Back to the blog
    DORA in Practice: What Insurers and IT Service Providers Really Need to Consider in 2026
    01.07.2026Sasha Justmann5 min read

    DORA in Practice: What Insurers and IT Service Providers Really Need to Consider in 2026

    An article on compliance and risk management in German insurance IT

    From Documentation Obligation to Active Supervision

    Since 17 January 2025, the Digital Operational Resilience Act (DORA) has applied directly in all EU member states. For banks, insurance companies, payment service providers, and other financial undertakings, this marked the end of a multi-year preparation phase. However, in 2026, the nature of the regulation has noticeably changed: pure documentation obligation has become active supervision. BaFin has unequivocally declared 2026 a test of endurance – the focus is no longer on whether DORA has been implemented, but how stringently.

    For IT managers in insurance companies, this means: those who have so far treated DORA primarily as a completed project should now sharpen their focus. The actual operational test is only just beginning.

    The Legal Classification for Germany

    DORA is an EU regulation and applies directly, without the need for a national implementing law for its substantive requirements. Germany only needed an accompanying law for responsibilities and powers – the Finanzmarktdigitalisierungsgesetz (FinmadiG), which has adapted national supervisory powers to DORA since the beginning of 2025. In practice, this means consolidation: DORA replaces BaFin's previous supervisory IT requirements, specifically the VAIT circular for insurers (Source: shattered.io). What was previously set out in separate national regulations for banks, insurance companies, capital management companies, and payment institutions is now integrated into a unified European framework.

    The competent supervisory authority for DORA in Germany is BaFin, in close cooperation with the Deutsche Bundesbank. In preparation, BaFin had already established six working groups in 2023 with representatives from the industry and the Bundesbank, which, in more than 30 meetings, compared DORA's requirements with previous VAIT guidelines and derived concrete needs for action.

    The Strictest Requirement: Reporting Obligations for ICT-Related Incidents

    The reporting obligation for severe ICT-related incidents is considered particularly demanding in practice. DORA prescribes a three-stage, tightly timed reporting system for this:

    • Initial report: within 4 hours of classifying an incident as severe, but no later than 24 hours after discovery.
    • Intermediate report: within 72 hours.
    • Final report: within one month.

    These deadlines require established, practiced internal escalation processes – from the technical detection of an incident to legally compliant reporting to BaFin. Those who do not regularly test this chain risk missing the tight deadlines in an emergency.

    ICT Third-Party Risk: The Register as an Ongoing Obligation

    A second focus of current supervisory practice concerns the management of ICT third-party risks. The deadline for the initial information register was already 30 April 2025 – now more than a year ago, and the deadlines continue: for 2026, another submission of the ICT third-party provider register in xBRL-CSV format is planned. This also affects the major cloud providers: 19 ICT third-party providers are considered Critical Third-Party Providers (CTPPs) across Europe and are thus subject to direct supervision by European supervisory authorities – including the major hyperscalers.

    For insurers, this specifically means that all ICT service providers – from cloud infrastructure to BiPRO interface providers and specialised software companies – must be comprehensively recorded in the register, including details on the type of service, data storage location, subcontractors used, contract duration, and a documented exit strategy. BaFin has already documented common errors in submitting these registers in workshops in 2025 and is preparing further workshops for 2026 – a clear signal that there is still considerable need for improvement across the board here.

    Threat-Led Penetration Testing: The Next Level

    For systemically important financial institutions, DORA also mandates regular penetration tests based on the ECB's TIBER-EU framework – so-called Threat-Led Penetration Testing (TLPT), which includes the entire ICT supply chain. Concrete BaFin requirements for this are expected to be published in the second half of 2026. Insurers potentially falling within the scope should actively follow this development, as the preparation of such tests – unlike mere documentation tasks – requires significant technical and organisational lead time.

    Implementation Status is Unevenly Distributed

    The actual maturity level of DORA implementation varies considerably in practice. According to an industry survey, the average planned implementation status by the deadline was about two-thirds of the requirements – at best 90 percent, but in the worst case only 30 percent. Small and medium-sized financial undertakings are particularly affected, as they have neither the resources of large corporations nor the simplified requirements under Article 16 DORA for micro-undertakings – they are in a regulatory sandwich position between full requirements and limited capacities. Europe-wide, the picture is also inconsistent: by the end of 2025, only around 50 percent of European financial institutions had achieved full DORA compliance, and around 38 percent of financial institutions had postponed their compliance target during 2026.

    Practical Recommendations for Insurers and their IT Service Providers

    • Regularly test reporting processes, do not just document them. The tight deadlines of 4, 72 hours, and one month can only be met if escalation chains are practiced – mere procedural documentation is insufficient.
    • Understand the third-party register as an ongoing task. The ICT third-party provider register is not a one-off submission but must be continuously maintained and updated at fixed dates – for example, 30 March.
    • Specify exit strategies for critical ICT service providers. Especially for cloud providers and central interface service providers, DORA requires a documented, implementable exit strategy in an emergency – a point that is still insufficiently elaborated in many companies.
    • Consider TLPT requirements early on. Even though specific BaFin guidelines are only expected in the second half of 2026, it is worthwhile to familiarise oneself with the TIBER-EU framework early to avoid being under short-term pressure.
    • Use DORA as an opportunity to review IT security architecture. Those who perceive DORA not merely as a compulsory exercise but as an opportunity for a comprehensive review of their own IT security and contract architecture will gain a better organised and documented IT landscape beyond pure regulation.

    Conclusion

    DORA compliance is not a one-off project with a single deadline, but an ongoing process, with the actual operational test only beginning in 2026. For insurers and their IT service providers, the focus is noticeably shifting: away from initial implementation towards demonstrable, repeatable practice in reporting, third-party management, and resilience testing. Those who take this test seriously will not only secure regulatory legal certainty but also a more robust IT security organisation overall.