Digital Operational Resilience Act (Regulation (EU) 2022/2554)
In application since 17 January 2025
DORA is the EU's digital operational resilience regime for the financial sector: ICT risk management, incident reporting, resilience testing, and — its sharpest edge — direct oversight of critical third-party ICT providers. It applies to banks, payment and e-money institutions, investment firms, crypto-asset service providers and insurers operating in the EU.
Since 17 January 2025 DORA applies directly, and supervisory attention has shifted to implementation detail: registers of information, threat-led penetration testing, subcontracting chains and incident-classification practice. Third-country firms serving EU clients feel it through their EU entities and vendors.
This page tracks DORA-related supervisory publications, guidance and equivalent operational-resilience regimes emerging in other jurisdictions, updated same-day.
The Supervisory ICT Risk and Cybersecurity (SIRC) Function's Webpage and Key Updates
Malta
MFSA
Final report on Guidelines on the sound management of third-party risk related to non-ICT services
European Union
EBA
How we supervise FMI
New Zealand
RBNZ
KiwiSaver Annual Report 2026 stresses the importance of good governance as balances pass $40,000
New Zealand
FMA
Circular CSSF 26/915 — on the applicability of the Digital Operational Resilience Act (DORA) to third-country branches in Luxembourg
Luxembourg
CSSF
Enhancement of Operational Resilience to Address Quantum Computing Risks
Saudi Arabia
SAMA
Pakistan Virtual Asset Services Activity Specific Regulations, 2026
Pakistan
PVARA
ESMA launches a Common Supervisory Action with NCAs on CASPs’ digital operational resilience for custody
Cyprus
CySEC
DORA-update 7
Netherlands
AFM
Frontier Artificial Intelligence Models and the Evolving Cyber-Threat Landscape
Malta
MFSA
Operational Risk Management Regulation
United Arab Emirates
CBUAE
Supervisory Expectations on Geopolitical Risk Management
Portugal
BDP
Financial Policy Committee Record – July 2026
United Kingdom
BOE
ESRB warns of vulnerabilities in the financial system linked to advanced AI models
Sweden
Riksbank
Minutes of the London FXJSC Operations Sub-Committee Meeting – 18 March 2026
United Kingdom
BOE
Final Report on revised SREP and supervisory stress testing Guidelines
European Union
EBA
Warning of the European Systemic Risk Board on systemic cyber risks from frontier AI models
European Union
ESRB
Comparing the TIBER-EU Framework with other established Non-EU TLPT Frameworks
Malta
MFSA
Summary of the RTGS CHAPS Industry Forum
United Kingdom
BOE
ICT Self-Assessment Tool 2026
Ireland
CBI
General Observations on Digital Operational Resilience in Authorisation Applications Received in 2025
Malta
MFSA
Law on Markets in Financial Instruments
Bulgaria
FSC
MFSA Issues AI Governance and Prudential Risk Expectations for Malta Financial Services Firms
Malta
MFSA
Operational Resilience: Sustaining and Uplifting
Hong Kong
HKMA
Law on Crypto-Asset Markets
Bulgaria
FSC
The Bank, FCA and HM Treasury joint statement on Frontier AI models and cyber resilience
United Kingdom
BOE
GFSC Guidance Note on Outsourcing and Third Party Risk Management for Banks and Insurers
Gibraltar
GFSC
Good practices for addressing vulnerabilities related to operational resilience
Hong Kong
HKMA
Good Practices for Addressing Vulnerabilities Related to Operational Resilience
Hong Kong
HKMA
Notice of Consultation Paper Release: CP 170
United Arab Emirates
DFSA
Showing the 30 most recent of 255.