If you’ve been treating DORA like “another compliance deadline,” you’re not alone. But here’s what’s become clear since DORA started applying in January 2025: DORA doesn’t just require you to assess vendors. It requires you to operate third-party ICT risk as a living system.