On 13 July 2026, the Bank of England, the PRA and the FCA began directly overseeing the first four firms designated as Critical Third Parties to the UK financial system: Amazon Web Services, Google Cloud, Microsoft and Oracle. Eight months earlier, in November 2025, the European Supervisory Authorities named their own first list of critical ICT providers for direct oversight — and the same handful of hyperscalers sat at the top of it.

So here is the state of things, stated plainly for a board: the four companies your business almost certainly runs on are now regulated as systemically important on both sides of the Channel, by two regimes that rhyme. One of those regimes is British and you have probably heard your executives mention it. The other is the EU's Digital Operational Resilience Act — DORA — and a surprising number of UK boards have filed it under "not our problem, we left." This is a board read on why that filing is wrong, and what to do about it.

What DORA is, in one breath

DORA is an EU regulation that has applied directly across all twenty-seven member states since 17 January 2025. "Directly" matters: unlike a directive, there was no national transposition, no local flavour, no grace for translation. On that date it simply became the law that financial entities operating in the EU are measured against, and the machinery of supervision has been switching on ever since.

It rests on five pillars, and they are worth knowing in plain English because your executives will use the acronyms and you should be able to translate:

ICT risk management — a documented framework to identify, protect, detect, respond and recover, owned at board level against a risk tolerance the board sets. Everything else hangs off this one.

Incident reporting — classify incidents by severity and report the major ones to the regulator on a fixed clock: initial, intermediate, final. It standardises what used to be twenty-seven different national habits.

Resilience testing — a regular testing programme for everyone, plus threat-led penetration testing, against live production systems, every three years, for the largest designated firms.

Third-party risk — contractual control and oversight of every ICT supplier: a register of them, mandatory contract clauses, tested exit strategies, and an honest look at concentration. Plus the EU-level direct oversight of those designated critical providers.

Information sharing — a voluntary framework for sharing threat intelligence. The only optional pillar; don't let anyone over-scope it into a project.

"We left the EU" is not an answer

The instinct in a British boardroom is that this is Brussels' business. It reaches you anyway, by three doors.

The first is the obvious one: if your group has an EU-authorised subsidiary or branch — a bank, an insurer, an asset manager, a payment firm — that entity is directly in scope, and its ICT framework, its register, its incident reporting and its testing must satisfy DORA. The group cannot ring-fence the obligation to a floor in Frankfurt; the framework has to hold.

The second door is quieter and catches firms that think they are nowhere near financial services. If your business is an ICT provider to EU financial entities — cloud, data, software, managed services, outsourced anything — DORA reaches you through your customers' contracts. Those customers are now required to impose DORA-compliant terms on you: audit and access rights, incident cooperation, exit provisions, control over who you subcontract to. You will feel DORA as a stack of re-papered contracts before you ever feel it as a regulator's letter.

The third door is the one nobody signs up for: contractual pull-through. Even with no EU entity and no EU financial customer, if you sit anywhere in the supply chain of a firm that has one, the DORA-shaped clauses propagate down the chain to you. This is how modern regulation travels — not by jurisdiction but by contract — and it is why "are we in scope?" is the wrong first question. The right one is "does anything we touch eventually touch an EU financial entity?" For most firms of any size, the honest answer is yes.

And if you are tempted to think the UK is a softer touch, look again at that 13 July date. The UK's own Critical Third Parties regime is now live and overseeing the same hyperscalers; the FCA and PRA operational-resilience rules passed their final deadline in March 2025; and the Cyber Security and Resilience Bill is moving through Parliament to widen the net further. The direction of travel is identical on both sides. DORA is just the most developed version of a rulebook the UK is writing anyway.

The part that is personally yours: Article 5

Most of DORA is machinery for the executive to build. One article is aimed squarely at the people reading this, and it is the reason a NED cannot delegate this file away.

Article 5 places ICT risk on the "management body" — the board and senior management — and says it must "define, approve, oversee and be responsible for the implementation of all arrangements related to the ICT risk management framework." The board, it says, "bears the ultimate responsibility" for the entity's ICT risk. That is not a drafting flourish. It is the same move regulators made with financial risk after 2008 and with data protection under GDPR: the accountability is pushed up to the people who are supposed to be governing, not merely down to the people operating.

Concretely, Article 5 expects the board to set and approve — and to be able to show it set and approved — the digital resilience strategy and the firm's ICT risk tolerance; the business-continuity and disaster-recovery policies; the internal audit plan for ICT; the policy on using third-party providers; and the budget, including for staff training. Each of those is a board decision with a minute against it, or it is a gap.

And then the sentence that should end the era of the silent director on this subject: members of the management body must "actively keep up to date with sufficient knowledge and skills" — through regular, specific training — to understand and assess ICT risk. DORA has written board cyber competence into law. A director who cannot interrogate the resilience report, and cannot evidence having been trained to, is no longer merely underprepared; they are out of line with the regulation. This is exactly the shift I have argued boards should get ahead of rather than be dragged into.

What the first year actually revealed

DORA's opening eighteen months were less about fines — I have found no named penalty against a financial entity yet, and I would not let anyone tell your board otherwise — and more about the supervisors discovering, in detail, how unready the plumbing was.

The clearest tell is the Register of Information, the inventory every firm must keep of its ICT third-party arrangements. In the regulators' voluntary dry run, with around a thousand firms taking part, only 6.5% of registers passed all the data-quality checks. Not because firms are careless, but because the information lives in three places that never talk — procurement, legal and IT — with no single source of truth, expired legal-entity identifiers, and free text where the rules demand codes. When the registers were collected for real, the validation was tightened: a register waved through in 2025 could be rejected in 2026.

Two failures inside that failure are worth a director's attention. The first is subcontracting chains — the template that maps the suppliers beneath your suppliers is among the most commonly left incomplete. Firms can name who they pay; they lose sight of the fourth and fifth parties actually doing the work, which is precisely where the supplier underneath the supplier can take you down. The second is concentration risk: Germany's regulator has explicitly named dependency on US hyperscalers as a supervisory focus and pressed firms on whether their exit strategies are real or theatrical. Given who just got designated critical on both sides of the Channel, that is not a German preoccupation. It is the central structural risk of how modern finance is built, and your board owns a piece of it.

What "good" looks like, and what to ask on Tuesday

Strip it down and the defensible position is not exotic. It is a single authoritative inventory of your ICT third parties, with valid identifiers and the subcontracting chain actually mapped. It is a documented, tested exit strategy for the critical providers you could not simply walk away from tomorrow. It is a testing programme sized to what matters, and TLPT readiness if you are large enough to be designated. It is board-approved risk tolerances with live monitoring against them. And it is incident classification that can actually meet the regulator's clock rather than discovering the clock during the incident.

So the questions for your next board meeting are short. Does anything we operate or supply touch an EU financial entity — and has someone actually traced that, rather than assumed the answer? Can the executive produce our Register of Information today, and would it pass the checks that failed nineteen firms in twenty? Where is our concentration risk, and is the exit plan for it tested or aspirational? And — the Article 5 question, the one that is personally yours — can each of us evidence the training that lets us challenge any of this, or have we been treating cyber resilience as somebody else's technical problem right up until the morning it becomes the board's?

The polite phase of this regime is ending. The firms that come through it well will be the ones whose boards treated DORA not as a European inconvenience to be filed away, but as the clearest statement yet of a duty that was always theirs.

This is general information for directors, not legal or regulatory advice; scope and obligations turn on your specific group structure and activities, and the position should be confirmed with your advisers.