Skip to content
Log inRegister

The Vendor Register Has Become the Audit: DORA and NIS2 Enforcement in 2026

Dr. Abeer Alshammari · Published 8/21/2026

IntermediateProfessionalsCISOsExecutives

Two European regimes that were drafted as risk-management law have quietly narrowed into something far more testable: a documentation audit. In 2026 the question supervisors put to financial entities and critical-infrastructure operators is no longer "do you manage third-party risk?" It is "show us the register, and let us check it against itself."

What DORA's second reporting cycle exposed

The Digital Operational Resilience Act has applied to EU financial entities since January 2025. Its Register of Information -- a structured inventory of every contractual arrangement for ICT services, including subcontracting chains -- is filed annually with national competent authorities and forwarded to the European Supervisory Authorities. The 2026 cycle ran through March, with the ESAs performing consistency and quality checks in April and returning deficient registers for remediation.

The benchmark for how difficult this is comes from the ESAs' 2024 dry-run exercise. Of nearly a thousand participating firms, only around 6.5% passed all 116 data-quality checks. The more useful detail is that roughly half of the remainder failed fewer than five. The failures were concentrated and correctable rather than evidence of systemic ignorance, and they clustered exactly where you would predict: missing subcontractor entities, incomplete contract data, and criticality classifications that did not reconcile with what the firm had recorded elsewhere.

That matters well beyond a compliance score. The aggregated registers are the input the ESAs use to designate Critical Third-Party Providers for direct EU-level oversight under DORA Article 31, and the input national authorities use to see concentration risk at entity level. A register with gaps is not merely an incomplete filing. It is a distortion in the supervisory picture, and it distorts in the direction of understating exposure.

NIS2 reached the same place from a different direction

NIS2 is not a reporting regime in the DORA sense, but its enforcement in 2026 has converged on the same evidence. As of May 2026, 21 of 27 member states had transposed the directive into national law, and the European Commission had referred seven member states to the Court of Justice for failing to do so. Audit programmes are now running in a majority of transposed states, aimed at essential entities.

Article 21 lists supply chain security among the ten baseline risk-management measures, and the first publicly reported penalties have landed in Belgium, Italy, Hungary and Lithuania. What is instructive is their size: tens to low hundreds of thousands of euros, far below the headline ceilings of 10 million euros or 2% of global turnover for essential entities. These are not deterrence fines. They are the fines a regulator issues when an entity could not produce documentation on request.

Why registers fail

In practice, three failure modes account for most of it. The first is that the register is assembled by procurement from contract metadata, while criticality is assessed by security from a different system, and nobody reconciles the two. The second is that subcontracting is captured only to the first tier, because that is the only tier the contract names. The third is that the register is treated as an annual deliverable rather than a live control, so it is accurate on the filing date and decaying by week three.

None of these are technology problems. They are ownership problems, and they persist because a register sits across procurement, legal, security and the business without a single accountable owner.

The governance reading

There is a pattern worth naming here. When a regulator cannot practically assess whether your risk management is good, it assesses whether your record of your risk management is complete -- because completeness is auditable and judgement is not. Over time, the register stops being a byproduct of third-party governance and becomes the object of it.

The healthy response is not to resent that. It is to recognise that an organisation which genuinely knows its dependencies can produce the register almost as a side effect, and an organisation which cannot produce the register almost certainly does not know its dependencies. The filing is a proxy, but it is not a bad one.

Three things worth doing this quarter

First, assign one accountable owner for the third-party register, with authority over both the contract data and the criticality classification. Reconciliation between the two should be a scheduled control, not a pre-filing scramble.

Second, extend visibility past the first tier for your critical services specifically. You do not need full fourth-party mapping across the estate; you need it for the handful of arrangements where a subcontractor failure would be indistinguishable from a provider failure.

Third, run your own version of the data-quality checks before the supervisor does. The DORA validation rules are published, and the same discipline -- referential integrity, no orphaned entities, classifications that agree across systems -- applies just as well to a NIS2 supply chain risk register that has no prescribed format at all.

The register is now the audit. Building it as a control rather than a filing is what separates the organisations that will pass from the ones that will remediate.

Try it yourself

An interactive CyberAbeer experience for this topic is in development.

Coming soon
Back to insights