2025-01-07
The Dutch Authority for the Financial Markets (AFM) issues its final DORA update to outline supervisory expectations and practical requirements for financial entities effective January 17, 2025. The document mandates the immediate preparation of the register of information and the reporting of serious ICT incidents within strict deadlines, while detailing the AFM's shift to ongoing supervision through targeted investigations and portal-based reporting. It further explains the upcoming Threat-Led Penetration Testing (TLPT) regime and the assessment of ICT risk knowledge for directors during licensing procedures.