Turkcell signs international B2B contracts with biometric-verified qualified signatures, live on WeVerify. See the Turkcell case →
Regulation · 29 January 2026

DORA, one year on: the register was the easy part

A year into the Digital Operational Resilience Act, supervisors have moved from registers to evidence: show us the exit plan, the test results, the incident timeline. Vendors are being sorted.

One year after DORA became applicable, the compliance conversation has matured. 2025 was about building the register of information and papering the contractual clauses. 2026's supervisory dialogues ask harder questions: demonstrate the exit strategy for this critical provider, show the resilience-testing results, walk us through this incident's timeline against the reporting clocks.

Vendors are being sorted

The year quietly sorted ICT providers into two classes: those who respond to DORA questionnaires with marketing decks, and those who respond with evidence: audited controls, documented recovery objectives, incident histories, and architectures that make client exit plausible rather than theoretical. Financial entities have begun consolidating toward the second class, because every vendor on the register is recurring due-diligence work.

Consolidation as a resilience strategy

The same logic keeps favouring platform consolidation in the identity layer. One provider covering verification, screening, signing and sealed video means one register entry, one exit plan, one resilience assessment, instead of four of each, with the eIDAS QTSP audit regime layered on top as independent assurance. Resilience, it turns out, is also an argument for simplicity.

Compliance centre · Banking solutions · Book a demo

See it working, live.

Identity, screening, signing and due diligence in one platform. 30 minutes.