DORA has been in force since 17 January 2025. Supervisor expectations are sharpening. TLPT exercises are reaching architectures assumed compliant when DORA went live.
For financial entities, “we have a DORA policy” is now insufficient. Supervisors expect demonstrable evidence — at the architecture level — that controls are met.
What demonstrable means
For each Article 6 and Article 28 requirement, you should be able to:
Name the control that satisfies it
Locate it in the running system (not just policy)
Provide evidence in a regulator-consumable format (logs, configurations, test results)
Most-common findings
In Ænix DORA engagements, four findings recur:
Observability data leaving the regulator’s perimeter
Exit plans never tested
Concentration risk treated as procurement question
Sub-contractor chain invisible past first hop
How to use the checklist
Download, walk through with your platform engineering and compliance teams. Identify gaps. Prioritize remediation.
For each Article 6 / Article 28 requirement, what three things should you be able to do "demonstrably"?
Why: For each Article 6 / Article 28 requirement: name the control, locate it in the running system (configurations, logs, test results), and provide evidence in a regulator-consumable format. "We have a DORA policy" is now insufficient.
Question 2 / 5
Which is NOT named as one of the four most-common DORA findings?
Why: Four recurring findings in Aenix DORA engagements: (1) observability data leaves the regulator perimeter, (2) exit plans never tested, (3) concentration risk treated as procurement question not architecture, (4) sub-contractor chain invisible past first hop. Provider-held encryption keys are a real sovereignty problem, but it is not one of the four findings this article names — the fourth is the sub-contractor chain being invisible past the first hop.
Question 3 / 5
What does the article say about supervisor expectations as of 2026?
Why: Supervisor expectations are sharpening. TLPT exercises are reaching architectures that were assumed compliant when DORA went live in January 2025 but had never been tested under realistic regulator scrutiny.
Question 4 / 5
What is the recommended workflow for using the checklist?
Why: Walk through with platform engineering and compliance teams jointly, identify gaps, prioritise remediation. Joint review surfaces architecture-level gaps that compliance-only or engineering-only reviews miss.
Question 5 / 5
When did DORA come into force?
Why: DORA has been in force since 17 January 2025. NIS2 transposition (a separate regulation) was due 17 October 2024 — easy to confuse.