dora compliance software

DORA Compliance Is No Longer Optional for Cross-Border EMIs and PIs

A strategic briefing for e-money and payment institutions authorised in one EEA member state and operating across borders under passport.
DORA

Select the regions your entity or passported operations touch

DORA is a single regulation, but it does not land uniformly. National competent authorities are already diverging in focus, reporting mechanics and enforcement appetite. Select your footprint below, and the supervisory signals that apply to it will surface for you.

5 Pillars of DORA

Where firms are actually falling short

These are the patterns our regulatory horizon scanning surfaces across payments supervision, signals you will not find in a generic article. Where you have selected regions above, the relevant cards are highlighted.
Book a DORA review session
Third-party risk is your single biggest exposure
EMIs and PIs lean heavily on cloud, payment processors and technology vendors. When nearly a third of major incidents trace back to a provider, third-party dependency is not a procurement footnote, it is a direct operational risk signal that belongs on the board agenda.

Applies to: EEA-wide
DORA covers non-EU third parties
DORA's requirements extend to ICT third-party providers themselves, non-EU providers included, so contracts with non-EU cloud and technology vendors must meet DORA standards. Delegated Regulation (EU) 2025/295 sets the RTS on critical third-party provider (CTPP) designation and the subcontracting templates.

Applies to: EEA-wide
Supervisory report, not a spreadsheet
Treat the register as a reporting obligation. DNB required entities to submit it as an xBRL-CSV file by 23 April 2025. Do not limit scrutiny to designated CTPPs either: non-critical dependencies are an emerging supervisory focus, and gaps there are increasingly being questioned.

Applies to: Netherlands
Malta's MFSA has already named the recurring gaps
The MFSA's September 2025 Dear CEO letter flagged recurring weaknesses in ICT risk frameworks, incident classification and third-party risk management across payment institutions. The consistent theme: firms have underestimated the workload and are resource-light against it.

Applies to: Malta
Cyprus has put AI-driven threats on the DORA agenda
CySEC's June 2026 Circular C786 added AI-driven cyber threats as an explicit DORA concern: frontier models that can find and exploit vulnerabilities at speed. Regulators now expect firms to assess whether their ICT arrangements hold up against AI-enabled attacks, not just conventional ones.

Applies to: Cyprus
TLPT is scoped, but testing discipline is universal
Delegated Regulation (EU) 2025/1190, in force since 8 July 2025, sets the RTS for threat-led penetration testing under the TIBER-EU methodology. Not every firm must run TLPT, but those below the threshold are still expected to run regular, documented vulnerability assessments.

Applies to: EEA-wide
DORA COMPLIANCE TOOL

DORA maturity Self-Assessment for Payments & Banking Firms

How ready is your firm for Digital Operational Resilience Act supervision
This regulatory gap analysis rates you across ten statements covering the obligations that matter most for a passported payments firm. Score each from 1 (not in place) to 5 (fully embedded and evidenced). Everything is computed in your browser and nothing is sent anywhere.
DORA SELF-CHECK
Where does your firm stand?
Answer to start building
0OUT OF 50
—0 of 10 answered
Speak to an expert
Question 1 of 100% complete
Building a robust reg-change process

How Vixio helps you get and stay ahead of DORA

DORA is not a one-off project. It is a continuous obligation across delegated regulations, RTS and diverging national signals. Here's how our regulatory change management software helps a passported firm run it as a controlled, auditable process.
01
One platform, every passported region
Our regulatory horizon scanning tracks DORA, its delegated regulations and RTS, and national-level signals, Dear CEO letters, circulars, register deadlines, across every region you passport into. Nothing is missed, and divergence is visible, not buried.
02
Analyst interpretation, not just alerts
Our analysts tell you what each change means in practice, not just that it happened. Automated regulatory intelligence flags it; playbooks and verdicts turn it into action your team can take, one reason we're positioned among the best ai tools for regulatory compliance in payments and banking.
03
A structured, auditable process
Horizon scanning, impact assessment, clear ownership, evidence at each step. Compliance tracking software that shows your board and supervisors you operate within tolerances, rather than just asserting it.
04
Cross-regime coordination
For firms straddling DORA and UK operational resilience, we keep one coherent process across both regimes, so a control or incident is evidenced once, not twice, not managed separately.

The passporting trap, and the UK parallel regime

A passport multiplies your obligations. It does not divide your effort. This is where a coherent change process either holds together or quietly fractures.

Around one third of the major ICT-related incidents reported across the EEA in 2025 had cross-border impact. For a passported firm operating under cross border payments regulation, that means a single event can trigger notification and coordination duties in several member states at once, on tight and not always identical clocks. Your incident process has to be built for multi-jurisdiction reporting from the start, not retrofitted during a live crisis.

DORA · EEA

Scope: ICT-focused, risk management, incident reporting, resilience testing, third-party oversight.
 
Consistency: Harmonised text across the EEA, but national competent authorities differ on mechanics and focus.- Layer an automatic "what this means for my business" analysis onto every query without complex prompt engineering.  

Supervision: Home and host supervisors both take an interest in a passported footprint. One framework, read nine different ways.
Map Your DORA Footprint

Around one third of the major ICT-related incidents reported across the EEA in 2025 had cross-border impact. For a passported firm operating under cross border payments regulation, that means a single event can trigger notification and coordination duties in several member states at once, on tight and not always identical clocks. Your incident process has to be built for multi-jurisdiction reporting from the start, not retrofitted during a live crisis.

UK Operational Resilience

Scope: Outcomes-focused across people, processes and facilities, not ICT alone.
 
Deadline: Impact tolerances for important business services required by 31 March 2025, already behind you if not in place.

Overlap: Runs in parallel with DORA for any firm also operating in the UK.
Check Your UK Overlap
Dates and instruments

The live deadline timeline

The dates and legal instruments that shape a passported payments firm's DORA position, and the banking compliance regulations running alongside it, from application through the delegated regulations and national supervisory signals. Where a firm still relies on manual tracking, this is where payments compliance software earns its place.

619

days since DORA became fully applicable

Applicable from 17 January 2025. This is already live and being supervised

DORA Resources

Everything you need to navigate DORA

View all articles

Schedule your DORA review session

A focused conversation on where your passported footprint is exposed and how to run DORA as one controlled process. No preparation required.

Simon Donkin · Senior Payments Consultant
sdonkin@vixio.com