The Digital Operational Resilience Act applies to banks, insurers, payment institutions, crypto-asset providers, and their critical ICT suppliers across the EU. Unlike a framework you adopt voluntarily, DORA is a regulation with a date attached — it has applied since 17 January 2025. Most compliance teams read it as a logging and incident-reporting mandate. Read more closely, it is also an evidence mandate, and the evidence half is where the gap sits.
What Article 9 actually asks for
DORA Article 9 requires financial entities to implement policies and tools that ensure the 'authenticity, integrity, availability and confidentiality' of data — including the data in logs and audit trails used to reconstruct incidents. The supervisory expectation is not that you retained the records. It is that you can demonstrate the records are the originals, unaltered, when a regulator or resolution authority asks.
There is a quiet assumption baked into most implementations: that the system which produced the log is also a trustworthy witness to the log's integrity. DORA's resilience lens breaks that assumption. If the ICT system is compromised — the exact scenario DORA exists to prepare for — its own attestation that the logs are intact is worth very little.
Where 'we log everything' falls short
Comprehensive logging is necessary and most regulated firms do it well. The gap appears at the three moments a supervisor cares about most:
- Reconstruction after an incident — DORA expects you to reconstruct the sequence of events. If the logs lived inside the system that was breached, the reconstruction relies on data an attacker could have edited.
- Third-party and ICT-supplier records — DORA extends to critical suppliers. Proving a supplier's record is intact is far easier when both sides verify against a shared, external reference rather than trading log exports.
- Independent demonstration — a regulator does not have to trust your word that retention and immutability controls held. Integrity that anyone can verify against an external anchor turns a claim into a demonstrable fact.
The deadline already passed — so why is this still a buying trigger?
January 2025 was the application date, not the enforcement plateau. Supervisory authorities spent the first year mapping entities and assessing baselines. The shift now underway is from 'do you have a policy' to 'show us the evidence' — and the second question is the one integrity proof answers directly.
The firms moving first are not the ones with the worst logging. They are the ones whose auditors and regulators have started asking the second question and who would rather answer it with a verifiable anchor than a screenshot of a retention policy.
How integrity proof maps onto the DORA workflow
Adding a verification layer does not replace your SIEM, your log pipeline, or your incident process. It runs alongside them, sealing the records those systems already produce:
When a supervisor asks you to demonstrate that a given audit record is the original, you produce a proof package: the record's hash, its position in the Merkle tree, and the public-chain reference where the root was anchored at a known time. None of that requires the regulator to trust the system that generated the log — which is precisely DORA's point.
Who inside the firm owns this
DORA pushed ICT risk onto the management body, so the people asking about integrity evidence are increasingly not engineers:
- Head of Compliance — owns the regulator relationship and has to translate 'we have controls' into 'here is the demonstrable evidence.'
- CISO / ICT risk — owns the resilience posture and knows that self-attested logs are the weak link in a breach reconstruction.
- Internal audit — owns the assurance line and benefits when integrity is verifiable without depending on the audited system.
The honest framing for a DORA conversation
DORA does not name blockchain, Merkle trees, or any specific technology — and you should be wary of any vendor who claims it does. What DORA requires is integrity you can demonstrate to an independent party. Anchoring records to a public chain is one structurally sound way to provide that, because the proof does not depend on the continued good behaviour of the system under examination. The question to bring to your next DORA review is simple: for each critical audit trail, can we prove to a regulator that it has not changed — without asking them to trust the system that produced it?
DORA does not ask whether you kept the records. It asks whether you can prove they are the originals — to someone who has no reason to trust the system that produced them.