DORA Compliance Deadlines Are Quietly Creating a Financial-Services Hiring Wave
DORA's 2026 enforcement calendar - the Register of Information deadline, the first Critical ICT Provider designations and the coming TLPT wave - is forcing banks and insurers to hire ICT risk and third-party risk talent now. Here's the signal, before it hits job boards.
TL;DR
DORA (the EU's Digital Operational Resilience Act) has been fully applicable since 17 January 2025, and 2026 is the year enforcement stops being theoretical [1] [3]. Financial entities filed their second annual Register of Information by 31 March 2026 [5], the European Supervisory Authorities designated the first 19 Critical ICT Third-Party Providers on 18 November 2025 [2], and the first wave of mandatory Threat-Led Penetration Testing notifications is landing this year, with completion due by January 2028 [6]. Each of those milestones forces a bank, insurer, investment firm or payment institution to prove it has someone accountable for ICT risk, third-party concentration risk and resilience testing - and more than 22,000 EU financial entities are in scope [1]. That is a hiring wave for ICT risk managers, third-party risk leads, operational resilience specialists and Digital Operational Resilience Officers that shows up in regulatory filings and enforcement calendars weeks before it shows up as a job ad [7] [9]. Recruitment agencies that read the DORA calendar the way they'd read a funding round get a genuine, timely reason to call financial-services clients first. boilr.ai turns exactly that kind of dated regulatory signal into a scored, ready-to-verify outreach task.
Why DORA Is a BD Signal, Not Just a Compliance Story
Most regulatory deadlines are a one-off headache for a client's legal team. DORA is different because it is structured as a recurring, dated calendar of obligations that each require a named, accountable person - and that accountability has to sit somewhere in the org chart. Five things make this a recruitment opportunity rather than just background noise:
- It applies to a huge, defined universe of clients: more than 22,000 financial entities across the EU - banks, insurers, investment firms, payment institutions and crypto-asset service providers - are in scope, plus their ICT third-party providers [1].
- The grace period is over: national competent authorities have moved from reviewing paperwork to active enforcement reviews, cross-checking Register of Information data and issuing the first compulsion payments [3].
- Every pillar needs a named owner: DORA's five pillars (ICT risk management, incident reporting, resilience testing, third-party risk management and information sharing) each require management body accountability, not just a policy document [8].
- Specialist candidates are scarce: compensation for DORA-related roles has tightened materially because there simply aren't many candidates with substantive prior DORA implementation experience [7].
- The strongest candidates aren't job-hunting: senior compliance and resilience professionals are typically approached, not applying, which is exactly the gap a well-networked agency fills [9].
The Roles This Is Actually Creating
"DORA hiring" is not one job title. It is a cluster of roles that finance and insurance clients are standing up or expanding right now, often for the first time as a dedicated headcount rather than a shared responsibility:
| Role | What it owns under DORA | Typical hiring trigger |
|---|---|---|
| ICT Risk Manager | Identifying, protecting against and recovering from ICT risk (Pillar 1) | Board-level ICT risk framework build-out |
| Third-Party Risk Manager | The Register of Information and vendor concentration risk (Pillar 4) | Annual RoI submission cycle |
| Digital Operational Resilience Officer (DORO) | Coordinating the entire DORA programme end to end | Regulator asking "who owns this?" |
| Resilience Testing / TLPT Lead | Scoping and running Threat-Led Penetration Testing (Pillar 3) | First TLPT notification from the supervisor |
| ICT Incident Reporting Specialist | Classifying and reporting major incidents (Pillar 2) | A near-miss incident that exposed a reporting gap |
| Regulatory/Compliance Programme Manager | Cross-functional DORA remediation and audit readiness | A supervisory review finding gaps |
The 2026 DORA Calendar: Where the Hiring Triggers Actually Sit
The reason this is a usable BD signal rather than a vague "compliance is important" pitch is that DORA runs on a public, dated calendar. Each date below is a moment when a client either has to already have the right person in place, or is scrambling because it doesn't:
| Date / window | What happens | Why it triggers hiring |
|---|---|---|
| 17 January 2025 | DORA becomes fully applicable across the EU [1] | Baseline - every in-scope entity needed ICT risk governance from day one |
| 18 November 2025 | ESAs designate the first 19 Critical ICT Third-Party Providers [2] | Every financial entity using a designated provider must reassess concentration risk |
| 31 March 2026 | Second annual Register of Information submission deadline, data as of 31 Dec 2025 [5] | Firms without a dedicated third-party risk lead scramble to compile vendor contract data |
| Throughout 2026 | First wave of TLPT notifications from supervisors; supervisory reviews move to active enforcement [3] [6] | Entities identified as "significant" need a resilience testing lead within a tight notification window |
| H2 2026 | First formal fines expected, based on 2025-2026 supervisory assessment work [3] | A fine or public censure at a peer firm is the fastest way to unlock budget for headcount |
| January 2028 | First TLPT completion deadline for "significant" entities [6] | A 9-14 month testing cycle means provider procurement and internal ownership must start now |
This calendar is exactly the kind of dated, verifiable trigger that outperforms a generic cold call. A recruiter who can say "you're using a newly designated critical provider" or "your RoI deadline just passed and you don't have a named third-party risk lead" is opening a conversation a client actually wants to have. Three questions turn the calendar into a call:
- Which trigger just fired? A passed RoI deadline, a fresh CTPP designation or a TLPT notification are all specific, dated events, not vague "compliance season" talk.
- Who's accountable right now? If the client can't name an owner, that's the gap your desk exists to fill.
- What's the honest urgency? Tie it to the real penalty structure below, not an inflated one - credibility here is the whole pitch.
What's Actually at Stake for Clients (So You Can Explain Urgency Credibly)
Understanding the penalty structure matters because it lets your consultants have a genuinely informed conversation instead of vague scaremongering - and getting it wrong damages credibility fast:
- Financial entities: DORA itself sets no EU-wide fine ceiling - it requires penalties that are "effective, proportionate and dissuasive," leaving the actual amount to each member state's national law [4]. Some national regimes go well into eight figures.
- Critical ICT Third-Party Providers: face a specific EU-wide penalty of up to 1% of average daily worldwide turnover, charged daily, capped at six months [4].
- Individuals: personal liability amounts are set by national law, not a single EU figure [4] - which is precisely why boards want a named, accountable owner rather than a shared responsibility.
- Beyond fines: NCAs also hold powers of public censure and authorisation withdrawal, which matters more to a board than a fine amount in many cases [3].
- Note the common mistake: a lot of secondary content online cites "2% of turnover" for DORA - that figure actually belongs to the separate NIS2 Directive, not DORA [4]. Get this wrong on a client call and you lose credibility on the rest of the pitch.
Manual Regulatory Tracking vs a Signal-Led BD Approach
Most agencies either ignore regulatory calendars entirely, or someone senior tracks a handful of them in a personal spreadsheet that nobody else sees. Neither scales once you're trying to cover a full book of financial- services clients across banking, insurance and asset management:
| Task | Manual approach | boilr.ai-powered approach |
|---|---|---|
| Spotting a client's new DORA-related job posting | Checking job boards after the role is already public | Signals surfaces hiring velocity often 48-72 hours before job boards |
| Knowing which clients use a newly designated CTPP | Nobody notices until a client mentions it | Companies tracks vendor and tech-stack signals as part of account enrichment |
| Remembering which financial-services clients need a DORA-led pitch | Lives in one consultant's head, lost on churn | Company Brain stores it as shared agency memory |
| Turning the calendar into outreach | Ad hoc, inconsistent across the desk | Tasks packages the signal into a verification-ready draft |
boilr.ai is not a compliance or legal tool and doesn't tell a client whether they're actually DORA-compliant. What it does is make sure a hiring-relevant signal - a new ICT risk requisition, a leadership change on a client's risk function, a tech-stack shift tied to a designated provider - reaches the right consultant's desk before a competitor spots the same job ad.
A Practical 5-Step Plan to Build a DORA-Aware Financial-Services Desk
- Map your financial-services book against DORA scope: flag every client that's a bank, insurer, investment firm, payment institution or crypto-asset service provider.
- Build a live DORA calendar: RoI deadlines, TLPT notification windows and known CTPP designations, cross-referenced against your client list.
- Define your DORA-role ICP: ICT Risk Manager, Third-Party Risk Manager, DORO, TLPT Lead, Incident Reporting Specialist - build search strings and a candidate pool for each before the brief lands.
- Pre-build a passive candidate pipeline: the strongest candidates aren't applying anywhere, so start network mapping now rather than after a mandate arrives [9].
- Turn the calendar into a call list: prioritise clients approaching a dated trigger (RoI deadline just passed, TLPT notification received, using a newly designated provider) over generic outreach.
KPIs to Track While You Build the Desk
| Metric | What it tells you | Target |
|---|---|---|
| % of financial-services clients mapped against DORA scope | How complete your account intelligence is | 100% within 2 weeks |
| Number of pre-built DORA-role candidate pools | Readiness to respond fast when a mandate lands | 6+ role pools before Q1 |
| Time from signal to first outreach | Whether you're beating job boards or reacting to them | <72 hours |
| DORA-led BD conversations opened per month | Whether the calendar is being used as a BD asset | Track and grow monthly |
How boilr Powers a DORA-Aware BD Motion
boilr.ai runs as one AI sales employee per consultant, watching your financial-services accounts and turning a regulatory calendar into a scored, ready-to-verify outreach task instead of something a consultant has to remember to check manually:
- Signals: flags new hiring activity and job-posting velocity on tracked accounts, often 48-72 hours before it appears on job boards.
- Companies: enriches and monitors your target and client accounts, including sector and tech-stack context relevant to DORA exposure.
- Company Brain: keeps agency-wide memory of which clients have been briefed on DORA-related roles and what messaging has worked - it survives consultant turnover.
- ICP: lets you flag in-scope financial entities as a priority segment while this enforcement cycle plays out.
- Candidates: helps pre-build a pool against specialist DORA role profiles ahead of a live brief.
- Tasks: converts the research into a verification-ready outreach draft, so the consultant reviews and sends rather than starting from a blank page.
- Integrations: works alongside Bullhorn, RecruiterFlow and your existing CRM, so the account picture lives where your desk already works.
What boilr does not do: give legal or regulatory compliance advice, confirm whether a specific client is actually DORA-compliant, or replace a specialist compliance search consultant's own network. It makes sure the signal reaches the right desk fast enough to act on it.
Turn the DORA enforcement calendar into your next financial-services client conversation. See how boilr.ai flags the accounts that need it, before the job ad goes live.
5 Mistakes Agencies Are Making With DORA Right Now
Mistake #1: Waiting for the Job Ad
Why it fails: by the time a DORA-related role hits a job board, in-house recruiting and competitor agencies have often already been briefed.
Fix: track the regulatory calendar itself as the leading indicator, not the job posting.
Mistake #2: Treating "DORA Compliance" as One Job Title
Why it fails: DORA spans at least six distinct role profiles with different skill sets, from ICT risk management to TLPT scoping.
Fix: build separate ICPs and candidate pools per role, not one generic "compliance" search.
Mistake #3: Citing the Wrong Penalty Figures
Why it fails: quoting NIS2's 2% of turnover figure as if it were DORA's penalty undermines credibility with a client's legal or risk team the moment they check [4].
Fix: know the actual CTPP penalty (1% of average daily turnover, capped at six months) and be explicit that financial-entity fines are set nationally.
Mistake #4: Ignoring the Third-Party Provider Angle
Why it fails: the 19 designated CTPPs create a knock-on hiring need at every financial entity that uses them, not just at the providers themselves [2].
Fix: map which of your clients use a designated provider and lead with that specific exposure.
Mistake #5: Only Pitching Compliance, Never BD
Why it fails: treating this purely as a "we understand regulation" credibility play wastes the dated, client-specific hook it actually is.
Fix: route the calendar and signal data to BD conversations, not just a compliance briefing document nobody reads.
A 2-Week Rollout Plan
Days 1-4: Map and Prioritise
Segment your financial-services book by DORA scope. Flag clients with a recent RoI deadline, a TLPT notification, or exposure to a newly designated CTPP.
Days 5-8: Build the Role Pools
Stand up candidate search strings and a light passive pipeline for each of the six DORA-related role profiles before a live brief lands.
Days 9-11: Brief the Desk
Train every consultant covering financial services on the calendar, the correct penalty figures, and the six role profiles - not just the specialist compliance desk.
Days 12-14: Open the Conversations
Prioritise the 10-15 clients where the calendar gives you a genuine, dated reason to call, and book the first round of DORA-aware BD conversations.
Frequently Asked Questions
What is DORA and why is it creating hiring demand now?
DORA (the Digital Operational Resilience Act, Regulation (EU) 2022/2554) is an EU regulation that harmonises ICT risk management rules for the financial sector. It has been fully applicable since 17 January 2025 [1], and 2026 is the year national supervisors moved from an informal tolerance period to active enforcement, forcing more than 22,000 in-scope financial entities to demonstrate named accountability for ICT risk, incident reporting, resilience testing and third-party risk [3] [1].
Which roles are recruitment agencies most likely to be briefed on?
ICT Risk Manager, Third-Party Risk Manager, Digital Operational Resilience Officer (DORO), Resilience Testing / TLPT Lead, ICT Incident Reporting Specialist and Regulatory/Compliance Programme Manager are the roles most directly created or expanded by DORA's five pillars [8] [9].
What is the Register of Information and why does it matter for BD?
The Register of Information is the document every in-scope financial entity must submit detailing its contractual arrangements with ICT third-party providers. The second annual submission deadline was 31 March 2026, with data reflecting the entity's position as of 31 December 2025 [5]. Firms without a dedicated third-party risk owner tend to scramble ahead of this deadline every cycle - a predictable, recurring BD trigger.
What happened with Critical ICT Third-Party Providers?
On 18 November 2025, the European Supervisory Authorities designated the first 19 Critical ICT Third-Party Providers (CTPPs) under DORA, covering major cloud, data centre and telecommunications providers [2]. Any financial entity using one of these providers has to reassess its concentration and exit-strategy risk, which is a specific, client-provable reason to open a conversation.
What is Threat-Led Penetration Testing (TLPT) and when is it due?
TLPT is mandatory advanced security testing under DORA Articles 26-27 for entities identified by their supervisor as "significant." A full cycle from provider procurement to attestation takes 9-14 months, the first wave of supervisor notifications is landing in 2026, and the first completion deadline is January 2028 [6]. That timeline means clients need a resilience testing owner well before the deadline, not after.
What are the actual penalties for DORA non-compliance?
DORA itself sets no single EU-wide fine amount for financial entities - it requires penalties that are "effective, proportionate and dissuasive" under national law [4]. Critical ICT Third-Party Providers face a specific EU-wide penalty of up to 1% of average daily worldwide turnover, charged daily and capped at six months [4]. The commonly cited "2% of turnover" figure belongs to the separate NIS2 Directive, not DORA [4].
How does boilr help agencies act on the DORA hiring signal?
boilr.ai tracks your financial-services client accounts and flags relevant signals, including hiring activity and job-posting velocity often 48-72 hours before job boards, so consultants see the opportunity before competitors do. The Company Brain keeps DORA-related account context as shared agency memory, and Tasks turns it into a verification-ready outreach draft. It is not a substitute for legal or regulatory compliance advice.
Sources
Information sourced from public regulatory publications, law firm briefings and industry reports as of September 2026.
- Regulation DORA - What Is DORA? Complete Guide to EU Digital Resilience
- European Banking Authority - ESAs Designate Critical ICT Third-Party Providers Under DORA
- Regulation DORA - DORA in 2026: The Grace Period Is Over
- Regulation DORA - DORA Penalties 2026: Exact Amounts and Timeline
- ComplianceHub - DORA Register of Information Annual Submission 2026
- financialregulations.eu - DORA Threat-Led Penetration Testing (TLPT) Guide
- FD Capital - DORA Compliance Officer Recruitment
- Nemko Digital - DORA Compliance 2026: Key Requirements Explained
- International Compliance Association - Digital Operational Resilience Officer: Key Skills and the Role's Importance in 2026