OneClickComply
    Back to BlogStandards & Frameworks

    DORA Compliance for Payment Institutions: What to Buy (2026)

    21 August 2026
    DORA compliance for payment and e-money institutions

    TL;DR

    • DORA compliance for payment institutions has been mandatory since 17 January 2025 for EU-regulated payment and e-money firms.
    • OneClickComply's automated compliance platform wins for continuous evidence collection instead of rebuilding audits by hand. Buy.
    • Vendor risk management software is required, not optional — DORA's Register of Information turns third-party tracking into a live document. Buy.
    • Threat-led penetration testing runs on a 3-year cycle for significant institutions — start scoping it in 2026, not after a supervisor asks.

    DORA compliance for payment institutions and e-money firms comes down to five things supervisors check in 2026: ICT risk management, incident reporting, resilience testing, third-party oversight, and information sharing. This guide breaks down what to build first, what to buy, and what a lean compliance team can safely skip.

    Why this matters

    DORA — Regulation (EU) 2022/2554 — has applied to EU financial entities, including payment institutions and e-money institutions, since 17 January 2025. It replaced a patchwork of national ICT rules with one operational resilience standard built around five pillars: ICT risk management, incident reporting, resilience testing, third-party risk, and information sharing.

    Payment institutions and EMIs are named explicitly in DORA's scope, not swept in as an afterthought. If your firm moves money for EU customers or holds an EU passport, a supervisor can ask for your Register of Information, your incident log, and your last resilience test results in 2026 — and expects a live system behind the answer, not a folder of PDFs pulled together the week before.

    UK-only firms with zero EU exposure sit outside DORA and follow FCA and PRA operational resilience rules instead, a related but separate framework. Read DORA compliance for UK financial services firms if you're still mapping which rules apply to your entity structure.

    Who this is for

    This guide is for compliance leads, COOs, and founders at payment institutions and e-money institutions authorised in the EU or EEA, plus UK-based payment firms with EU branches, subsidiaries, or passporting arrangements. If your institution reports to a national competent authority anywhere in the EU, DORA compliance for payment institutions isn't optional reading — it's the standard your next supervisory review measures you against.

    It's not for UK firms with no EU footprint at all. Those institutions answer to the FCA's operational resilience rules, which share DNA with DORA but aren't the same regulation, so don't force-fit a DORA checklist onto a purely domestic licence.

    What to look for in DORA compliance for payment and e-money institutions

    Most payment institutions already have pieces of this in place — an incident process here, a vendor list there. DORA asks you to prove those pieces connect into one live system, reviewed continuously rather than dusted off before an audit.

    ICT risk management framework coverage

    Your ICT risk framework has to cover every system that processes payments, not just the ones facing customers. Supervisors want risk ownership mapped to a named function, reviewed at least annually, and updated whenever you change core payment infrastructure.

    Third-party and critical ICT provider mapping

    Payment institutions run on outsourced infrastructure: card processors, cloud hosting, fraud screening APIs. DORA requires a Register of Information listing every ICT third party, their criticality, and any sub-outsourcing chain beneath them — miss a sub-processor and the register is incomplete on day one.

    Incident classification and reporting timelines

    DORA sets strict windows for reporting major ICT-related incidents to your regulator — hours, not days, once an incident is classified as major. A payment institution processing thousands of transactions an hour needs a classification process that runs faster than the reporting clock, not one that starts ticking before anyone notices.

    Digital operational resilience testing, including TLPT

    Basic testing — vulnerability scans, scenario-based tests — applies to every in-scope entity. Threat-led penetration testing (TLPT), a live intelligence-led attack against production systems, applies only to institutions designated significant, on a three-year cycle. Know which bucket you're in before you budget for either.

    Continuous evidence and audit-readiness

    A Register of Information, an incident log, and resilience test results only help if they're current the day a supervisor asks. Point-in-time audit prep — updating everything two weeks before a review — is the most common gap OneClickComply sees in payment and e-money firms mid-DORA rollout.

    Top picks for closing DORA compliance gaps

    Four ways payment and e-money institutions actually close DORA gaps in 2026, ranked by what holds up under supervisory review.

    Automated DORA compliance platform — the safe pick An automated platform keeps your ICT risk register, incident log, and third-party register in one system instead of five spreadsheets and a shared drive. DORA compliance software for financial services firms built for this maps evidence collection to each of DORA's five pillars automatically, so your team isn't rebuilding the Register of Information from scratch every audit cycle. OneClickComply runs this continuously rather than as a once-a-year sprint before a review. Verdict: Buy — the biggest single force-multiplier for a payment institution managing DORA compliance in 2026.

    Vendor risk management software — the one regulators check first DORA's Register of Information demands live tracking of every ICT third party and its sub-outsourcing chains, ranked by criticality. Vendor risk management software for fintech companies keeps that register current instead of a static document nobody touches after the initial audit. Third-party ICT failure is one of the most commonly flagged incident triggers among EU supervisors since DORA took effect. Verdict: Buy.

    Threat-led penetration testing (TLPT) — the resilience test you can't fake Institutions designated significant under DORA must run TLPT against live production systems at least once every three years, scoped using real threat intelligence rather than a generic pen test brief. Budgeting and scoping this takes months, not weeks — start in 2026 if your next cycle lands in 2027. Verdict: Consider — mandatory if you're designated significant, worth doing anyway even if you're not yet on that list.

    Spreadsheets and email threads — the false economy Tracking incidents, vendor contracts, and test results across spreadsheets and inbox folders works fine until a supervisor asks for a timestamped audit trail with version history. DORA's documentation moves fast, and a spreadsheet with no change log doesn't survive that kind of review. Verdict: Skip — tolerable for a five-person startup, a liability for a licensed payment institution.

    What to avoid

    • Treating DORA like a yearly certification. DORA is inspected on an ongoing basis, not renewed once a year like Cyber Essentials — continuous monitoring beats point-in-time audit prep every time.
    • Assuming "UK-headquartered" means out of scope. If you passport into the EU, run an EU subsidiary, or serve EU customers through an EU-regulated entity, DORA compliance for payment institutions applies regardless of where your head office sits.
    • Outsourcing your third-party register to a consultant without owning the underlying data. Supervisors ask the regulated institution to produce the Register of Information on request, not the consultant who built it.

    See how OneClickComply handles DORA

    Automated evidence collection and live third-party registers for payment and e-money institutions.

    Verdict comparison table

    ApproachBest forICT risk mappingThird-party registerVerdict
    Automated compliance platformFirms wanting one system across all five pillarsContinuousAutomatedBuy
    Vendor risk management softwareFirms with 10+ ICT third partiesPartialContinuousBuy
    TLPT providerInstitutions designated significantN/AN/AConsider
    Spreadsheets and emailVery early-stage firms onlyManualManual, stale fastSkip

    Frequently asked questions

    One last thing

    DORA doesn't stop at institutions the EU directly regulates. Title V of the regulation lets EU authorities designate critical ICT third-party providers for direct oversight, including non-EU providers, if enough EU financial entities depend on them. A UK-based payment processor with no EU licence of its own can still land inside DORA's oversight net simply because its EU clients rely on it. Check your customer base before assuming DORA compliance for payment institutions is someone else's problem in 2026.

    Key DORA numbers

    17 Jan 2025

    DORA enforcement start date

    3 years

    TLPT testing cycle for significant entities