One year after DORA became applicable, the compliance conversation has matured. 2025 was about building the register of information and papering the contractual clauses. 2026's supervisory dialogues ask harder questions: demonstrate the exit strategy for this critical provider, show the resilience-testing results, walk us through this incident's timeline against the reporting clocks.
Vendors are being sorted
The year quietly sorted ICT providers into two classes: those who respond to DORA questionnaires with marketing decks, and those who respond with evidence: audited controls, documented recovery objectives, incident histories, and architectures that make client exit plausible rather than theoretical. Financial entities have begun consolidating toward the second class, because every vendor on the register is recurring due-diligence work.
Consolidation as a resilience strategy
The same logic keeps favouring platform consolidation in the identity layer. One provider covering verification, screening, signing and sealed video means one register entry, one exit plan, one resilience assessment, instead of four of each, with the eIDAS QTSP audit regime layered on top as independent assurance. Resilience, it turns out, is also an argument for simplicity.
