Certyo/v1
Back to blog
ComplianceMay 12, 2026 · 9 min read

DORA wants tamper-proof records — and most firms can't prove it yet

DORA has been in force since January 2025. It requires EU financial entities to ensure the integrity of ICT records and prove it to regulators. 'We log everything' satisfies the first half. It does not satisfy the second.

The Digital Operational Resilience Act applies to banks, insurers, payment institutions, crypto-asset providers, and their critical ICT suppliers across the EU. Unlike a framework you adopt voluntarily, DORA is a regulation with a date attached — it has applied since 17 January 2025. Most compliance teams read it as a logging and incident-reporting mandate. Read more closely, it is also an evidence mandate, and the evidence half is where the gap sits.

01

What Article 9 actually asks for

DORA Article 9 requires financial entities to implement policies and tools that ensure the 'authenticity, integrity, availability and confidentiality' of data — including the data in logs and audit trails used to reconstruct incidents. The supervisory expectation is not that you retained the records. It is that you can demonstrate the records are the originals, unaltered, when a regulator or resolution authority asks.

There is a quiet assumption baked into most implementations: that the system which produced the log is also a trustworthy witness to the log's integrity. DORA's resilience lens breaks that assumption. If the ICT system is compromised — the exact scenario DORA exists to prepare for — its own attestation that the logs are intact is worth very little.

02

Where 'we log everything' falls short

Comprehensive logging is necessary and most regulated firms do it well. The gap appears at the three moments a supervisor cares about most:

  • Reconstruction after an incident — DORA expects you to reconstruct the sequence of events. If the logs lived inside the system that was breached, the reconstruction relies on data an attacker could have edited.
  • Third-party and ICT-supplier records — DORA extends to critical suppliers. Proving a supplier's record is intact is far easier when both sides verify against a shared, external reference rather than trading log exports.
  • Independent demonstration — a regulator does not have to trust your word that retention and immutability controls held. Integrity that anyone can verify against an external anchor turns a claim into a demonstrable fact.
03

The deadline already passed — so why is this still a buying trigger?

January 2025 was the application date, not the enforcement plateau. Supervisory authorities spent the first year mapping entities and assessing baselines. The shift now underway is from 'do you have a policy' to 'show us the evidence' — and the second question is the one integrity proof answers directly.

Jan 2025
DORA application date
Art. 9
Integrity of data and logs
2% / day
Potential penalty for critical suppliers

The firms moving first are not the ones with the worst logging. They are the ones whose auditors and regulators have started asking the second question and who would rather answer it with a verifiable anchor than a screenshot of a retention policy.

04

How integrity proof maps onto the DORA workflow

Adding a verification layer does not replace your SIEM, your log pipeline, or your incident process. It runs alongside them, sealing the records those systems already produce:

ICT event logged
Record hashed
Batched + anchored
Regulator request
Verify externally

When a supervisor asks you to demonstrate that a given audit record is the original, you produce a proof package: the record's hash, its position in the Merkle tree, and the public-chain reference where the root was anchored at a known time. None of that requires the regulator to trust the system that generated the log — which is precisely DORA's point.

05

Who inside the firm owns this

DORA pushed ICT risk onto the management body, so the people asking about integrity evidence are increasingly not engineers:

  • Head of Complianceowns the regulator relationship and has to translate 'we have controls' into 'here is the demonstrable evidence.'
  • CISO / ICT riskowns the resilience posture and knows that self-attested logs are the weak link in a breach reconstruction.
  • Internal auditowns the assurance line and benefits when integrity is verifiable without depending on the audited system.
06

The honest framing for a DORA conversation

DORA does not name blockchain, Merkle trees, or any specific technology — and you should be wary of any vendor who claims it does. What DORA requires is integrity you can demonstrate to an independent party. Anchoring records to a public chain is one structurally sound way to provide that, because the proof does not depend on the continued good behaviour of the system under examination. The question to bring to your next DORA review is simple: for each critical audit trail, can we prove to a regulator that it has not changed — without asking them to trust the system that produced it?

DORA does not ask whether you kept the records. It asks whether you can prove they are the originals — to someone who has no reason to trust the system that produced them.

May 12, 2026 · 9 min read

Ready to see this in action?

Request a demo and verify your first record in minutes.

Request demo → See how it works