[codicts-css-switcher id=”346″]

Global Law Experts Logo
europes banking operationalresilience deadline

Europe's Banking Operational-resilience Deadline: What Greek Banks Must Do Now

By Global Law Experts
– posted 52 minutes ago

Last updated: August 10, 2026

Europe’s banking operational-resilience deadline has moved from policy ambition to enforceable reality, and Greek financial institutions that have not yet aligned their ICT governance with the Digital Operational Resilience Act (DORA) face mounting supervisory risk. Regulation (EU) 2022/2554 became directly applicable across all EU Member States on 17 January 2025, imposing binding obligations on credit institutions, investment firms, payment service providers, and their critical ICT third-party suppliers. The Bank of Greece has signalled that it expects supervised entities to demonstrate full compliance with DORA’s core pillars, ICT risk management, incident reporting, third-party oversight and resilience testing, and has begun integrating DORA requirements into its supervisory review process.

For compliance officers and in-house counsel at Greek banks, the question is no longer whether DORA applies, but whether the evidence of compliance is robust enough to withstand regulatory scrutiny.

  • Key applicability date: 17 January 2025, DORA’s substantive requirements became enforceable.
  • First ESA register submission: Financial entities were required to submit their registers of information on ICT third-party arrangements by 30 April 2025.
  • Immediate priority: Greek banks must ensure their ICT risk-management framework, incident-reporting workflows, third-party contracts and resilience-testing programmes are documented and audit-ready.

What Is DORA and Why It Matters for European Banks

The Digital Operational Resilience Act, formally Regulation (EU) 2022/2554, is the EU’s dedicated legislative framework mandating that financial entities can withstand, respond to, and recover from ICT-related disruptions. Published in the Official Journal of the European Union on 27 December 2022, DORA entered into force on 16 January 2023 and became directly applicable on 17 January 2025, following a two-year implementation window. Unlike a directive, DORA does not require national transposition; it applies uniformly across all 27 Member States, creating a single rulebook for digital operational resilience in financial services.

The policy rationale is straightforward. As banks and financial firms increasingly depend on digital infrastructure and third-party technology providers, a single cyber-attack, cloud outage, or data-centre failure can cascade across interconnected markets. DORA addresses this systemic vulnerability by requiring regulated entities to treat ICT risk with the same rigour they apply to credit, market, and liquidity risk.

What DORA Covers

DORA is structured around five core pillars, each supported by technical standards developed by the European Supervisory Authorities (EBA, EIOPA, and ESMA):

  • ICT risk management: Entities must establish and maintain a comprehensive ICT risk-management framework, including policies for identification, protection, detection, response and recovery (Articles 5–16).
  • ICT-related incident reporting: Major ICT incidents must be classified, recorded and reported to competent authorities within prescribed timeframes (Articles 17–23).
  • Digital operational resilience testing: Entities must conduct regular testing, including threat-led penetration testing (TLPT) for systemically important firms, at intervals specified by regulators (Articles 24–27).
  • ICT third-party risk management: Financial firms must maintain a register of all ICT third-party arrangements, conduct due diligence on providers, and ensure contracts include mandatory clauses on audit rights, exit strategies, and data protection (Articles 28–44).
  • Information sharing: Voluntary arrangements for sharing cyber-threat intelligence among financial entities are encouraged (Article 45).

For any entity starting a business in Greece in the financial sector, understanding DORA is no longer optional, it is a foundational compliance requirement.

Key Timeline and Operational Resilience Deadlines

Understanding the sequencing of Europe’s operational-resilience deadline is critical for compliance planning. DORA’s rollout followed a phased approach, with the substantive obligations applying simultaneously across the EU. The timeline below captures the milestones that Greek banks and regulated entities must track.

Date Obligation / Milestone Who Is Affected
27 December 2022 DORA published in the Official Journal of the EU All EU financial entities and ICT third-party providers
16 January 2023 DORA enters into force; two-year implementation window begins All in-scope entities
17 January 2025 DORA becomes directly applicable, all substantive obligations enforceable Credit institutions, investment firms, payment institutions, insurers, ICT third-party providers
30 April 2025 First submission of register of information on ICT third-party service arrangements to competent authorities and ESAs All financial entities subject to DORA
Ongoing (at least every 3 years) Advanced threat-led penetration testing (TLPT) for systemically important entities Significant credit institutions and other entities designated by competent authorities
Ongoing Regular (annual or more frequent) basic digital operational resilience testing All financial entities
11 September 2026 Certain Cyber Resilience Act (CRA) obligations begin to apply (reporting of vulnerabilities) Manufacturers and providers of products with digital elements (cross-sector, not DORA-specific)

The critical takeaway for Greek banks: the 17 January 2025 applicability date means supervisory expectations are already in effect. The 30 April 2025 register submission was the first concrete test of compliance readiness, entities that missed or inadequately completed this submission face immediate supervisory follow-up. Industry observers expect national competent authorities, including the Bank of Greece, to intensify on-site inspections and data quality reviews throughout 2026.

Core DORA Obligations: What Firms Must Do Now

With Europe’s banking operational-resilience deadline now past, the focus shifts from preparation to demonstrable compliance. DORA’s four mandatory pillars each require documented frameworks, designated owners, and auditable evidence. Below is a breakdown of each obligation and the practical steps Greek banks should take.

ICT Risk-Management Framework

Under Articles 5–16 of DORA, every financial entity must maintain a comprehensive ICT risk-management framework approved by the management body. This framework must cover the identification and classification of ICT assets, protection measures (including encryption, access controls and network security), detection capabilities (monitoring and anomaly detection), response and recovery procedures, and learning mechanisms that feed incident outcomes back into policy updates.

In practical terms, Greek banks should ensure they have a documented ICT risk policy signed off by the board, a current inventory of all ICT assets and dependencies, and a named senior officer, typically the Chief Information Security Officer or an equivalent, accountable for DORA compliance. Supervisors will expect to see evidence that the framework is tested and updated at least annually.

Incident Reporting and Information Sharing

Articles 17–23 require financial entities to classify ICT-related incidents using criteria set by the ESAs, including data losses, service degradation duration, geographic spread, and impact on clients. When an incident meets the threshold for a major ICT incident, the entity must notify its competent authority using a standardised reporting template. The reporting flow involves an initial notification, an intermediate report, and a final report, each within prescribed windows.

Greek banks should ensure their incident-response procedures map directly to DORA’s classification criteria. Early indications suggest that the Bank of Greece expects entities to have pre-populated reporting templates ready and to have conducted at least one tabletop exercise simulating a major incident report.

ICT Third-Party Provider Oversight

One of DORA’s most resource-intensive requirements relates to ICT third-party risk management. Articles 28–44 oblige financial entities to maintain a detailed register of all ICT third-party service arrangements, which must be submitted to competent authorities, the first EU-wide submission deadline was 30 April 2025. This register must include the identity of each provider, the nature of services provided, whether the service supports critical or important functions, and the jurisdictions in which data is stored or processed.

Beyond the register, DORA mandates that contracts with ICT providers include provisions on audit rights, exit strategies, sub-outsourcing restrictions, data location, and incident notification. Greek banks relying on international cloud providers or ICT services falling under DORA’s scope should review and, where necessary, renegotiate existing service-level agreements to incorporate these mandatory contractual clauses.

Digital Operational Resilience Testing

Articles 24–27 establish a tiered testing regime. All financial entities must conduct basic digital operational resilience testing, including vulnerability assessments, network security testing, and scenario-based exercises, on at least an annual basis. Systemically important entities, designated by their competent authority, must also undergo advanced threat-led penetration testing (TLPT) at least every three years, following the TIBER-EU framework or equivalent methodologies endorsed by the ESAs.

For Greek banks designated as significant by the Bank of Greece, this means budgeting for and scheduling TLPT engagements with qualified external testers, documenting results, and remediating identified vulnerabilities within agreed timeframes.

Entity Type Reporting & Register Obligations Notes / Greek Authority Contact
Credit institutions (banks) Full ICT risk framework; incident reporting; register of ICT third-party arrangements; TLPT for significant entities Bank of Greece, Banking Supervision Department
Investment firms ICT risk framework; incident reporting; register submission; basic resilience testing Hellenic Capital Market Commission (HCMC)
Payment institutions / e-money institutions ICT risk framework; incident reporting; register submission; basic resilience testing Bank of Greece, Payment Systems Oversight
Insurance / reinsurance undertakings ICT risk framework; incident reporting; register submission Bank of Greece, Private Insurance Supervision
Critical ICT third-party providers (designated) Subject to direct oversight by Lead Overseer (ESA-appointed); cooperation with national authorities Lead Overseer (EBA/EIOPA/ESMA) + Bank of Greece

Greece-Specific Implications and Where to Engage

While DORA applies uniformly across the EU, its practical implementation in Greece involves specific supervisory dynamics and national considerations that compliance teams must account for.

Bank of Greece Expectations

The Bank of Greece has published dedicated guidance on DORA through its supervision portal, outlining how the regulation integrates with existing prudential supervision. As the competent authority for credit institutions, payment institutions, and insurance undertakings in Greece, the Bank of Greece is responsible for receiving and reviewing incident reports, ICT third-party registers, and resilience-testing results from supervised entities. The Bank of Greece DORA guidance confirms that the institution views digital operational resilience as a core component of its Supervisory Review and Evaluation Process (SREP), meaning deficiencies in DORA compliance may directly affect a bank’s capital and governance assessment scores.

Greek banks should establish a direct communication channel with their designated supervisory contact at the Bank of Greece for DORA-related submissions. Industry observers expect the Bank of Greece to issue further implementing guidance or circulars addressing Greek-specific operational details, including language requirements for incident-reporting templates and technical instructions for register submissions.

Cross-Border ICT Providers and Greek Legal Considerations

Many Greek banks rely on ICT service providers headquartered outside Greece, including major cloud platforms, core-banking software vendors, and cybersecurity firms. Under DORA, these cross-border arrangements require particular attention. Financial entities must ensure that contracts with foreign providers comply with DORA’s mandatory contractual provisions, including data-location transparency, audit-access rights, and exit-strategy clauses.

Where ICT providers process personal data of Greek clients, the broader Greek regulatory landscape, including GDPR enforcement by the Hellenic Data Protection Authority, adds a layer of compliance complexity. Greek banks should map the intersection between DORA’s ICT third-party requirements and existing data-protection obligations to avoid regulatory gaps.

Practical DORA Compliance Checklist for Greek Banks

The following checklist translates DORA’s requirements into time-bound actions for legal, compliance and technology teams at Greek banks. Each action is assigned a priority timeframe to help institutions structure their remediation efforts.

Immediate actions (now):

  • Confirm that the ICT risk-management framework has been formally approved by the management body and is documented in writing.
  • Verify that the register of ICT third-party service arrangements has been submitted to the Bank of Greece and the ESAs, and that it is accurate and complete.
  • Assign a named DORA compliance owner at senior management level with a clear mandate and reporting line to the board.

Short-term actions (1–3 months):

  • Review and update all ICT third-party contracts to include DORA-mandated clauses (audit rights, exit strategies, incident notification, sub-outsourcing restrictions).
  • Conduct a tabletop exercise simulating a major ICT incident, testing the incident-classification and reporting workflow against DORA’s criteria and timelines.
  • Map all critical and important functions and identify the ICT services underpinning them.

Medium-term actions (3–6 months):

  • Complete the annual cycle of basic digital operational resilience testing (vulnerability assessments, network security tests, scenario-based exercises).
  • For significant institutions: initiate planning for the next TLPT cycle, engage qualified external testers, and agree scope with the Bank of Greece.
  • Update business continuity and disaster recovery plans to reflect DORA’s response and recovery requirements.

Ongoing actions:

  • Maintain the ICT third-party register as a living document, update it when new providers are onboarded or existing arrangements change.
  • Feed incident outcomes and testing results back into the ICT risk-management framework as continuous improvements.
  • Monitor ESA publications for updated technical standards, reporting templates, and Q&A guidance.
Compliance Criterion Evidence Needed Priority
Board-approved ICT risk framework Signed policy document; board minutes recording approval Critical
ICT third-party register submitted Confirmation receipt from Bank of Greece / ESA portal Critical
Incident-reporting workflow tested Tabletop exercise report; completed template dry run High
DORA clauses in third-party contracts Contract amendment log; legal review sign-off High
Resilience testing completed (annual) Test reports; remediation tracker; management summary High

Obligations and Timelines by Entity Type

DORA’s obligations are proportionate, the scope and intensity of compliance requirements vary depending on the type, size and systemic importance of the financial entity. The table below summarises the key differences for entities most commonly supervised in Greece.

Entity Type Key DORA Obligations Next-Step Deadline
Credit institutions (banks) Full ICT risk framework; incident reporting; third-party register; basic testing (annual); TLPT (every 3 years for significant entities) TLPT planning: agree scope with Bank of Greece by next review cycle
Investment firms ICT risk framework (proportionate); incident reporting; third-party register; basic resilience testing Annual testing cycle; register maintenance ongoing
Payment institutions ICT risk framework; incident reporting; third-party register; basic resilience testing Annual testing cycle; register maintenance ongoing
Critical ICT third-party providers Subject to direct oversight by ESA-appointed Lead Overseer; must cooperate with oversight activities, audits and recommendations Ongoing, designation and oversight framework operational

The proportionality principle means that smaller investment firms or payment institutions may implement simplified ICT risk-management frameworks, but they are not exempt from the core obligations. The likely practical effect is that even smaller Greek financial entities will need to allocate dedicated compliance resources to DORA.

Risks, Enforcement and Penalties

DORA does not prescribe a harmonised fine schedule at the EU level for financial entities. Instead, enforcement is delegated to national competent authorities, in Greece, principally the Bank of Greece and the Hellenic Capital Market Commission, which retain the power to impose administrative penalties and remedial measures under their existing supervisory mandates. This means that a Greek bank found to be non-compliant with DORA’s ICT risk-management or incident-reporting obligations may face supervisory measures ranging from formal warnings and mandatory remediation orders to financial penalties calibrated under national law.

For critical ICT third-party providers designated at EU level, the Lead Overseer (one of the three ESAs) has the power to impose periodic penalty payments. Beyond formal sanctions, the reputational consequences of a publicised DORA deficiency, or, worse, an unreported major ICT incident, can erode client trust and trigger contractual liability with counterparties. Industry observers expect enforcement actions to accelerate through 2026 and 2027 as supervisors complete their first full cycle of DORA-focused inspections.

Hypothetical Scenario: A Greek Bank Responds to a Major ICT Incident

Consider a mid-sized Greek commercial bank that experiences a ransomware attack on its core-banking platform during a holiday weekend. The attack encrypts transaction databases and disrupts online-banking services for approximately 40,000 retail customers over a 16-hour period. Under DORA, the bank’s incident-response team must immediately classify the event using the ESA criteria, duration of service disruption, number of affected clients, data integrity impact, and geographic spread. Given the scale, the event meets the threshold for a major ICT incident.

The bank submits its initial notification to the Bank of Greece within the prescribed window, using the standardised reporting template. Over the following days, it files intermediate and final reports detailing root-cause analysis, containment measures, recovery actions and lessons learned. Simultaneously, the compliance team reviews whether the ICT provider hosting the affected platform met its contractual obligations under the DORA-compliant service agreement, including incident-notification timelines and recovery-time commitments. The incident report and remediation plan are incorporated into the bank’s ICT risk-management framework review, informing the next cycle of resilience testing.

Conclusion and Recommended Next Steps

Europe’s banking operational-resilience deadline is no longer a future milestone, it is an active supervisory reality for every Greek bank and regulated financial entity. DORA compliance is not a one-off project but an ongoing governance obligation that requires continuous investment in ICT risk management, incident preparedness, third-party oversight and resilience testing.

Greek banks should prioritise the following five actions immediately:

  1. Audit the completeness and accuracy of the ICT third-party register already submitted.
  2. Confirm board-level sign-off on the ICT risk-management framework.
  3. Test the incident-reporting workflow through a realistic tabletop exercise.
  4. Review and amend all critical ICT third-party contracts for DORA-mandated clauses.
  5. Schedule the next cycle of digital operational resilience testing, including TLPT where applicable.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Ioannis Charaktiniotis at I. Charaktiniotis & Partners Law Firm, a member of the Global Law Experts network.

Sources

  1. EUR-Lex, Regulation (EU) 2022/2554 (DORA)
  2. European Banking Authority, Operational Resilience
  3. Bank of Greece, DORA / Digital Operational Resilience Act for the Financial Sector
  4. EIOPA, DORA Overview
  5. European Banking Federation, Cyber Resilience
  6. Bank of England, Operational Resilience of the Financial Sector

FAQs

What is the DORA timeline for financial firms?
DORA, Regulation (EU) 2022/2554, was published on 27 December 2022, entered into force on 16 January 2023, and became directly applicable across all EU Member States on 17 January 2025. Financial entities were required to have all core obligations in place by the applicability date. The first submission of ICT third-party registers to competent authorities and the ESAs was due by 30 April 2025.
Under Articles 17–23 of DORA, a major ICT-related incident is one that meets classification thresholds set by the ESAs. These thresholds consider factors such as the duration of service disruption, the number of affected clients or counterparties, data losses, the geographic spread of the impact, and whether critical or important functions were compromised. When an incident qualifies as major, the financial entity must submit initial, intermediate and final reports to its national competent authority, in Greece, typically the Bank of Greece, using a standardised reporting template.
Yes. DORA requires all financial entities to conduct basic digital operational resilience testing, including vulnerability assessments, network security testing and scenario-based exercises, on at least an annual basis. Systemically important entities designated by the Bank of Greece must also undergo advanced threat-led penetration testing (TLPT) at least every three years. The Bank of Greece has confirmed that digital operational resilience is integrated into its supervisory review process.
DORA imposes detailed third-party risk-management obligations under Articles 28–44. Financial entities must maintain a comprehensive register of all ICT third-party service arrangements, conduct due diligence before entering into new contracts, and ensure that agreements include mandatory clauses covering audit rights, exit strategies, sub-outsourcing restrictions, data-location transparency and incident notification. Contracts that do not include these provisions must be amended to achieve DORA compliance.
DORA and the Cyber Resilience Act (CRA) address different dimensions of digital security. DORA focuses on the operational resilience of financial-sector entities, their ability to withstand, respond to and recover from ICT disruptions. The CRA, by contrast, targets the cybersecurity of products with digital elements (hardware and software) placed on the EU market. The CRA entered into force on 10 December 2024, with certain vulnerability-reporting obligations applying from 11 September 2026 and full product-security requirements expected from 2027. Financial firms that manufacture or market digital products may need to comply with both frameworks in parallel.
Greek banks should focus on six priority actions within the next 30 days: map all critical and important business functions and the ICT services supporting them; verify the accuracy of the ICT third-party register; review and update the incident-classification and reporting workflow; assign a named DORA compliance owner at senior management level; begin documenting evidence of compliance for each DORA pillar; and schedule the next round of basic digital operational resilience testing.
A financial entity may take into account testing conducted by its ICT third-party provider, but this does not relieve the entity of its own testing obligations. Regulators expect supervised institutions to exercise independent oversight and, where critical or important functions are involved, to validate provider-supplied test results through their own assessment. Greek banks should document the scope, methodology and limitations of any provider-supplied test results and demonstrate to the Bank of Greece that supervisory expectations for independent assurance have been met.
how to file fc-trs online
By Global Law Experts

posted 14 minutes ago

europes insolvency harmonisation drive
By Global Law Experts

posted 52 minutes ago

irelands nis2 reckoning
By Global Law Experts

posted 52 minutes ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Europe's Banking Operational-resilience Deadline: What Greek Banks Must Do Now

Send welcome message

Custom Message