DORA and the CSRB: Where the IT contract jobs are

One regime is already a binding EU regulation; the other is working its way through the House of Lords — but both are reshaping IT hiring. Tech lawyer Evane Alexandre sets out what DORA and the Cyber Security & Resilience Bill require of contractors, why supply chains (not just banks) are where the holy grail might be, and four ways your job profile can signal you're cyber regulation-savvy.
Cybersecurity is now Britain's “single strongest [hiring] market,” according to an August 2026 update by SThree — which credits the rise to DORA (the Digital Operational Resilience Act), the UK Cyber Security and Resilience Bill (CSRB) and the EU AI Act. No surprise, then, that temporary technologists have been swapping notes.
On day rates — here's up to €800 a day for a DORA programme specialist; on debates — here’s a technology leader at Capital One (Kiran Rane) hailing DORA as the “gold standard of delivery performance”; and on dos and don'ts — here's a senior tech programme manager (Alfred Obeng) opining on how to act when DORA and the EU AI Act interact. It's all now in the conversational mix.
Why could supply chains be your way into DORA and CSRB hiring?

And it's not just a UK story — Free-Work’s dedicated DORA job pages pool roles across France, Belgium and elsewhere in Europe. From here, I want to outline why supply chains, not just headline sectors, might be the holy grail if you’re ‘on the bench’ and want to leverage DORA/CSRB to land your next role.
I’ll also pinpoint four practical steps for security tech job board users wanting to add these in-force cyber security regulations (DORA) and incoming regulatory framework (CSRB) to their online profile to flag up DORA-awareness and CSRB-readiness to any browsing hiring decision-maker, writes technology lawyer Evane Alexandre, associate at Gerrish Legal.
What DORA/CSRB powering cyber security demand means for your online tech job profile
Not every IT professional needs to become a cyber specialist to plug into DORA/CSRB-inspired hiring. The opportunity is pairing your existing technical skillset with UK/EU regulatory literacy — increasingly valuable to hiring managers alongside raw technical ability.
It’s much more about IT contractors (in particular) realising that UK/EU regulatory literacy is increasingly valuable to hiring managers — alongside technical capability — and it’s particularly ‘hireable’ in:
Financial Services (FS)
Critical Infrastructure
Technology Supply Chains.
What does a DORA hiring brief actually look like?
FS features on this list first, intentionally. Here’s a London role at a “leading international bank” advertising for a senior techie to:
Lead DORA initiatives.
Coordinate across IT, Risk, and third parties to assess cyber risk and ensure regulatory alignment.
Deliver DORA deliverables.
Does DORA only affect financial services?
However, DORA’s reach extends beyond Financial Services.
In fact, wherever a contractor’s client supplies software or services to a regulated firm, that firm will push resilience and testing requirements down the supply chain. And that’s why supply chains are worth assessing if you’re in the market for a DORA-related role but aren’t having any luck.
DORA binds more than banks, insurers and investment firms
DORA sets binding requirements on financial entities:
Banks
Insurers
Investment firms.
Yet, crucially, it also makes those requirements binding for the ICT providers that supply that trio.
What does DORA actually require from IT contractors?

For IT contractors, DORA’s practical effect is straightforward if not obvious: firms in scope need people who can build the evidence to prove DORA compliance, albeit stemming from an understanding of DORA’s core requirements:
ICT risk management
incident reporting
resilience testing
oversight of third-party risk.
The result is sustained demand for specific roles: threat-led penetration testers, ICT risk managers, incident-response specialists and third-party risk analysts. Job descriptions may therefore place greater emphasis on experience of regulated environments, resilience testing, supplier assurance, incident management and documentation that stands up to audit or regulatory scrutiny.
Which contract roles is DORA compliance creating demand for?
This supply-chain push is exactly why DORA-related hiring reaches beyond FS — and it's a boon for IT contractors specifically, sustaining demand for contract and temporary specialists in:
· Threat-led penetration testing
ICT risk management
Incident response
Third-party risk analysis.
Expect these job descriptions to lean harder on regulated-environment experience, audit-ready documentation and supplier assurance than on general security skills alone.
What is DORA (Digital Operational Resilience Act), in brief?
Before we continue onto the CSRB, a recap: DORA is an EU regulation that has applied since January 2025.
DORA is designed to strengthen the financial sector’s resilience to information and communications technology (ICT) disruption.
DORA captures both a defined set of financial entities and, as emphasised here, the ICT providers that serve them. Information and Communications Technology (ICT) Providers judged systemically important may be designated ‘critical’, bringing heightened scrutiny, resilience testing and contractual obligations.
From DORA to the CSRB: two regimes, one direction
Let’s now move to the other cyber-resilience regime that, alongside the EU AI Act, is increasingly behind the strength and resilience of cyber security hires – the CSRB.
Before unpacking the bill, which is different in scale and scope to DORA, here's what unifies the pair: they both point in the same direction — operational resilience, cyber risk and supply-chain security as ongoing governance issues, not one-off technical exercises.
Is the Cyber Security and Resilience Bill law yet?
Not yet — and that's exactly why it’s worth technologists getting ahead of it now.
The CSRB had its Second Reading in the House of Lords in July 2026, having been introduced in November 2025.
Once passed, the CSRB will expand the UK’s existing Network and Information Systems regime — pulling data centres and managed service providers into scope for the first time.
What will the CSRB require of Data Centres and MSPs?
The bill requires them to report significant incidents, run proportionate risk management and secure their digital supply chains. As you can imagine, employers are not waiting for Royal Assent to start hiring against it.
Which roles will the CSRB put in demand?

At the time of writing (August 28th 2026) the CSRB is already reshaping team structure.
Permanent governance, risk and compliance (GRC) and security staff are anchoring the function, but with contractors the 'go-to' for specialist testing and surge capacity as resilience becomes a board-level responsibility.
So resilience is now a board-level line item, not an IT ticket — which means readiness assessments, risk reporting and incident-response documentation are becoming genuinely marketable skills, not just compliance box-ticking. Free-Work's NIS2-tagged roles are worth a look too: they reflect the EU's parallel NIS2 directive rather than the UK's own regime directly, but they're a useful read on how fast this kind of compliance hiring is moving across Europe more broadly.
The CSRB pulls the same lever as DORA: supply-chain pressure
This is the detail worth sitting with if you're job-hunting rather than job-secure: as more suppliers and managed service providers get pulled into the CSRB’s scope, the hiring need spreads to organisations that are new or newer to formalising cyber compliance. For candidates, that's a wider, ‘softer’ market than the banks and insurers everyone else is chasing — and it’s precisely the ‘supply chains, not headline sectors’ opportunity I flagged at the start of this piece. Candidates with experience of readiness assessments and risk reporting track records appear to be among the best-positioned.
How can you make DORA-awareness and CSRB-readiness visible on your job profile?
Four practical steps worth taking now to make your online tech job profile ‘speak’ to these seminal cyber security regulatory frameworks:
Name your certifications, not just your skills. CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor or CompTIA Security+ each give a hiring manager an instant, credible shorthand they can match to client briefs.
Speak the regime’s language accurately and precisely. Referencing DORA's third-party risk requirements, or the CSRB's NIS reforms by name, signals you understand a client's actual compliance context — not just ‘cybersecurity’ in the abstract.
Build security into your existing tech discipline. If you're a developer, infrastructure engineer or delivery lead who can evidence secure-by-design and resilience thinking, it primes you strategically for regulated work.
Go where the suppliers are, not just the key sectors or household brands. If you’re feeling heavily outweighed by the competition, remember that the supply chain — now in scope, or soon to be — is where the CSRB and DORA are quietly creating a swathe of openings.
The takeaway
DORA and the CSRB are different instruments at different stages — one already binding, one still moving through the Lords — but they're pulling UK and EU cybersecurity hiring in the same direction. For contractors, that's not a niche opening in dedicated cyber roles; it's a live case for regulatory literacy across every discipline that touches a regulated client's supply chain. The bottom line? Look to those wider teams that design, operate, test and assure resilient systems.
Evane Alexandre



Comment
Log in or create your account to react to the article.