2026-08-06

Added

DORA-update 7

This DORA update reviews the implementation of the Digital Operational Resilience Act, noting an increase in information register approval rates by the EBA from 40% in 2025 to 94% in 2026. It advises financial entities to conduct periodic self-assessments of their ICT risk management policies and procedures, particularly for logical access security and patch/vulnerability management, and to ensure incident processes facilitate timely reporting of serious ICT-related incidents within specified deadlines. The document also clarifies DORA's applicability thresholds for small and medium-sized insurance intermediaries, detailing how to calculate FTE, annual turnover, and balance sheet totals for those with limited insurance activities or those belonging to a group.

Autoriteit Financiele Markten logo

Netherlands

Autoriteit Financiele Markten

Click to view thumbnail

REPORT ANALYSIS DORA-update 7 In brief - The past eighteen months have been dominated by the implementation of the Digital Operational Resilience Act (DORA) for many financial undertakings. From the request for the register of information and the initial experiences with DORA supervision to further clarifications in the underlying regulations: the sector has made significant progress in a short time. At the same time, we see a number of areas for improvement that undertakings can still address. In this DORA update, we look back at the most important developments, experiences, and points of attention since the introduction of DORA. AUGUST | 2026

© AFM 2026 | DORA-update 7 2 Table of Contents

  1. DORA Information Register 3 Request 3 Q&A session 3 DORA Oversight Activities 4
  2. DORA Supervision 5 TLPT 5 DORA Notifications 6
  3. Developments for Insurance Intermediaries 7
  4. Conclusion 8

© AFM 2026 | DORA-update 7 3

  1. DORA Information Register Request The AFM has requested the register of information twice from all DORA-obligated undertakings. In the first year, 40% of the registers were approved by the European Banking Authority (EBA). In 2026, this increased to 94% of the registers. The request for the information register was the first (and largest) request that undertakings encountered after DORA became applicable. During this annual request, the EBA asks all national supervisory authorities to request the information registers from DORA-obligated undertakings and share them. The EBA then uses these registers to determine which critical third-party providers of ICT services will fall under the supervision of the European supervisory authorities (see 'DORA Oversight Activities' below). Since undertakings had to submit their information register in the first quarter of 2025, there was still much unclarity about the xBRL-CSV format and how the register should be completed. We therefore decided for 2025 that we would take on the conversion to xBRL-CSV once. This meant that institutions could submit their information register in Excel, allowing them more time to correctly complete the register. Ultimately, 40% of the submitted registers in 2025 were approved by the EBA. For the 2026 request, undertakings had to submit the information register in xBRL-CSV themselves for the first time. At the same time, we organized the process on our side such that the registers were automatically sent to the EBA and feedback was automatically retrieved. This allowed undertakings to submit a new version as often as necessary. In 2026, 94% of the information registers were approved by the EBA. This increase compared to 2025 can (partially) be explained by undertakings knowing better what to expect from the request in the second year. In addition, we noticed that many undertakings in 2026 used external parties who handled the conversion to xBRL-CSV and helped them complete the register. Q&A session During the request for the information register in 2026, we organized a Q&A session where undertakings had the opportunity to ask questions about the register. The goal was to answer as many questions as possible in a short time. In addition, the Q&A session helped us identify the biggest bottlenecks in completing the register. After the deadline, based on the Q&A session and the submitted registers, we created an overview of the most common errors and how they can be resolved. This overview is included in the questions and answers of the Q&A session (pdf, 240 kB). 1 1 https://www.afm.nl/~/profmedia/files/onderwerpen/dora/20260305-qa-dora-sessie.pdf

© AFM 2026 | DORA-update 7 4 DORA Oversight Activities Based on their analysis of the information registers from the various member states, the European Supervisory Authorities (EBA, EIOPA, and ESMA – collectively the ESAs) have drawn up a list of nineteen critical ICT third-party providers.2 These undertakings will fall under the direct supervision of the ESAs (the DORA Oversight Framework). As a national supervisory authority, we contribute to Joint Examination Teams (JETs) that carry out DORA Oversight activities at various critical ICT third-party providers. The DORA Oversight activities can be divided into the following components:

  • Ongoing regular monitoring. This includes, among other things, periodic information gathering and an ongoing dialogue with Critical ICT Third-Party Providers (CTPPs) about the current state of affairs and emerging risks, such as operational incidents or new threats.
  • General investigations. These are more in-depth investigations into specific risk areas. These are carried out in accordance with the supervisory plan and are aimed at addressing newly identified points of attention or assessing remedial measures following previous investigations.
  • Inspections. Inspections are similar to general investigations but are more intrusive and aimed at an in-depth assessment of the risks that service providers pose to financial institutions. Inspections include, among other things, the authority to request files, data, and other relevant documentation.
  • Information requests. This offers the possibility to request information from CTPPs without initiating a general investigation or inspection. Information requests can, for example, be used to clarify a specific situation for which supervisors need additional information or explanation from the CTPP.
  • Recommendations. Recommendations focus on identified shortcomings at a CTPP within specific assessment areas. The follow-up of recommendations takes place through ongoing monitoring and reports describing the measures taken and improvements implemented as a result of the recommendations. More information about DORA Oversight activities can be found in the guideline previously published by the ESAs.3 2 The European Supervisory Authorities designate critical ICT third-party providers under the Digital Operational Resilience Act | European Banking Authority 3 JC 2025 29 Guide on DORA oversight activities

© AFM 2026 | DORA-update 7 5 2. DORA Supervision In 2025, our supervision of compliance with DORA requirements focused on ICT risk management (Chapter II of the regulation). During our investigations, we requested policy documents and procedures from undertakings and assessed the extent to which these documents meet the requirements set by DORA. It was striking that financial entities do not always have all the policy documents and procedures required under DORA. In addition, not all submitted policy documents and procedures met the requirements of the regulation and Commission Delegated Regulation (EU) 2024/1774. We therefore advise undertakings to periodically perform a self-assessment, checking whether existing policy documents and procedures comply with DORA requirements. By doing this regularly, for example during the mandatory evaluation of the ICT risk management framework, financial entities can also ensure that their policies and procedures align with current risks and the actual working methods of the undertaking. Furthermore, we note that financial entities that are part of a larger group often use policy documents and procedures drawn up at group level. In many cases, this is more efficient than individual undertakings within the group developing their own policies. However, the DORA-obligated undertaking (license holder) always remains responsible for compliance with DORA requirements. It is therefore important that undertakings themselves check whether all relevant DORA requirements are fully incorporated into their policy documents and procedures. Finally, we observe that most undertakings have taken sufficient measures to detect (potential) disruptions in a timely manner. At the same time, we see that undertakings often still have insufficient preventive measures in place to prevent such disruptions. Improvements are still possible, particularly in the areas of logical access security and patch and vulnerability management. TLPT The first undertakings started Threat-Led Penetration Testing (TLPT) in 2025. These are extensive tests that simulate tactics, techniques, and procedures used in practice by threat actors (such as hackers). These tests take place under the guidance of the AFM's TLPT test managers. Undertakings designated by us for TLPT must periodically perform a test that meets the requirements of DORA. During the test, the DORA TLPT test managers check whether the activities are carried out in accordance with the requirements of Commission Delegated Regulation (EU) 2025/1190.4 At the end of the test, undertakings receive an attestation with which they can demonstrate that they have successfully performed a TLPT test. After completion of the test, the results, including the Test Summary and the Remediation Plan, are shared with the supervisory departments of the AFM. This allows for follow-up on the findings and the implementation of the remediation plan. 4 Delegated regulation - EU - 2025/1190 - EN - EUR-Lex

© AFM 2026 | DORA-update 7 6 DORA Notifications In 2025, we received 123 DORA notifications from undertakings under our supervision. Of these, 65 notifications concerned serious ICT-related incidents. 54 notifications concerned new agreements with ICT service providers. Four notifications concerned significant cyber threats. Since the number of incident notifications lags behind our expectations, we advise undertakings to (re)check whether the incident process is correctly set up. It is important that the process is designed in such a way that incidents can be detected, registered, managed, classified, and reported in a timely manner. Three types of notifications DORA distinguishes three types of notifications that undertakings must or can continuously make to the supervisory authority. The first type of notification concerns serious ICT-related incidents. These must be reported no later than four hours after the classification of the incident, or within 24 hours after its detection. Subsequently, an interim report must be submitted no later than 72 hours after the initial notification. A final report must be submitted no later than one month after classification. Given these strict deadlines, it is important that undertakings design their incident process in such a way that mandatory notifications can be submitted to the supervisory authority in a timely manner. In addition to reporting incidents, undertakings are obliged under DORA to report all new agreements concluded with third-party providers of ICT services at least once a year. Finally, undertakings can voluntarily report significant cyber threats that are relevant to the financial sector. More information about the obligations regarding DORA notifications can be found in Articles 18, 19, and 28, third paragraph, of the regulation and the Delegated Regulation on the reporting of serious ICT-related incidents and significant cyber threats5. 5 Delegated regulation - EU - 2025/301 - EN - EUR-Lex

© AFM 2026 | DORA-update 7 7 3. Developments for Insurance Intermediaries For a long time, there was unclarity about how to determine whether insurance intermediaries fall under DORA. The ESAs have now provided more clarity on this in Q&A DORA0996 and DORA2377. The regulation includes an exemption for small and medium-sized insurance intermediaries (fewer than 250 FTE and an annual turnover of less than €50 million and/or a balance sheet total of less than €43 million). Because mediating in insurance constitutes only a limited part of the activities for some insurance intermediaries, the question arose how these criteria should be applied to undertakings for which mediating in insurance is not the primary activity. In addition, there was unclarity about how the number of FTE, annual turnover, and balance sheet total should be calculated for undertakings that are part of a group. Q&A DORA237 answers the question of how the number of FTE, annual turnover, and balance sheet total should be calculated when insurance mediation activities constitute only a limited part of an undertaking's total activities. The EIOPA's answer indicates that, in principle, the figures for the entire undertaking must be included in this assessment. However, based on the principle of proportionality, undertakings whose insurance mediation activities are of limited scope must only take into account the activities and resources used for those insurance activities. For insurance intermediaries that are part of a group, it must first be determined whether it is a financial group or a non-financial group. When an undertaking is part of a non-financial group, only the individual undertaking must be considered. For financial entities that are part of a financial group, the interest they hold in other undertakings or the interest that other undertakings hold in them must be considered. When an undertaking owns between 25% and 50% of the shares or voting rights of another undertaking, these undertakings are designated as partner undertakings (partner entities). In that case, the number of FTE, annual turnover, and balance sheet total of the partner undertaking must be included proportionally in the calculation of the thresholds. For linked undertakings (linked entities), where there is a majority interest or control, the number of FTE, annual turnover, and balance sheet total of the linked undertaking must be fully included in the calculation. 6 3100 - DORA099 - European Insurance and Occupational Pensions Authority 7 DORA237 - 3350 - European Insurance and Occupational Pensions Authority

© AFM 2026 | DORA-update 7 8 4. Conclusion For more information on developments in legislation and regulations, please consult the DORA page on the AFM website. In addition, you can monitor developments on the ESAs' website:

  • Digital Operational Resilience Act (DORA) - EBA
  • Digital Operational Resilience Act (DORA) - EIOPA
  • Digital Operational Resilience Act (DORA) - ESMA Further questions? Please contact the AFM business desk. Links to previous publications: Publications Trading systems require sharper ICT risk management under DORA SREP Market View: management requires more than just policy Preparations for reporting of DORA registers of information | European Banking Authority

More like this from AFM

AFM published 1 document in the last 30 days. We email you each new one the day it's published.

Share