2026-08-06
Added
This DORA update reviews the implementation of the Digital Operational Resilience Act, noting an increase in information register approval rates by the EBA from 40% in 2025 to 94% in 2026. It advises financial entities to conduct periodic self-assessments of their ICT risk management policies and procedures, particularly for logical access security and patch/vulnerability management, and to ensure incident processes facilitate timely reporting of serious ICT-related incidents within specified deadlines. The document also clarifies DORA's applicability thresholds for small and medium-sized insurance intermediaries, detailing how to calculate FTE, annual turnover, and balance sheet totals for those with limited insurance activities or those belonging to a group.
REPORT ANALYSIS DORA-update 7 In brief - The past eighteen months have been dominated by the implementation of the Digital Operational Resilience Act (DORA) for many financial undertakings. From the request for the register of information and the initial experiences with DORA supervision to further clarifications in the underlying regulations: the sector has made significant progress in a short time. At the same time, we see a number of areas for improvement that undertakings can still address. In this DORA update, we look back at the most important developments, experiences, and points of attention since the introduction of DORA. AUGUST | 2026
© AFM 2026 | DORA-update 7 2 Table of Contents
© AFM 2026 | DORA-update 7 3
© AFM 2026 | DORA-update 7 4 DORA Oversight Activities Based on their analysis of the information registers from the various member states, the European Supervisory Authorities (EBA, EIOPA, and ESMA – collectively the ESAs) have drawn up a list of nineteen critical ICT third-party providers.2 These undertakings will fall under the direct supervision of the ESAs (the DORA Oversight Framework). As a national supervisory authority, we contribute to Joint Examination Teams (JETs) that carry out DORA Oversight activities at various critical ICT third-party providers. The DORA Oversight activities can be divided into the following components:
© AFM 2026 | DORA-update 7 5 2. DORA Supervision In 2025, our supervision of compliance with DORA requirements focused on ICT risk management (Chapter II of the regulation). During our investigations, we requested policy documents and procedures from undertakings and assessed the extent to which these documents meet the requirements set by DORA. It was striking that financial entities do not always have all the policy documents and procedures required under DORA. In addition, not all submitted policy documents and procedures met the requirements of the regulation and Commission Delegated Regulation (EU) 2024/1774. We therefore advise undertakings to periodically perform a self-assessment, checking whether existing policy documents and procedures comply with DORA requirements. By doing this regularly, for example during the mandatory evaluation of the ICT risk management framework, financial entities can also ensure that their policies and procedures align with current risks and the actual working methods of the undertaking. Furthermore, we note that financial entities that are part of a larger group often use policy documents and procedures drawn up at group level. In many cases, this is more efficient than individual undertakings within the group developing their own policies. However, the DORA-obligated undertaking (license holder) always remains responsible for compliance with DORA requirements. It is therefore important that undertakings themselves check whether all relevant DORA requirements are fully incorporated into their policy documents and procedures. Finally, we observe that most undertakings have taken sufficient measures to detect (potential) disruptions in a timely manner. At the same time, we see that undertakings often still have insufficient preventive measures in place to prevent such disruptions. Improvements are still possible, particularly in the areas of logical access security and patch and vulnerability management. TLPT The first undertakings started Threat-Led Penetration Testing (TLPT) in 2025. These are extensive tests that simulate tactics, techniques, and procedures used in practice by threat actors (such as hackers). These tests take place under the guidance of the AFM's TLPT test managers. Undertakings designated by us for TLPT must periodically perform a test that meets the requirements of DORA. During the test, the DORA TLPT test managers check whether the activities are carried out in accordance with the requirements of Commission Delegated Regulation (EU) 2025/1190.4 At the end of the test, undertakings receive an attestation with which they can demonstrate that they have successfully performed a TLPT test. After completion of the test, the results, including the Test Summary and the Remediation Plan, are shared with the supervisory departments of the AFM. This allows for follow-up on the findings and the implementation of the remediation plan. 4 Delegated regulation - EU - 2025/1190 - EN - EUR-Lex
© AFM 2026 | DORA-update 7 6 DORA Notifications In 2025, we received 123 DORA notifications from undertakings under our supervision. Of these, 65 notifications concerned serious ICT-related incidents. 54 notifications concerned new agreements with ICT service providers. Four notifications concerned significant cyber threats. Since the number of incident notifications lags behind our expectations, we advise undertakings to (re)check whether the incident process is correctly set up. It is important that the process is designed in such a way that incidents can be detected, registered, managed, classified, and reported in a timely manner. Three types of notifications DORA distinguishes three types of notifications that undertakings must or can continuously make to the supervisory authority. The first type of notification concerns serious ICT-related incidents. These must be reported no later than four hours after the classification of the incident, or within 24 hours after its detection. Subsequently, an interim report must be submitted no later than 72 hours after the initial notification. A final report must be submitted no later than one month after classification. Given these strict deadlines, it is important that undertakings design their incident process in such a way that mandatory notifications can be submitted to the supervisory authority in a timely manner. In addition to reporting incidents, undertakings are obliged under DORA to report all new agreements concluded with third-party providers of ICT services at least once a year. Finally, undertakings can voluntarily report significant cyber threats that are relevant to the financial sector. More information about the obligations regarding DORA notifications can be found in Articles 18, 19, and 28, third paragraph, of the regulation and the Delegated Regulation on the reporting of serious ICT-related incidents and significant cyber threats5. 5 Delegated regulation - EU - 2025/301 - EN - EUR-Lex
© AFM 2026 | DORA-update 7 7 3. Developments for Insurance Intermediaries For a long time, there was unclarity about how to determine whether insurance intermediaries fall under DORA. The ESAs have now provided more clarity on this in Q&A DORA0996 and DORA2377. The regulation includes an exemption for small and medium-sized insurance intermediaries (fewer than 250 FTE and an annual turnover of less than €50 million and/or a balance sheet total of less than €43 million). Because mediating in insurance constitutes only a limited part of the activities for some insurance intermediaries, the question arose how these criteria should be applied to undertakings for which mediating in insurance is not the primary activity. In addition, there was unclarity about how the number of FTE, annual turnover, and balance sheet total should be calculated for undertakings that are part of a group. Q&A DORA237 answers the question of how the number of FTE, annual turnover, and balance sheet total should be calculated when insurance mediation activities constitute only a limited part of an undertaking's total activities. The EIOPA's answer indicates that, in principle, the figures for the entire undertaking must be included in this assessment. However, based on the principle of proportionality, undertakings whose insurance mediation activities are of limited scope must only take into account the activities and resources used for those insurance activities. For insurance intermediaries that are part of a group, it must first be determined whether it is a financial group or a non-financial group. When an undertaking is part of a non-financial group, only the individual undertaking must be considered. For financial entities that are part of a financial group, the interest they hold in other undertakings or the interest that other undertakings hold in them must be considered. When an undertaking owns between 25% and 50% of the shares or voting rights of another undertaking, these undertakings are designated as partner undertakings (partner entities). In that case, the number of FTE, annual turnover, and balance sheet total of the partner undertaking must be included proportionally in the calculation of the thresholds. For linked undertakings (linked entities), where there is a majority interest or control, the number of FTE, annual turnover, and balance sheet total of the linked undertaking must be fully included in the calculation. 6 3100 - DORA099 - European Insurance and Occupational Pensions Authority 7 DORA237 - 3350 - European Insurance and Occupational Pensions Authority
© AFM 2026 | DORA-update 7 8 4. Conclusion For more information on developments in legislation and regulations, please consult the DORA page on the AFM website. In addition, you can monitor developments on the ESAs' website:
More like this from AFM
AFM published 1 document in the last 30 days. We email you each new one the day it's published.