutch supervisors have just applied to DORA compliance across the country's financial sector. On 6 August 2026 the Autoriteit Financiele Markten (AFM) published its own supervisory update on the Digital Operational Resilience Act, first flagged for a wider legal audience by Norton Rose Fulbright's fintech team, and the headline number looks like good news: the share of firms' information registers accepted by the European Banking Authority rose from 40% in 2025 to 94% in 2026.
Read past the headline, though, and the report reads more like a hedgerow than a headline: thick in places, thin in others, and the thin patches are exactly where a fox would choose to slip through. The AFM found that not every firm has all the policies and procedures DORA compliance actually requires, that some existing policies do not fully match either the regulation or the firm's own daily operations, and that, as TradeInformer's own coverage of the update confirms, the regulator received fewer incident reports than it expected, a sign that detection and classification inside many firms still lag the letter of the law.
DORA, formally Regulation (EU) 2022/2554, has applied to the EU's banks, insurers, investment firms, payment institutions and crypto-asset providers since 17 January 2025. It asks a blunt question of every regulated firm: if your technology broke tomorrow, could you prove, in writing, that you saw it coming, reported it on time, and tested for it in advance? For a growing number of Dutch firms the honest answer, eighteen months in, is still 'nearly'.
National regulators across the EU, including the AFM, hold real teeth here. DORA's own penalty regime, mapped in detail by DLA Piper across every member state, lets a competent authority fine a firm up to 2% of annual worldwide turnover, with national ceilings running from EUR2 million in the Czech Republic to EUR20 million in Italy. folkfox reads the AFM's tone, patient rather than punitive so far, as the grace period's grey area rather than its end: the supervisory groundwork laid through 2025 and early 2026 is exactly the groundwork that tends to turn into the first formal DORA compliance fines once the second half of the year runs its course.
That climb is real progress, and folkfox will not pretend otherwise. But a register is a filing cabinet, not a live system, and the AFM's harder finding sits one layer down, in the policies and the ICT risk management practice a register can never fully capture on its own.
The ICT risk management pillars DORA actually tests#
DORA is not one rule, it is four interlocking ones, and the European Banking Authority names them plainly: ICT risk management, incident reporting, resilience testing, and third-party risk monitoring. The three European Supervisory Authorities, the EBA, ESMA and EIOPA, share the job of keeping those four pillars harmonised across roughly twenty categories of financial entity, from high-street banks to crypto-asset service providers, a scope Katten's own analysis puts at roughly 22,000 financial entities across the EU. Operational resilience is not a purely European invention either: practical guidance published in the British Actuarial Journal shows UK regulators reaching for the same discipline on their own track.
The den the whole regulation is built around#
ICT risk management sits underneath all three of the others, the den the whole regulation is built around. A firm that cannot map which servers, cloud services and vendors keep a critical function running cannot report an incident against that function accurately, cannot test it meaningfully, and cannot monitor the third party running it. That is the thicket the AFM's report describes: firms that built a register because a register was demanded, without first doing the ICT risk management groundwork the register was supposed to describe. It is a policy patchwork wearing a compliance costume.
Dutch firms reading this alongside folkfox's coverage of NIS2 compliance will recognise the shape: a second EU regime, a second register, a second sweep. DORA is narrower, financial services only, but sharper, because unlike the Cyber Resilience Act's product-safety lens, it grades an institution's whole operating model, not a single device.
Resilience testing is the pillar firms most often shortchange, because it is the one that costs money before it proves anything. Threat-led penetration testing on a three-year cycle sounds survivable until a firm notices the sentence sits inside a sector still tracking its own testing trail through server rooms and supplier contracts, a quiet quarry that is far bigger than any single audit.
Why compliance management tools became a boardroom line item#

Put four regulatory pillars, twenty entity types and a supervisor who cross-checks registers automatically in one filing cabinet, and you get exactly the problem folkfox's clients keep describing: the compliance management tools they bought for one regulation quietly buckle under a second. A spreadsheet register survives a first audit. It does not survive DORA compliance at scale, where policies, incidents, test results and third-party contracts all have to reconcile with each other on demand.
The AFM's own complaint, that group-level policies do not always reflect the requirements of the local licence holder, is a compliance management tools problem before it is a legal one. A platform that cannot show which policy version applies to which entity, in which jurisdiction, on which date, will fail exactly the check the AFM just ran. That is also why buyers researching compliance risk management software this year are asking harder questions than whether it has a dashboard: they want audit trails, entity-level policy mapping, and an incident workflow that meets DORA's statutory reporting clock, not a generic ticket queue wearing a compliance label.
| Member state | Maximum fine (legal entity) | Source |
|---|---|---|
| Czech Republic | EUR2 million absolute ceiling | DLA Piper |
| Spain | 5% of turnover or EUR5 million | DLA Piper |
| Belgium | EUR5 million or 10% of turnover | DLA Piper |
| Ireland | EUR10 million or 10% of turnover | DLA Piper |
| Sweden | 10% of turnover ceiling | DLA Piper |
| Italy | EUR20 million absolute ceiling | DLA Piper |
None of that is exotic. It is the same discipline folkfox already brings to content built for regulated buyers: name the number, link the source, let the reader check the working. A vendor selling compliance risk management software that cannot do the same for its own claims is asking a DORA-anxious compliance officer to take rather a lot on faith.
What DORA compliance means for the people who sell into it#
A register is a filing cabinet, not a live system. DORA compliance rewards the firms that can prove the difference in one sentence, not just one spreadsheet.
Somebody has to explain all of this to a board that does not read regulation for fun, and increasingly that somebody sits inside a marketing team, not just a GRC function. DORA compliance has become a genuine buying trigger: fintechs need to prove it to banking partners, GRC vendors need to prove their tooling covers it, and law firms need to prove they understand it well enough to bill for it.
Vague, unsourced, unliftable
We take operational resilience extremely seriously and are fully aligned with the latest regulatory expectations.
Specific, sourced, self-contained
Our DORA information register was accepted by the European Banking Authority in 2026, and our incident reporting meets the statutory classification deadlines the AFM checks for.
That is a content problem before it is anything else, and it is the same problem folkfox already solves for fintech marketing clients working under MiCA, PSD2 and now DORA at once. A page that claims 'robust operational resilience' without a date, a register score or a named regulator is unquotable, both to a human compliance officer doing due diligence and to an AI system trying to summarise a product honestly. A page that states the four pillars, links the AFM's own findings, and says plainly where a product sits against each one earns the citation instead.
That is a brand strategy discipline as much as a legal one: say the true thing plainly, cite it, and let the compliance officer do less work to trust it. Skip it, and a DORA compliance page reads exactly like the AFM's polite warning about group-level policies that do not match local reality.
Five moves before the next supervisory sweep#
Finish the ICT risk management inventory of critical functions before filing the register that is supposed to describe it, not after.
Check every group-level policy against the licence holder's actual local operations, the exact gap the AFM named.
Rehearse detection-to-report timing against DORA's statutory windows, not just against an internal service target.
Schedule threat-led penetration testing on its three-year cycle now, before the queue for qualified testers gets longer.
Publish the register score, the policy status and the test date in plain, sourced sentences a regulator or an AI system can both check.
folkfox has watched this pattern before, in this morning's look at a 24-hour EU reporting deadline and in Denmark's payment provider compliance case: regulators rarely surprise a sector twice with the same gap. The firms that treat a supervisory update as a free audit, rather than a formality to file away, are the ones still standing when the next sweep starts, and fintech's AML fines this year tell the same story from a different angle.
The AFM did not accuse anyone of hiding in the brush. It simply turned the light on early, while the grace period still has a few honest, dated deadlines left to run, and a fox given that much warning does not waste it arguing about the weather.
If a DORA compliance story still lives in three different spreadsheets, talk to folkfox before the next supervisory sweep does the finding for you.
Frequently asked questions#
What is DORA compliance, in plain terms?
DORA compliance means an EU financial firm can prove, with an ICT risk register, tested resilience plans and on-time incident reports, that it manages the technology behind its critical functions the way Regulation (EU) 2022/2554 requires. It has applied since 17 January 2025 and covers roughly twenty types of financial entity, from banks to crypto-asset service providers.
What are the DORA compliance requirements?
The DORA compliance requirements sit on four pillars: an ICT risk management framework, incident detection and reporting within statutory deadlines, regular resilience testing including threat-led penetration testing, and oversight of critical technology vendors. The AFM's 2026 review found most Dutch firms strong on the first pillar's paperwork and weaker on the other three.
Why did the AFM say DORA compliance still has gaps?
Because a rising register score hides two separate problems: not every firm has the full set of required policies, and some group-level policies do not actually match what the local, licensed entity does day to day. The AFM also received fewer incident reports than expected, suggesting detection still lags the rulebook.
How big are the fines for failing DORA compliance?
DORA's Article 50 lets national regulators fine a firm up to 2% of annual worldwide turnover, though the absolute ceiling varies sharply by country, from EUR2 million in the Czech Republic to EUR20 million in Italy, according to DLA Piper's mapping of the divergence. Individuals can also be fined separately.
What is ICT risk management under DORA?
ICT risk management is DORA's foundational pillar: identifying, classifying and documenting every system, service and vendor that supports a critical business function. Without it, a firm cannot report incidents accurately, test resilience meaningfully, or monitor third-party risk, which is why the AFM treats it as the base the other three pillars stand on.
Do compliance management tools actually help with DORA?
Good compliance management tools help by mapping policies to the specific licensed entity they apply to, tracking incidents against DORA's statutory reporting clock, and keeping test evidence audit-ready. A spreadsheet register can pass a first check; it rarely survives the kind of cross-referenced supervisory sweep the AFM just ran.
Read more on this topic#
NIS2 Compliance Arrives 'One Day' After Brussels Sued for the Wait
A second EU regime, a second register, a second sweep: see how the Netherlands' NIS2 deadline landed a day after a CJEU referral.
Read the pieceFintech AML Requirements Just Got a EUR2.6 Million Reminder
bunq's fine shows what happens when a fast-growing fintech outruns its own compliance file, the same risk DORA now tests for technology.
Read the piecePayment Provider Compliance Just Stopped Being Someone Else's Problem
Denmark's regulator barred a payments firm over AML failings, a sharp companion case to the AFM's DORA compliance findings.
Read the pieceTwenty Five Days Until the Cyber Resilience Act Starts Counting Hours
Another dated EU deadline, another countdown: see how the Cyber Resilience Act's reporting clock compares to DORA's.
Read the piece
Ready to make DORA compliance quotable, not just filed?
folkfox builds sourced, GEO-ready compliance content for fintech and cybersecurity brands, the kind that survives an AFM sweep and an AI Overview at the same time.