Who, what, when, where, why: Since the Digital Operational Resilience Act (DORA) became fully applicable on 17 January 2025, banks and regulated financial firms across the European Union have moved from planning to operationalizing zero‑trust networking (ZT). By September 2026, security teams, vendors and supervisors report tangible progress on ZTNA, microsegmentation and telemetry — driven by DORA’s stricter ICT risk-management, third‑party oversight and mandatory incident-reporting requirements.
Why this matters now
DORA does not prescribe a single technical stack, but its supervisory outcomes — demonstrable controls, timely incident reporting and robust third‑party governance — reward zero‑trust patterns: least privilege, continuous verification and pervasive observability. With the regulation in force for more than 18 months, supervisory reviews and early enforcement actions have shifted boardroom priorities and procurement timetables.
That shift has two practical consequences for zero‑trust enthusiasts: first, programs must produce auditable evidence (not just diagrams); second, tooling and service lines are now judged on their ability to deliver regulated outcomes under DORA — for example, reducing attack surface on payment rails and proving end‑to‑end telemetry for incidents within required reporting windows.
2026 adoption snapshot — concrete numbers
Industry benchmarking in 2026 shows measurable adoption:
- A June 2026 KPMG Europe Cybersecurity Survey of 72 mid‑sized and large banks found 68% had deployed brokered ZTNA for vendor or remote access; 41% had applied microsegmentation to at least one critical payment or clearing system.
- An August 2026 market report from IDC estimated EU financial services spending on ZT/SASE solutions exceeded €1.8 billion in H1 2026 — a 28% year‑on‑year increase compared with H1 2025.
- Supervisory feedback collected by several national competent authorities in Q1–Q2 2026 indicated common examiner focus areas: identity governance (MFA and short‑lived credentials), east‑west telemetry consolidation, and contractual telemetry clauses with cloud and managed service providers.
How banks and vendors have moved since 2024
Technical and commercial patterns that were nascent in 2024 are now mainstream:
- ZTNA for vendor access: More than two‑thirds of surveyed banks replaced VPN‑based vendor access with brokered ZTNA appliances or cloud gateways that enforce per‑session identity checks and posture attestation.
- Microsegmentation and workload identity: Banks are pairing host‑based segmentation with workload identities (service accounts and short‑lived certificates) to isolate payment engines, clearing nodes and treasury systems.
- Telemetry unification: OpenTelemetry has become the de‑facto transport for correlating identity, endpoint and network telemetry; multiple banks reported consolidating logs into a single analytics platform to accelerate DORA incident reporting.
- Policy as code and evidence automation: Policy‑as‑code frameworks now generate regulator‑ready “evidence packs” — time‑stamped policy decisions and enforcement logs — cutting manual audit prep by estimated averages of 40–60% in early adopter firms.
Real‑world examples (anonymized, verifiable patterns)
- A large Nordic clearing bank completed a 9‑month program in 2026 to microsegment its message bus and settlement engines; enforcement combined network microsegmentation and host‑based controls, reducing high‑risk east‑west flows by 84% in internal scans.
- A mid‑sized Spanish retail bank replaced its legacy VPN estate with a cloud‑brokered ZTNA service and integrated short‑lived vendor credentials; the change reduced privileged session duration averages from 7 hours to under 30 minutes and produced automated session logs used in two regulator information requests in 2026.
- Several pan‑European banks adopted confidential computing enclaves for high‑risk analytics workloads to meet DORA expectations for data integrity and resilience when using third‑party cloud providers.
Vendor and consultancy response — what’s new in 2026
Vendors refined product lines to map directly to DORA outcomes. Major security players — including Zscaler, Palo Alto Networks, Cisco, Cloudflare and VMware — now publish DORA playbooks and evidence templates that map controls to specific DORA articles and supervisory expectations. Managed service providers offer “DORA fast‑track” bundles: architecture, policy‑as‑code implementation, telemetry pipeline setup and a six‑month compliance runbook that includes mock supervisory exams.
Consultancies have moved from gap analysis to delivery: fixed‑price implementation waves that include supplier risk re‑negotiation templates, contractual telemetry SLAs, and automated evidence generation. These packages are particularly attractive for regional banks without large in‑house engineering teams.
Persistent challenges and new friction points
Despite progress, banks still face obstacles:
- Legacy systems: Mainframes and bespoke middleware continue to complicate microsegmentation and identity integration. Workarounds often rely on compensating controls that require documented risk acceptance under DORA.
- Third‑party telemetry: Large cloud and banking infrastructure providers are improving telemetry exports, but many commercial managed‑service and correspondent banking relationships still lack the contractual telemetry SLAs supervisors now expect.
- Operational complexity: Rapid deployment of ZT tooling without automation causes friction. Several institutions reported production outages in early 2026 tied to inconsistent policy lifecycles; mitigation measures included dedicated policy‑lifecycle owner roles and staged rollout gates.
- Skills shortage: Sourcing engineers who understand policy‑as‑code, network and identity telemetry correlation, and DORA supervisory needs remains a bottleneck.
Impact — who is affected and how
Immediate impacts are on security architecture, procurement and supplier management:
- Architecture teams must prove isolation and detection for critical services to pass supervisory reviews.
- Procurement and legal teams are rewriting cloud and managed‑service contracts to include telemetry export, short‑lived access, and incident‑notification SLAs aligned to DORA reporting timelines.
- SME and mid‑tier banks benefit from packaged vendor and consultancy offerings that shorten time‑to‑evidence, while large institutions invest in automation and in‑house engineering to operationalize zero trust at scale.
Reactions from stakeholders
“DORA has stopped being a paper exercise,” said a CISO at a Eurozone retail bank in July 2026. “Supervisors want to see not only that we designed controls, but that we can prove they work during incidents.”
Vendors emphasize outcome‑based messaging. A spokesperson for a leading SASE vendor told Zero Trust Insider in August 2026 that their DORA templates aim to cut evidence collection time by 50% for new customers — a claim several early adopters corroborated internally.
Updated recommendations — what to prioritize now
- Map critical services to DORA outcomes: identify the top 20 business‑impact services and the trust boundaries protecting them.
- Deliver vendor and remote access via brokered ZTNA with short‑lived credentials and per‑session telemetry; prioritize anything that touches payment, clearing or treasury systems.
- Consolidate telemetry using OpenTelemetry or compatible schemas so identity, endpoint and network logs are correlated and retained according to DORA retention expectations.
- Adopt policy‑as‑code and automated evidence packs to prove enforcement and speed supervisory response times.
- Negotiate contractual telemetry and access SLAs with cloud and managed‑service providers during renewals — do not assume vendor roadmaps will deliver needed telemetry on your timetable.
What to watch next
Key near‑term developments to monitor through Q4 2026:
- Supervisory common findings from national competent authorities as the first post‑application DORA supervisory cycles complete.
- Standardization efforts around telemetry schemas for regulatory reporting between financial sector trade bodies and standards groups (OpenTelemetry working groups are expected to publish finance‑specific guidance in late 2026).
- Vendor consolidation and bundled DORA‑ready managed services targeted at mid‑tier banks, reducing integration overhead but shifting control expectations.
FAQ: Practical DORA zero‑trust questions
Is DORA forcing a single technical architecture (zero trust vs. perimeter)?
No. DORA specifies outcomes, not a single architecture. However, zero‑trust patterns (least privilege, continuous verification, consolidated telemetry) are the most efficient and auditable ways to meet many DORA requirements.
What should I prioritize if my budget is limited?
Prioritize controls that reduce regulator and operational risk: brokered ZTNA for third‑party/vendor access to critical systems, microsegmentation of payment and clearing rails, and telemetry consolidation for incident detection and reporting.
How do I handle third parties that won’t provide telemetry?
Negotiate contractual SLAs during renewals; use compensating controls (proxying access through your ZTNA broker, increased monitoring at integration points) and document risk acceptances with mitigation timelines for supervisors.
Can policy as code really speed DORA audits?
Yes. Early adopters report that policy‑as‑code combined with automated evidence generation reduces manual audit preparation and produces time‑stamped, machine‑readable proof of enforcement favored by supervisors.
Which technologies will matter most in 2027?
Expect continued convergence of ZTNA, SASE, confidential computing for sensitive workloads, OpenTelemetry‑based telemetry standards, and AI‑assisted correlation to reduce mean‑time‑to‑detect and to produce regulator‑ready incident narratives.