{"id":17245,"date":"2026-04-07T15:49:08","date_gmt":"2026-04-07T13:49:08","guid":{"rendered":"https:\/\/measureworks.nl\/blog\/dora-compliance-shared-burden-or-a-collective-solution\/"},"modified":"2026-04-16T10:20:10","modified_gmt":"2026-04-16T08:20:10","slug":"dora-compliance-shared-burden-or-a-collective-solution","status":"publish","type":"post","link":"https:\/\/measureworks.nl\/en\/blog\/dora-compliance-shared-burden-or-a-collective-solution\/","title":{"rendered":"DORA compliance: Shared burden or a collective solution?"},"content":{"rendered":"\n<h3 class=\"wp-block-heading\">One year of DORA. What have we learned?<\/h3>\n\n<p><strong>A year after the Digital Operational Resilience Act (DORA) officially came into force, the question for insurers is no longer if they are compliant, but what compliance looks like in practice.<\/strong><\/p>\n\n<p><strong>On 19 March 2026, CIOs and IT leaders from across the sector gathered for a <a href=\"https:\/\/digitalecosystems.institute\/dora-rondetafel-hoe-verzekeraars-grip-krijgen-op-de-keten\/\">roundtable<\/a> hosted by MeasureWorks and DEI. The conversation was refreshingly candid: while a vast amount of energy is being poured into ticking boxes, are organisations actually becoming more resilient?<\/strong><\/p>\n\n<p><strong>In this blog, we explore how insurers are experiencing DORA on the ground and what is required to move beyond mere compliance toward genuine digital resilience.<\/strong><\/p>\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>&#8220;By gaining visibility into your supply chain and monitoring it continuously, you aren\u2019t just compliant; more importantly, you ensure you aren&#8217;t caught off guard.&#8221; \u2013 Marcel Schipper, Sales Director at MeasureWorks<\/p>\n<\/blockquote>\n\n<figure class=\"wp-block-image aligncenter size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"683\" src=\"https:\/\/measureworks.nl\/wp-content\/uploads\/2026\/04\/measureworkstijdensrondetafel-1024x683.jpg\" alt=\"\" class=\"wp-image-17237\" srcset=\"https:\/\/measureworks.nl\/wp-content\/uploads\/2026\/04\/measureworkstijdensrondetafel-1024x683.jpg 1024w, https:\/\/measureworks.nl\/wp-content\/uploads\/2026\/04\/measureworkstijdensrondetafel-300x200.jpg 300w, https:\/\/measureworks.nl\/wp-content\/uploads\/2026\/04\/measureworkstijdensrondetafel-768x512.jpg 768w, https:\/\/measureworks.nl\/wp-content\/uploads\/2026\/04\/measureworkstijdensrondetafel-1536x1024.jpg 1536w, https:\/\/measureworks.nl\/wp-content\/uploads\/2026\/04\/measureworkstijdensrondetafel-2048x1365.jpg 2048w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n<h2 class=\"wp-block-heading\">What is DORA?<\/h2>\n\n<p>The Digital Operational Resilience Act is an EU regulation designed to strengthen the digital resilience of the financial sector. It mandates the reporting of IT incidents, regular ethical hacking tests, and strict requirements for IT contracts with third-party providers.<\/p>\n\n<p>Crucially, the scope extends far beyond the financial organisation itself. Insurers must maintain a firm grip on their critical supply chain partners; after all, a disruption at an IT provider can be just as catastrophic as an internal system failure. DORA has been officially in effect since January 2025.<\/p>\n\n<h2 class=\"wp-block-heading\">The Impact of DORA<\/h2>\n\n<p>DORA requires more than just a list of critical suppliers. Where organisations previously categorised outsourcing partners as \u2018critical\u2019 or \u2018important,\u2019 the regulation now mandates the identification of critical functions.<\/p>\n\n<p>Health insurer ONVZ took a practical approach using their core process model. &#8220;We identified all our functions and labelled a specific subset as critical,&#8221; explains Supplier Manager Jan-Dirk Rundervoort. DORA also introduced new requirements for the selection, contracting, and performance of IT service providers. ONVZ addressed this via an addendum to existing contracts, updated risk analyses, and a refreshed control framework.&#13;\n&#13;\nFurthermore, quarterly reports are now submitted to the Board of Directors, a step that wasn&#8217;t previously standard practice. &#8220;The Board never used to involve itself in procurement. We really had to drag them to the table,&#8221; says Rundervoort. &#8220;But we\u2019ve succeeded in doing that now.&#8221;<\/p>\n\n<p>The results are impressive. With a lean team, close coordination with the risk department, and an external partner providing a fresh perspective, 92 out of 94 controls have been met. One outstanding control concerns exit plans: ONVZ has opted for an overarching exit strategy with management approval, rather than individual plans for every single supplier.<\/p>\n\n<figure class=\"wp-block-image aligncenter size-large\"><img decoding=\"async\" width=\"1024\" height=\"683\" src=\"https:\/\/measureworks.nl\/wp-content\/uploads\/2026\/04\/DORADEIrondetafel-1024x683.jpg\" alt=\"\" class=\"wp-image-17239\" srcset=\"https:\/\/measureworks.nl\/wp-content\/uploads\/2026\/04\/DORADEIrondetafel-1024x683.jpg 1024w, https:\/\/measureworks.nl\/wp-content\/uploads\/2026\/04\/DORADEIrondetafel-300x200.jpg 300w, https:\/\/measureworks.nl\/wp-content\/uploads\/2026\/04\/DORADEIrondetafel-768x512.jpg 768w, https:\/\/measureworks.nl\/wp-content\/uploads\/2026\/04\/DORADEIrondetafel-1536x1024.jpg 1536w, https:\/\/measureworks.nl\/wp-content\/uploads\/2026\/04\/DORADEIrondetafel-2048x1365.jpg 2048w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n<h2 class=\"wp-block-heading\">Compliance is not the same as resilience<\/h2>\n\n<p>The greatest challenge lies not just in implementation, but in the mindset that follows. Sandor Beckmann of BNG Bank put it sharply: &#8220;DORA is, first and foremost, a license to operate. The fear of regulatory oversight and board liability is the dominant driver.&#8221; This creates a side effect: a focus on &#8220;ticking the box&#8221; rather than the underlying intent of the regulation.<\/p>\n\n<p>John de Voogd of Klaverblad recognises this trend: &#8220;We are so focused on providing evidence that all our energy goes there. Far less energy goes into the actual controls, which might even suffer as a result. Is anyone still stopping to ask why we are doing this?&#8221;<\/p>\n\n<p>Internally, this pattern is often reinforced. Michiel van Dijk of VGZ notes that everyone from the first to the third line of defence wants to have a say in newly introduced processes. &#8220;They are sometimes even stricter than the external regulators. It doesn&#8217;t exactly make the organisation more agile. Everyone wants to add their own layer of requirements.&#8221;<\/p>\n\n<p>The risk is what participants described as a false sense of security. Rundervoort illustrated this with the ransomware attack on Maastricht University, where all data was held hostage, leaving the organisation paralysed. &#8220;After the hack, the CIO said on TV that everything had been &#8216;reported as green.&#8217; That\u2019s all well and good, but it\u2019s useless in practice. I see the same in audits: they only check if something exists, not why it\u2019s there or if it actually works.&#8221;<\/p>\n\n<h2 class=\"wp-block-heading\">The chain extends beyond your own IT landscape<\/h2>\n\n<p>Digital resilience doesn&#8217;t stop at the office door. Insurers must manage their critical partners, but this responsibility weighs heavily on the rest of the chain, particularly smaller players.<\/p>\n\n<p>Take StichtingVbV, a joint initiative by Dutch non-life insurers that helps recover missing and stolen vehicles. The foundation itself does not fall under DORA, but it is a key partner to insurers that do. Project Leader Roelof Muis voices his concern: &#8220;Our fear is: how will insurers enforce their requirements on suppliers and third parties? If every partner starts imposing their own unique set of demands on us, it becomes unmanageable.&#8221;<\/p>\n\n<p>This is a significant hurdle for a small organisation without a dedicated compliance department. The challenges are already evident with the rollout of ISO 27001. &#8220;We are still in the phase of embedding basic behaviours, like remembering to lock your computer when you go to the toilet. For a large corporation, that\u2019s second nature; for us, it\u2019s still a transition.&#8221;<\/p>\n\n<p>Additionally, the organisation currently relies on numerous Excel spreadsheets, where a single change must be updated in eight different places. Muis is calling for standardisation: &#8220;We want to move away from this &#8216;Excel hell.&#8217; We need a single software solution that acts as a &#8216;golden source&#8217; of information.&#8221;<\/p>\n\n<h2 class=\"wp-block-heading\">Everybody wants to collaborate, but trust proves to be difficult<\/h2>\n\n<p>The challenges of DORA are universal. Almost all insurers are wrestling with the same questions: How do you label critical functions? How do you structure supplier management? How do you ensure contractual safeguards?&#13;\n&#13;\nThis suggests a collective approach would be logical. While the Dutch Association of Insurers provides a standard DORA addendum, and experiences are shared via CIO platforms, each insurer still has to tailor these documents to their specific organisation. Furthermore, every insurer independently requests information from the same pool of suppliers.<\/p>\n\n<p>Previous attempts at centralisation have struggled. In 2024, Rundervoort initiated a shared register to divide the workload. The initial enthusiasm was high. A second session led to concrete plans: adapting the standard addendum for universal use and creating a joint supplier register with a generic questionnaire. Suppliers would only have to fill it in once for all participating insurers.<\/p>\n\n<p>&#8220;I updated the addendum, created the questionnaire, and sent it to everyone,&#8221; says Rundervoort. &#8220;The result? Stone-cold silence.&#8221; The initiative fizzled out, and everyone went back to reinventing the wheel. This wasn&#8217;t due to a lack of will, but a structural lack of trust, fuelled by personal liability at the board level. As Rundervoort summarises: &#8220;The crux is trust. If another insurer builds something for us collectively, but I am the one held accountable for it, I\u2019m still going to want to check it myself.&#8221;<\/p>\n\n<h2 class=\"wp-block-heading\">What does work: starting small with a concrete goal<\/h2>\n\n<p>The consensus at the table was that it is better to start small. Two parties tackling a specific project achieve results faster than a broad coalition trying to reach a consensus on high-level principles. In large groups, you often only agree on the basics, after which the details get bogged down in internal stakeholder management.&#13;\n&#13;\nAccording to Rundervoort, two ingredients are essential: a concrete use case and one party taking the lead. &#8220;In large groups, thirty people want to include their own &#8216;pet projects.&#8217; It becomes much more bloated than it needs to be.&#8221; ONVZ\u2019s approach proves that a focused, small-scale method works. Furthermore, a &#8220;quick win&#8221; is easier to report internally and builds an appetite for more.<\/p>\n\n<p>This lesson points to a broader truth: digital resilience is an ongoing process. It requires operational grip, knowing what is happening in the chain, who is responsible for what, and what the impact is if a link breaks.&#13;\n&#13;\nMarcel Schipper of MeasureWorks highlights this: &#8220;DORA demands operational control: knowing what\u2019s happening and knowing what to do when things go wrong. That doesn&#8217;t end with your own IT landscape; it includes the dependencies outside of it.&#8221;<\/p>\n\n<p>MeasureWorks addresses this through <a href=\"https:\/\/measureworks.nl\/en\/performance-solutions\/observability\/\">observability<\/a>: monitoring every link in the IT chain, technically, organisationally, and operationally. Who responds to an alert? What is the downtime impact? Does everyone know their role during an incident? &#8220;Only with this insight can you react quickly and limit disruption.&#8221; This level of insight will only become more critical with the upcoming AI Act, which places transparency and system controllability at its core.<\/p>\n\n<figure class=\"wp-block-image aligncenter size-large\"><img decoding=\"async\" width=\"1024\" height=\"683\" src=\"https:\/\/measureworks.nl\/wp-content\/uploads\/2026\/04\/dorarondetafelmw-1024x683.jpg\" alt=\"\" class=\"wp-image-17242\" srcset=\"https:\/\/measureworks.nl\/wp-content\/uploads\/2026\/04\/dorarondetafelmw-1024x683.jpg 1024w, https:\/\/measureworks.nl\/wp-content\/uploads\/2026\/04\/dorarondetafelmw-300x200.jpg 300w, https:\/\/measureworks.nl\/wp-content\/uploads\/2026\/04\/dorarondetafelmw-768x512.jpg 768w, https:\/\/measureworks.nl\/wp-content\/uploads\/2026\/04\/dorarondetafelmw-1536x1024.jpg 1536w, https:\/\/measureworks.nl\/wp-content\/uploads\/2026\/04\/dorarondetafelmw-2048x1365.jpg 2048w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n<h2 class=\"wp-block-heading\">Looking ahead post-DORA: operational control as destination<\/h2>\n\n<p>The roundtable made it clear that compliance is merely the starting point. The real value lies in turning regulations into actionable capability. Organisations that invest now in truly understanding their digital supply chain, not just documenting it, are building a foundation that will withstand future regulations.&#13;\n&#13;\nAs Schipper puts it: &#8220;By gaining visibility into your supply chain and monitoring it continuously, you aren\u2019t just compliant; you prevent yourself from being caught off guard.&#8221;<\/p>\n\n<h2 class=\"wp-block-heading\">Want to discuss DORA?<\/h2>\n\n<p>Do you want DORA to contribute to your organisation\u2019s continuity? Or do you have questions about achieving full digital resilience? <a href=\"https:\/\/measureworks.nl\/en\/contact\/\">Feel free to contact our team for a chat.<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>One year of DORA. What have we learned? A year after the Digital Operational Resilience Act (DORA) officially came into force, the question for insurers is no longer if they are compliant, but what compliance looks like in practice. On 19 March 2026, CIOs and IT leaders from across the sector gathered for a roundtable [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":17236,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-17245","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-insights"],"acf":[],"_links":{"self":[{"href":"https:\/\/measureworks.nl\/en\/wp-json\/wp\/v2\/posts\/17245","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/measureworks.nl\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/measureworks.nl\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/measureworks.nl\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/measureworks.nl\/en\/wp-json\/wp\/v2\/comments?post=17245"}],"version-history":[{"count":1,"href":"https:\/\/measureworks.nl\/en\/wp-json\/wp\/v2\/posts\/17245\/revisions"}],"predecessor-version":[{"id":17246,"href":"https:\/\/measureworks.nl\/en\/wp-json\/wp\/v2\/posts\/17245\/revisions\/17246"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/measureworks.nl\/en\/wp-json\/wp\/v2\/media\/17236"}],"wp:attachment":[{"href":"https:\/\/measureworks.nl\/en\/wp-json\/wp\/v2\/media?parent=17245"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/measureworks.nl\/en\/wp-json\/wp\/v2\/categories?post=17245"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/measureworks.nl\/en\/wp-json\/wp\/v2\/tags?post=17245"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}