Our Expert in Greece
No results available
Last updated: August 10, 2026
Europe’s banking operational-resilience deadline has moved from policy ambition to enforceable reality, and Greek financial institutions that have not yet aligned their ICT governance with the Digital Operational Resilience Act (DORA) face mounting supervisory risk. Regulation (EU) 2022/2554 became directly applicable across all EU Member States on 17 January 2025, imposing binding obligations on credit institutions, investment firms, payment service providers, and their critical ICT third-party suppliers. The Bank of Greece has signalled that it expects supervised entities to demonstrate full compliance with DORA’s core pillars, ICT risk management, incident reporting, third-party oversight and resilience testing, and has begun integrating DORA requirements into its supervisory review process.
For compliance officers and in-house counsel at Greek banks, the question is no longer whether DORA applies, but whether the evidence of compliance is robust enough to withstand regulatory scrutiny.
The Digital Operational Resilience Act, formally Regulation (EU) 2022/2554, is the EU’s dedicated legislative framework mandating that financial entities can withstand, respond to, and recover from ICT-related disruptions. Published in the Official Journal of the European Union on 27 December 2022, DORA entered into force on 16 January 2023 and became directly applicable on 17 January 2025, following a two-year implementation window. Unlike a directive, DORA does not require national transposition; it applies uniformly across all 27 Member States, creating a single rulebook for digital operational resilience in financial services.
The policy rationale is straightforward. As banks and financial firms increasingly depend on digital infrastructure and third-party technology providers, a single cyber-attack, cloud outage, or data-centre failure can cascade across interconnected markets. DORA addresses this systemic vulnerability by requiring regulated entities to treat ICT risk with the same rigour they apply to credit, market, and liquidity risk.
DORA is structured around five core pillars, each supported by technical standards developed by the European Supervisory Authorities (EBA, EIOPA, and ESMA):
For any entity starting a business in Greece in the financial sector, understanding DORA is no longer optional, it is a foundational compliance requirement.
Understanding the sequencing of Europe’s operational-resilience deadline is critical for compliance planning. DORA’s rollout followed a phased approach, with the substantive obligations applying simultaneously across the EU. The timeline below captures the milestones that Greek banks and regulated entities must track.
| Date | Obligation / Milestone | Who Is Affected |
|---|---|---|
| 27 December 2022 | DORA published in the Official Journal of the EU | All EU financial entities and ICT third-party providers |
| 16 January 2023 | DORA enters into force; two-year implementation window begins | All in-scope entities |
| 17 January 2025 | DORA becomes directly applicable, all substantive obligations enforceable | Credit institutions, investment firms, payment institutions, insurers, ICT third-party providers |
| 30 April 2025 | First submission of register of information on ICT third-party service arrangements to competent authorities and ESAs | All financial entities subject to DORA |
| Ongoing (at least every 3 years) | Advanced threat-led penetration testing (TLPT) for systemically important entities | Significant credit institutions and other entities designated by competent authorities |
| Ongoing | Regular (annual or more frequent) basic digital operational resilience testing | All financial entities |
| 11 September 2026 | Certain Cyber Resilience Act (CRA) obligations begin to apply (reporting of vulnerabilities) | Manufacturers and providers of products with digital elements (cross-sector, not DORA-specific) |
The critical takeaway for Greek banks: the 17 January 2025 applicability date means supervisory expectations are already in effect. The 30 April 2025 register submission was the first concrete test of compliance readiness, entities that missed or inadequately completed this submission face immediate supervisory follow-up. Industry observers expect national competent authorities, including the Bank of Greece, to intensify on-site inspections and data quality reviews throughout 2026.
With Europe’s banking operational-resilience deadline now past, the focus shifts from preparation to demonstrable compliance. DORA’s four mandatory pillars each require documented frameworks, designated owners, and auditable evidence. Below is a breakdown of each obligation and the practical steps Greek banks should take.
Under Articles 5–16 of DORA, every financial entity must maintain a comprehensive ICT risk-management framework approved by the management body. This framework must cover the identification and classification of ICT assets, protection measures (including encryption, access controls and network security), detection capabilities (monitoring and anomaly detection), response and recovery procedures, and learning mechanisms that feed incident outcomes back into policy updates.
In practical terms, Greek banks should ensure they have a documented ICT risk policy signed off by the board, a current inventory of all ICT assets and dependencies, and a named senior officer, typically the Chief Information Security Officer or an equivalent, accountable for DORA compliance. Supervisors will expect to see evidence that the framework is tested and updated at least annually.
Articles 17–23 require financial entities to classify ICT-related incidents using criteria set by the ESAs, including data losses, service degradation duration, geographic spread, and impact on clients. When an incident meets the threshold for a major ICT incident, the entity must notify its competent authority using a standardised reporting template. The reporting flow involves an initial notification, an intermediate report, and a final report, each within prescribed windows.
Greek banks should ensure their incident-response procedures map directly to DORA’s classification criteria. Early indications suggest that the Bank of Greece expects entities to have pre-populated reporting templates ready and to have conducted at least one tabletop exercise simulating a major incident report.
One of DORA’s most resource-intensive requirements relates to ICT third-party risk management. Articles 28–44 oblige financial entities to maintain a detailed register of all ICT third-party service arrangements, which must be submitted to competent authorities, the first EU-wide submission deadline was 30 April 2025. This register must include the identity of each provider, the nature of services provided, whether the service supports critical or important functions, and the jurisdictions in which data is stored or processed.
Beyond the register, DORA mandates that contracts with ICT providers include provisions on audit rights, exit strategies, sub-outsourcing restrictions, data location, and incident notification. Greek banks relying on international cloud providers or ICT services falling under DORA’s scope should review and, where necessary, renegotiate existing service-level agreements to incorporate these mandatory contractual clauses.
Articles 24–27 establish a tiered testing regime. All financial entities must conduct basic digital operational resilience testing, including vulnerability assessments, network security testing, and scenario-based exercises, on at least an annual basis. Systemically important entities, designated by their competent authority, must also undergo advanced threat-led penetration testing (TLPT) at least every three years, following the TIBER-EU framework or equivalent methodologies endorsed by the ESAs.
For Greek banks designated as significant by the Bank of Greece, this means budgeting for and scheduling TLPT engagements with qualified external testers, documenting results, and remediating identified vulnerabilities within agreed timeframes.
| Entity Type | Reporting & Register Obligations | Notes / Greek Authority Contact |
|---|---|---|
| Credit institutions (banks) | Full ICT risk framework; incident reporting; register of ICT third-party arrangements; TLPT for significant entities | Bank of Greece, Banking Supervision Department |
| Investment firms | ICT risk framework; incident reporting; register submission; basic resilience testing | Hellenic Capital Market Commission (HCMC) |
| Payment institutions / e-money institutions | ICT risk framework; incident reporting; register submission; basic resilience testing | Bank of Greece, Payment Systems Oversight |
| Insurance / reinsurance undertakings | ICT risk framework; incident reporting; register submission | Bank of Greece, Private Insurance Supervision |
| Critical ICT third-party providers (designated) | Subject to direct oversight by Lead Overseer (ESA-appointed); cooperation with national authorities | Lead Overseer (EBA/EIOPA/ESMA) + Bank of Greece |
While DORA applies uniformly across the EU, its practical implementation in Greece involves specific supervisory dynamics and national considerations that compliance teams must account for.
The Bank of Greece has published dedicated guidance on DORA through its supervision portal, outlining how the regulation integrates with existing prudential supervision. As the competent authority for credit institutions, payment institutions, and insurance undertakings in Greece, the Bank of Greece is responsible for receiving and reviewing incident reports, ICT third-party registers, and resilience-testing results from supervised entities. The Bank of Greece DORA guidance confirms that the institution views digital operational resilience as a core component of its Supervisory Review and Evaluation Process (SREP), meaning deficiencies in DORA compliance may directly affect a bank’s capital and governance assessment scores.
Greek banks should establish a direct communication channel with their designated supervisory contact at the Bank of Greece for DORA-related submissions. Industry observers expect the Bank of Greece to issue further implementing guidance or circulars addressing Greek-specific operational details, including language requirements for incident-reporting templates and technical instructions for register submissions.
Many Greek banks rely on ICT service providers headquartered outside Greece, including major cloud platforms, core-banking software vendors, and cybersecurity firms. Under DORA, these cross-border arrangements require particular attention. Financial entities must ensure that contracts with foreign providers comply with DORA’s mandatory contractual provisions, including data-location transparency, audit-access rights, and exit-strategy clauses.
Where ICT providers process personal data of Greek clients, the broader Greek regulatory landscape, including GDPR enforcement by the Hellenic Data Protection Authority, adds a layer of compliance complexity. Greek banks should map the intersection between DORA’s ICT third-party requirements and existing data-protection obligations to avoid regulatory gaps.
The following checklist translates DORA’s requirements into time-bound actions for legal, compliance and technology teams at Greek banks. Each action is assigned a priority timeframe to help institutions structure their remediation efforts.
Immediate actions (now):
Short-term actions (1–3 months):
Medium-term actions (3–6 months):
Ongoing actions:
| Compliance Criterion | Evidence Needed | Priority |
|---|---|---|
| Board-approved ICT risk framework | Signed policy document; board minutes recording approval | Critical |
| ICT third-party register submitted | Confirmation receipt from Bank of Greece / ESA portal | Critical |
| Incident-reporting workflow tested | Tabletop exercise report; completed template dry run | High |
| DORA clauses in third-party contracts | Contract amendment log; legal review sign-off | High |
| Resilience testing completed (annual) | Test reports; remediation tracker; management summary | High |
DORA’s obligations are proportionate, the scope and intensity of compliance requirements vary depending on the type, size and systemic importance of the financial entity. The table below summarises the key differences for entities most commonly supervised in Greece.
| Entity Type | Key DORA Obligations | Next-Step Deadline |
|---|---|---|
| Credit institutions (banks) | Full ICT risk framework; incident reporting; third-party register; basic testing (annual); TLPT (every 3 years for significant entities) | TLPT planning: agree scope with Bank of Greece by next review cycle |
| Investment firms | ICT risk framework (proportionate); incident reporting; third-party register; basic resilience testing | Annual testing cycle; register maintenance ongoing |
| Payment institutions | ICT risk framework; incident reporting; third-party register; basic resilience testing | Annual testing cycle; register maintenance ongoing |
| Critical ICT third-party providers | Subject to direct oversight by ESA-appointed Lead Overseer; must cooperate with oversight activities, audits and recommendations | Ongoing, designation and oversight framework operational |
The proportionality principle means that smaller investment firms or payment institutions may implement simplified ICT risk-management frameworks, but they are not exempt from the core obligations. The likely practical effect is that even smaller Greek financial entities will need to allocate dedicated compliance resources to DORA.
DORA does not prescribe a harmonised fine schedule at the EU level for financial entities. Instead, enforcement is delegated to national competent authorities, in Greece, principally the Bank of Greece and the Hellenic Capital Market Commission, which retain the power to impose administrative penalties and remedial measures under their existing supervisory mandates. This means that a Greek bank found to be non-compliant with DORA’s ICT risk-management or incident-reporting obligations may face supervisory measures ranging from formal warnings and mandatory remediation orders to financial penalties calibrated under national law.
For critical ICT third-party providers designated at EU level, the Lead Overseer (one of the three ESAs) has the power to impose periodic penalty payments. Beyond formal sanctions, the reputational consequences of a publicised DORA deficiency, or, worse, an unreported major ICT incident, can erode client trust and trigger contractual liability with counterparties. Industry observers expect enforcement actions to accelerate through 2026 and 2027 as supervisors complete their first full cycle of DORA-focused inspections.
Consider a mid-sized Greek commercial bank that experiences a ransomware attack on its core-banking platform during a holiday weekend. The attack encrypts transaction databases and disrupts online-banking services for approximately 40,000 retail customers over a 16-hour period. Under DORA, the bank’s incident-response team must immediately classify the event using the ESA criteria, duration of service disruption, number of affected clients, data integrity impact, and geographic spread. Given the scale, the event meets the threshold for a major ICT incident.
The bank submits its initial notification to the Bank of Greece within the prescribed window, using the standardised reporting template. Over the following days, it files intermediate and final reports detailing root-cause analysis, containment measures, recovery actions and lessons learned. Simultaneously, the compliance team reviews whether the ICT provider hosting the affected platform met its contractual obligations under the DORA-compliant service agreement, including incident-notification timelines and recovery-time commitments. The incident report and remediation plan are incorporated into the bank’s ICT risk-management framework review, informing the next cycle of resilience testing.
Europe’s banking operational-resilience deadline is no longer a future milestone, it is an active supervisory reality for every Greek bank and regulated financial entity. DORA compliance is not a one-off project but an ongoing governance obligation that requires continuous investment in ICT risk management, incident preparedness, third-party oversight and resilience testing.
Greek banks should prioritise the following five actions immediately:
This article was produced by Global Law Experts. For specialist advice on this topic, contact Ioannis Charaktiniotis at I. Charaktiniotis & Partners Law Firm, a member of the Global Law Experts network.
posted 28 minutes ago
posted 51 minutes ago
posted 1 hour ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message