Six months after the EU’s Digital Operational Resilience Act (DORA) came into effect, a new Censuswide survey commissioned by Veeam Software has found that 96% of EMEA financial services organizations still feel their current level of data resilience falls short.
The survey, which gathered insights from senior IT decision-makers at financial services companies in the UK, France, Germany, and the Netherlands, underscores the ongoing challenges faced by the sector as it adapts to DORA.
While DORA has been embedded as a strategic priority across the financial sector, many organizations are still navigating the path to full compliance. The survey found that 94% of organizations now rank DORA higher in their organizational priorities than they did in the month before the deadline, with 40% calling it a current ‘top digital resilience priority’. Half of the respondents said DORA requirements have been integrated into their broader resilience programmes, while 39% reported it remains a central focus.
Even with 94% of organizations reporting that they are clear on the steps they need to take, many are facing unforeseen challenges, including:
- 41% report increased stress and pressure on IT and security teams.
- 37% are dealing with higher costs passed on by ICT vendors.
- 22% believe the volume of digital regulation is becoming a barrier to innovation or competition.
- 20% have yet to secure the necessary budget to meet DORA requirements.
DORA is still a work in progress
Despite the deadline having passed, a significant proportion of organizations are still working to meet key DORA requirements:
- 24% have not established recovery and continuity testing.
- 24% have not implemented incident reporting.
- 24% have not identified a DORA implementation lead.
- 23% have not conducted digital operational resilience testing.
- 21% have not ensured backup integrity and secure data recovery.
Methodology
Censuswide conducted this research between June 5 and June 11, 2025. The survey included 404 senior IT decision makers and heads of compliance at financial service companies and banks with over 500+ employees across the UK, France, Germany, and the Netherlands. Although the UK is a non-EU member state, it was included due to its significant business ties with EU countries that fall under DORA. An additional criterion ensured that all UK respondents worked for organizations that currently fall under DORA. The study was nationally representative.






