Supervision & regulator
DORA sanctions: fines, penalty payments and licence withdrawal — the real regime
What does a non-compliant entity actually risk under DORA? Administrative fines, penalty payments for critical providers, and real scope.

A frequent — and legitimate — question: what does one actually risk by not being compliant with DORA? The regulation does not merely set obligations; it gives authorities the means to enforce them. Here is a factual overview of the sanctions regime, distinguishing what applies to financial entities from what targets critical third-party providers — two different logics.
The powers of national authorities (ACPR, AMF)
In France, the ACPR and the AMF are responsible for supervising DORA. They have the usual range of administrative measures and sanctions of financial supervision law, now available under DORA:
- Administrative measures: injunctions, requests to bring into compliance, corrective measures.
- Financial sanctions (administrative fines).
- Penalty payments.
- In the most serious cases, measures that can go as far as licence withdrawal.
The order of magnitude cited for a non-compliant financial entity can reach a percentage of its annual worldwide turnover. Beyond the amount, it is the logic that matters: the sanction is proportionate to the seriousness and persistence of the breach.
The specific case of critical third-party providers (CTPPs)
Providers designated as critical at European level — typically the large cloud hyperscalers — fall under a distinct regime, under the direct oversight of a European lead overseer. The latter has a particular penalty-payment power: if it imposes measures and the provider does not comply within a minimum of 30 days, it may decide on a daily penalty payment, for a limited duration (up to six months), which can reach a percentage of the provider's average daily worldwide turnover.
This mechanism is notable: it applies direct financial pressure to technology players that had until now largely escaped financial supervision.
The timeline for the first sanctions
An important point to frame expectations: at this stage, the phase of formal sanctions specifically under DORA is in its early days. After a 2025 oriented towards support, 2026 marks the shift to active supervision. The first dedicated decisions are expected as inspection cycles unfold. This does not signify tolerance: it means the window to get in order before the first formal controls is closing.
Beyond the sanction: the real risk
Focusing only on the fine would be an analytical mistake. For a financial entity, the consequences of a DORA breach go beyond the penalty:
- Reputational risk. A resilience failure made public, or a sanction, affects the confidence of clients and counterparties.
- Real operational risk. DORA is not just an administrative constraint: a weak framework exposes you to real, costly and destabilising incidents.
- Relational risk with the supervisor. An entity identified as fragile attracts reinforced and lasting attention, which weighs on all its regulatory exchanges.
In other words, DORA compliance is justified less by fear of the fine than by the risk control it organises.
How to reduce your exposure
The best protection against sanction is not façade compliance, but the ability to demonstrate an effective framework:
- An ICT risk management framework documented and approved by the management body.
- An up-to-date, quality register of information.
- An operational incident process, meeting the deadlines.
- ICT contracts compliant with Article 30.
- Resilience tests carried out and traced.
- Evidence linked to requirements, available on demand.
It is this continuous demonstrability that distinguishes a solid entity from one vulnerable at control time.
Where Axenia fits in. Axenia does not « guarantee » the absence of sanction — no tool can. But by linking your compliance data and keeping your evidence tied to requirements, it reduces the most concrete risk: that of being unable to demonstrate, on control day, what you have nonetheless put in place.
This article presents a general overview of the sanctions regime and does not constitute legal advice. The precise amounts, thresholds and procedures are set out in the DORA regulation and applicable national texts; consult a qualified professional for any specific situation.
See how Axenia strengthens your DORA demonstrability. Book a demo →
