< Back to all clusters
[BUSINESS] · 3 sources

EU financial firms lag on DORA compliance amid sweeping regulatory overhaul

A recent analysis shows that 96% of European financial‑services firms are still not fully compliant with the Digital Operational Resilience Act (DORA), which requires measurable recovery objectives and proven backup immutability to protect against cyber‑attacks and system failures. Regulators are shifting focus from mere policy intent to demonstrable results, demanding periodic testing of recovery plans and realistic simulations.

At the same time, an Accenture study identifies more than 70 regulatory milestones slated for 2026‑2029, highlighting a convergence of EU rules such as the AI Act, Cyber Resilience Act, PSD3, Digital Euro, and others. The study warns that fragmented compliance efforts could lead to inefficiencies, urging financial institutions to adopt integrated governance of data, technology risk and customer protection across banking, capital‑markets and insurance sectors.