Brussels — 14 October 2026. Sixteen months after the Digital Operational Resilience Act (DORA) came into application on 17 January 2025, EU banks are moving from pilot projects to production zero‑trust architectures for third‑party access. Renewed supervisory scrutiny, clearer expectations from compliance teams, and a maturing vendor market have combined to make identity‑first Zero Trust Network Access (ZTNA), microsegmentation and continuous telemetry the operational default for many institutions.
Why this matters now
DORA established a harmonised framework for information and communication technology (ICT) risk management across the EU financial sector and set explicit obligations for third‑party ICT providers, resilience testing and ICT‑incident reporting. That regulatory baseline — plus DORA’s operational testing regime — turns vendor access from a contractual checkbox into a measurable engineering problem: who has access, under what context, for how long, and with what telemetry to prove it.
Between H1 and Q3 2026, Zero Trust Insider reporting shows banks accelerated ZTNA rollouts to meet evidence requirements requested during supervisory on‑site reviews and preparedness tests. The result: many institutions that began pilots in 2025 are now operating continuous‑control paths for critical vendor sessions.
What changed since August 2026
- Faster timelines in practice: Where projects were commonly forecast at 12–24 months in early 2026, multiple tier‑1 banks told Zero Trust Insider they achieved production rollouts for DORA‑scoped workloads in 6–12 months by simplifying scope and automating onboarding workflows.
- Stronger supervisory requests: Supervisors are increasingly asking for continuous evidence — session recordings, attestation logs and short‑lived credential issuance records — rather than periodic attestations. Banks report regulators asking for demonstrable proof during tabletop tests and live access reviews.
- Vendor market maturation: ZTNA and microsegmentation vendors have released out‑of‑the‑box blueprints for common banking workloads and prebuilt connectors for vendor onboarding systems. Examples in the field include ZTNA integrations with vendor identity providers, microsegmentation templates for core payment and trade systems and managed telemetry services that normalise vendor session logs for audits.
- Cloud and API reality: As third parties access cloud APIs and hybrid environments, banks are combining ZTNA with API gateways and workload identities (SPIFFE‑style) to protect service‑to‑service interactions — not just human sessions.
How banks are implementing zero trust in production
- Identity‑first ZTNA at scale: Banks use SAML/OAuth + conditional access to bind vendor sessions to corporate IDs and context (device posture, location, time). Session policies apply least privilege and are short‑lived by default.
- Microsegmentation and application‑level controls: Teams are deploying microsegmentation to prevent lateral movement; segmentation policies are tied to business criticality and DORA testing scope.
- Continuous telemetry and hardware attestation: Production deployments now commonly include TPM/secure enclave attestation for vendor devices where supported, continuous logging of keystrokes/commands for privileged sessions, and cryptographic session evidence (short‑lived certificates) for non‑interactive machine access.
- Automated vendor onboarding and deprovisioning: Banks link procurement, legal and identity systems so that contract milestones automatically trigger access provisioning and revocation — reducing stale accounts and improving auditability.
- WORM and chain‑of‑custody logging: Logging pipelines now use write‑once, read‑many (WORM) storage and integrity checks to meet evidentiary expectations during DORA testing and incident investigations.
Real‑world examples and vendor signals
Zero Trust Insider interviews with CISOs and product managers in Europe show a few recurring vendor and pattern signals:
- Major ZTNA providers have published DORA‑targeted templates for vendor onboarding and session retention policies.
- Microsegmentation vendors offer prebuilt rules for common banking protocols (SWIFT adapters, core banking app ports) to speed segmentation without business disruption.
- Managed security service providers (MSSPs) now package “DORA evidence” services — normalising vendor session telemetry, providing tamper‑resistant storage and delivering attestation reports for supervisors.
Several banks told Zero Trust Insider that pairing a ZTNA vendor with a microsegmentation platform and a managed telemetry pipeline reduced implementation risk and shortened the time to demonstrable audit evidence.
Challenges that remain
- Legacy industrial systems: Air‑gapped or unsupported vendor appliances still require bespoke engineering and can delay full coverage.
- Operational scale: Short‑lived credentials, continuous attestations and fine‑grained policies increase orchestration needs. Firms without mature IAM/CIAM automation struggle to scale.
- Cross‑border contractual friction: Some third parties resist intrusive telemetry or right‑to‑audit clauses, requiring legal negotiation and compensating technical controls.
- Evidence quality: Supervisors want tamper‑resistant, searchable artefacts. Achieving that across cloud and on‑prem stacks still drives architectural rework in logging and SIEM pipelines.
Practical, updated roadmap for October 2026
Based on reporting and practitioner interviews, Zero Trust Insider recommends this pragmatic, time‑bound approach for banks still closing gaps:
- 0–30 days: Complete a DORA‑scoped vendor access inventory and map each vendor to a control tier (critical, important, standard).
- 30–90 days: Deploy ZTNA for critical vendors only; enforce conditional access and short‑lived sessions. Start ingesting vendor session logs into a tamper‑resistant pipeline (WORM/immutable buckets).
- 90–180 days: Roll out microsegmentation templates for the most critical application flows and automate vendor onboarding/offboarding with procurement and legal hooks.
- 180+ days: Extend attestation (TPM/secure enclave) to vendor endpoints where possible; instrument machine‑to‑machine identities for API and cloud workloads; prepare tabletop tests with supervisory‑grade evidence packs.
Impact and who should act first
Boards, CROs and CISOs should prioritise DORA‑scoped services and ensure vendor onboarding integrates technical controls with contract provisions. Procurement and legal teams must accept that engineering controls — automated provisioning, telemetry and session evidence — are as important as contractual clauses to meet supervisory expectations.
Reactions from the field
"Supervisors want to see continuous evidence, not just a checkbox," said an EU bank security lead who briefed Zero Trust Insider in September 2026. "Operationalising zero trust meant rethinking onboarding — now access is a lifecycle event tied to legal and procurement systems."
What to watch next
Watch for: (1) further standardisation of DORA evidence formats from managed telemetry providers; (2) more prebuilt sector templates for microsegmentation; and (3) increased demand for immutable log storage and chain‑of‑custody reporting. Boards should expect supervisory queries on third‑party access evidence in upcoming reviews and stress tests.
How should I prioritise vendors under DORA?
Prioritise by impact and exposure: map which vendors can affect confidentiality, integrity or availability of DORA‑scoped services. Start with those that have privileged access to payments, ledgers, customer data or operational controls, and apply ZTNA + microsegmentation first.
Can I use managed services to meet DORA evidence requirements?
Yes — MSSPs now commonly offer DORA‑focused telemetry pipelines and immutable storage. But you remain responsible for proving controls to supervisors: validate the MSSP’s tamper resistance, retention, searchability and chain‑of‑custody guarantees before delegating.
Are short‑lived credentials enough?
No. Short‑lived credentials are a key control but must be combined with continuous device/user attestation, session telemetry, least‑privilege policies and automated revocation tied to contract events to meet DORA expectations.
What’s the single most effective near‑term step?
Automate vendor onboarding so that contract signature, procurement milestones and identity provisioning are linked. That single change eliminates many stale accounts, enforces policy from day one and produces audit trails supervisors can validate.