Digital Operational Resilience Act (Regulation (EU) 2022/2554)
In application since 17 January 2025
DORA is the EU's digital operational resilience regime for the financial sector: ICT risk management, incident reporting, resilience testing, and — its sharpest edge — direct oversight of critical third-party ICT providers. It applies to banks, payment and e-money institutions, investment firms, crypto-asset service providers and insurers operating in the EU.
Since 17 January 2025 DORA applies directly, and supervisory attention has shifted to implementation detail: registers of information, threat-led penetration testing, subcontracting chains and incident-classification practice. Third-country firms serving EU clients feel it through their EU entities and vendors.
This page tracks DORA-related supervisory publications, guidance and equivalent operational-resilience regimes emerging in other jurisdictions, updated same-day.
Regulation on Outsourcing of Functions and Activities by Insurance or Reinsurance Undertakings (Decision No 242/2024)
Moldova
NBM
Final report on amending Guidelines on ICT risk and security management
European Union
EBA
Insurance Act – Unofficial Consolidated Text (Official Gazette Nos. 30/15, 112/18, 63/20, 133/20, 151/22, 152/24, 151/25)
Croatia
HANFA
Bank of Zambia Cyber and Information Risk Management Guidelines 2023
Zambia
BOZ
Law on Digital Operational Resilience for the Financial Sector
Montenegro
CBCG
Finansinspektionen’s regulations and general guidelines regarding supervisory reporting for insurance business (FFFS 2015:13)
Sweden
FI
Law on Voluntary Pension Funds – Unofficial Consolidated Text (NN, Nos. 19/14, 29/18, 115/18, 156/23 and 52/25)
Croatia
HANFA
Finansinspektionen Regulations and General Guidelines on Operational Risk Management
Sweden
FI
Capital Markets Act (Official Gazette, Nos. 65/18, 17/20, 83/21, 151/22, 85/24 and 126/25) – Unofficial Consolidated Text
Croatia
HANFA
Regulation on Audit in Pension Insurance Companies (NN, Nos. 131/24 and 139/25)
Croatia
HANFA
Data Model for DORA RoI
European Union
EBA
Finansinspektionen’s regulations and general guidelines regarding occupational pension undertakings (FFFS 2019:21)
Sweden
FI
Finansinspektionen’s Regulations and General Guidelines regarding governance, risk management and control at credit institutions
Sweden
FI
Cybersecurity and Resilience Guideline
Zimbabwe
RBZ
Regulatory Impact Statement on the Central Depositories (Regulation of Central Depositories) (Amendment) Rules 2025
Kenya
CMA
Finansinspektionen’s regulations regarding alternative investment fund managers
Sweden
FI
Pakistan Virtual Asset Services Activity Specific Regulations, 2026
Pakistan
PVARA
ESMA launches a Common Supervisory Action with NCAs on CASPs’ digital operational resilience for custody
Cyprus
CySEC
Frontier Artificial Intelligence Models and the Evolving Cyber-Threat Landscape
Malta
MFSA
Operational Risk Management Regulation
United Arab Emirates
CBUAE
Supervisory Expectations on Geopolitical Risk Management
Portugal
BDP
ESRB warns of vulnerabilities in the financial system linked to advanced AI models
Sweden
Riksbank
Financial Policy Committee Record – July 2026
United Kingdom
BOE
Minutes of the London FXJSC Operations Sub-Committee Meeting – 18 March 2026
United Kingdom
BOE
Final Report on revised SREP and supervisory stress testing Guidelines
European Union
EBA
Warning of the European Systemic Risk Board on systemic cyber risks from frontier AI models
European Union
ESRB
Comparing the TIBER-EU Framework with other established Non-EU TLPT Frameworks
Malta
MFSA
Summary of the RTGS CHAPS Industry Forum
United Kingdom
BOE
ICT Self-Assessment Tool 2026
Ireland
CBI
General Observations on Digital Operational Resilience in Authorisation Applications Received in 2025
Malta
MFSA
Showing the 30 most recent of 231.