For years, operational resilience in banking was something a bank answered for on its own. Could its systems stay up, and could it keep serving clients through an outage. The edge of the question matched the edge of the institution.
DORA has moved that edge.
What DORA Actually Changes
DORA has applied across the EU since 17 January 2025, and it makes financial entities responsible for understanding and managing the ICT risks that sit with their external providers, while leaving each institution fully responsible for its own regulatory obligations. The obligation is to know where those dependencies sit and to govern the risk they carry, without the bank becoming the guarantor of a provider’s own resilience.
DORA is the principal operational-resilience regime for the financial entities in its scope. NIS2, the EU’s broader cybersecurity directive, sits alongside it and raises expectations across the wider ecosystem that banks and their clients depend on, from ICT providers to counterparties. The two don’t apply to a bank in the same way, and it’s worth being precise: for entities covered by DORA, DORA governs the operational-resilience and incident-reporting requirements, not NIS2. What both reflect is a wider regulatory recognition that operational disruption can travel across connected organisations, even if they allocate the obligations differently.
For a bank working in one market, that’s a demanding but contained piece of work. For a bank whose clients and dependencies stretch across borders, the operational picture gets more complicated, and that’s where it turns structural.
What Lands on the Bank
Here the distinction matters. A bank doesn’t pick up fresh regulatory obligations in every country its clients happen to operate in. Its accountability stays institution-specific, tied to where it’s established and who supervises it. What does change is the operational picture. For a bank running through multiple entities, providers and partner institutions, resilience becomes a cross-border problem to coordinate even where the regulatory perimeter stays fixed.
That coordination challenge is sharpest at the point of an actual incident. Under DORA, the initial notification of a major ICT incident is due within four hours of it being classified as major. When a disruption hits a shared provider, the exposure is immediate and the clock is unforgiving, and a bank needs to know quickly what’s affected across its footprint. A picture that arrives market by market, on a delay, doesn’t give it that.
The wider environment is uneven in a way that compounds this. Nearly two years past NIS2’s October 2024 transposition deadline, the standard still hasn’t landed at the same time or in the same shape across the EU. As recently as July 2026 the Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice over incomplete transposition. For a bank coordinating across those markets, that unevenness isn’t a footnote. It’s the fragmentation that makes cross-border resilience so hard to hold from any single institution’s vantage point.
Two Ways to Cover the Gap
So a bank has two ways to hold cross-border resilience together, and neither is comfortable on its own.
It can build the coordination itself: the visibility across markets, the incident response that stays aligned wherever a client operates. That’s a real cost, and for a bank whose strength is its home market, it means funding an international capability that sits well outside its core.
Or it can lean on bilateral correspondent relationships to reach the markets it doesn’t cover directly. Those arrangements can solve an individual market-access need, but they don’t automatically create common governance, shared service standards or agreed escalation across a wider group of banks. When something goes wrong in a market you reach through a relationship you don’t govern, the coordination you need isn’t already there.
What DORA Reveals About Governance
This is the part worth sitting with, because DORA points at something broader than its own text.
The direction of travel is that institutions increasingly need visibility and governance over the dependencies that sit beyond their own organisational boundary. Cross-border banking poses a comparable challenge at a different level: coordination between independent banks that need to work together without merging. A governed alliance of independent banks doesn’t transfer anyone’s regulatory responsibility, and it shouldn’t. Each member stays independent, regulated in its own market and answerable for its own systems. What the structure changes is the friction of coordinating across those boundaries, because the governance and escalation routes already exist rather than being improvised per client.
None of that makes a bank compliant. Compliance is each institution’s own to hold. What a governed network offers is a standing answer to the coordination question DORA has put in front of everyone, already in place before an incident tests it.
For an independent bank reading the direction of travel, and weighing what it would take to hold resilience together across every market its clients touch, that’s the question worth asking. Whether that coordination is something to build from scratch, something to improvise, or something to belong to.