Under S.I. 20/2025, DORA does not apply to Irish credit unions until 17 January 2028. But the Central Bank of Ireland has been clear that credit unions should strengthen their digital and operational resilience now, rather than waiting for the deadline.
Irish credit unions have a genuine advantage — time. Used well, the period to January 2028 is an opportunity to prepare calmly rather than scramble.
The deferral to 17 January 2028
S.I. 20/2025 defers DORA’s application to Irish credit unions (within the meaning of the Credit Union Act 1997) until 17 January 2028. Until then, DORA’s obligations do not formally bite on credit unions.
Why not just wait?
Because the Central Bank expects action now. Its guidance for credit unions already points in the same direction as DORA — stronger ICT governance, risk management, continuity planning and third-party oversight. Credit unions that close these gaps early will be in a strong position for 2028, and more resilient in the meantime.
What to prepare before 2028
Strengthen ICT governance and board ownership of digital risk
Build basic ICT risk-management and incident processes
Map key third-party (including IT partner) dependencies
Establish proportionate resilience testing
Much of this can be done incrementally, at a pace that suits a smaller organisation.
Want a proportionate, credit-union-sized DORA readiness plan? Talk to CyberLabs.