The Digital Operational Resilience Act (DORA) entered into force in January 2023, with the compliance deadline set for 17 December 2024. As that deadline approached and passed, Cyprus's financial supervisory authority—the Central Bank of Cyprus and the Cyprus Securities and Exchange Commission (CySEC)—began conducting thematic and routine inspections of Cypriot investment firms (CIFs) and electronic money institutions (EMIs) to assess readiness and adherence.
Early enforcement activity reveals a pattern of common shortcomings. Many firms struggled with the foundational requirement of mapping their information and communication technology (ICT) infrastructure comprehensively. DORA Article 6 requires entities to identify and document all critical or important functions supported by ICT systems, but inspectors have found that smaller and mid-market CIFs and EMIs often lack adequate asset inventories or have only partial records of legacy systems, third-party dependencies, and cloud infrastructure. This gap undermines the entire framework, since resilience testing, incident management, and outsourcing controls all depend on accurate baseline data.
Third-party risk governance emerged as a second major area of regulatory attention. Under DORA's Article 28 regime, firms must conduct due diligence on critical ICT third-party service providers, monitor their performance continuously, and maintain contractual rights to audit and exit. Inspectors found that many CIFs and EMIs had extended lengthy transition arrangements for legacy providers without formalized contingency plans or exit strategies. Some had not updated their outsourcing agreements to include DORA-specific obligations around incident reporting and resilience testing.
Incident management and reporting protocols were frequently inadequate. DORA Article 19 and related regulatory technical standards require firms to report significant ICT-related incidents to supervisors within specific timeframes—24 hours for major incidents. Several firms inspected lacked clear internal escalation procedures, had not designated a single point of contact for incident notification, or maintained only sporadic incident logs. This was particularly evident in firms that had outsourced IT operations but retained minimal in-house expertise to recognize or categorize an incident appropriately.
Governance and accountability gaps also surfaced. DORA requires senior management and the management body to take active ownership of ICT risk strategy and to allocate adequate resources for compliance and testing. Inspections revealed instances where responsibility for DORA implementation was diffused across multiple departments or delegated entirely to an external consultant without sustained internal ownership or board-level oversight.
Finally, a number of CIFs and EMIs underestimated the scope of ICT security and testing obligations. DORA's Article 20 (advanced testing) and Article 18 (ICT security) requirements—including vulnerability assessments, penetration testing, and adversarial testing for larger or systemically important firms—were met only partially. Some firms conducted testing but had not fully documented findings, remediation timelines, or governance follow-up.
Key takeaways for Cypriot financial institutions:
— Complete and update ICT asset inventories and maintain them dynamically
— Revise third-party contracts to align with DORA and establish clear exit and contingency protocols
— Establish formal, documented incident reporting channels and response procedures
— Allocate explicit board-level accountability for DORA governance and ICT resilience
— Schedule and document regular resilience testing, including scenario-based and adversarial assessments where required
Regulatory expectations are clear: DORA compliance is not a one-time exercise but an embedded operational and governance discipline. Firms that treat it as a checkbox risk enforcement action, remedial orders, and potential sanctions.




