DORA in 2026: Why a Factory Reset May Put Your Compliance at Risk

With the Digital Operational Resilience Act (DORA) now in effect, financial institutions need to show they have full control over digital risks. DORA is not just about cybersecurity or incident response. It asks organizations to manage risk throughout the entire lifecycle of their ICT systems and the data they hold.

23-4-2026
Digital Operational Resilience Act

What Is DORA?

The Digital Operational Resilience Act (DORA) is a European regulation that helps financial institutions become more resilient to digital risks. It makes sure that banks, insurers, investment firms, and their ICT providers can handle, respond to, and recover from IT disruptions like cyberattacks or system failures.​

What DORA Requires (Articles 5–14)

DORA provides a clear framework for managing ICT risk. Articles 5 to 14 are at the heart of this framework and guide organizations on how to build digital resilience. In short, DORA asks organizations to:

  • Maintain a complete overview of all ICT assets and data
  • Understand where data resides and how it is used
  • Identify and assess risks continuously
  • Apply appropriate controls and safeguards
  • Be able to detect, respond to, and recover from incidents

The main point is that data is still a risk as long as it exists, even if the system it was on is no longer in use.​

Where Data Erasure Becomes Critical

When servers are replaced or systems are taken out of use, data is often deleted, formatted, or reset. While this might seem enough, these methods do not guarantee that the data is gone for good or provide proof of removal. Under DORA, this is a problem. If data can still be recovered or you cannot show it has been erased, it is still part of your risk.​

The Risk of Not Erasing Data

Data left on old or unmanaged systems creates unnecessary risk. It can make your organization more vulnerable, harder to monitor, and more difficult to respond to incidents. Most importantly, it means you are not meeting DORA’s requirement to maintain full control over your ICT assets and risks. The risk increases further when third parties are involved. If data is not securely erased when infrastructure is returned or reused, your organization remains accountable, even if the data is no longer within your direct control.​

What DORA Implies About Data Removal

DORA does not tell you exactly how to erase data, but it is clear that data should not exist without control. Keeping data you no longer need adds risk and can lead to compliance issues. Secure, certified data erasure makes sure your data is gone for good and gives you proof for audits. This helps you meet DORA’s focus on accountability and control.

At Certus, we help financial institutions and ICT providers meet DORA requirements with secure, certified, and fully auditable data erasure.

Original Logo (Horizontal)

We simplify certified data erasure with solutions for every industry.

Solutions

Secure data erasure solutions for ITADs, OEMs, IT recyclers, and refurbishers.

Secure data sanitization solutions for corporate IT teams focused on compliance, remote capabilities, and device lifecycle management.

Industry standard compliancy

Certus is a member of

Software Made in Germany 2026 english bleu

Copyright All Rights Reserved © 2026 - Cookie policy