DORA

Digital Operational Resilience Act (Regulation (EU) 2022/2554)

In application since 17 January 2025

DORA is the EU's digital operational resilience regime for the financial sector: ICT risk management, incident reporting, resilience testing, and — its sharpest edge — direct oversight of critical third-party ICT providers. It applies to banks, payment and e-money institutions, investment firms, crypto-asset service providers and insurers operating in the EU.

Since 17 January 2025 DORA applies directly, and supervisory attention has shifted to implementation detail: registers of information, threat-led penetration testing, subcontracting chains and incident-classification practice. Third-country firms serving EU clients feel it through their EU entities and vendors.

This page tracks DORA-related supervisory publications, guidance and equivalent operational-resilience regimes emerging in other jurisdictions, updated same-day.

Instrument:
Regulation (EU) 2022/2554 — directly applicable
In application:
17 January 2025
Scope:
Banks, PSPs/EMIs, investment firms, CASPs, insurers + critical ICT providers
Analogues:
APRA CPS 230 (AU), Bank of England/PRA operational-resilience rules (UK)

Latest tracked documents (255)

2026-10-01

The Supervisory ICT Risk and Cybersecurity (SIRC) Function's Webpage and Key Updates

Malta Financial Services Authority

Malta

MFSA

2026-09-18

Final report on Guidelines on the sound management of third-party risk related to non-ICT services

European Banking Authority

European Union

EBA

2026-09-16

How we supervise FMI

Reserve Bank of New Zealand

New Zealand

RBNZ

2026-09-10

KiwiSaver Annual Report 2026 stresses the importance of good governance as balances pass $40,000

Financial Markets Authority

New Zealand

FMA

2026-08-27

Circular CSSF 26/915 — on the applicability of the Digital Operational Resilience Act (DORA) to third-country branches in Luxembourg

Commission de Surveillance du Secteur Financier

Luxembourg

CSSF

2026-08-27

Enhancement of Operational Resilience to Address Quantum Computing Risks

Saudi Central Bank

Saudi Arabia

SAMA

2026-08-21

Pakistan Virtual Asset Services Activity Specific Regulations, 2026

Pakistan Virtual Assets Regulatory Authority

Pakistan

PVARA

2026-08-06

ESMA launches a Common Supervisory Action with NCAs on CASPs’ digital operational resilience for custody

Cyprus Securities and Exchange Commission

Cyprus

CySEC

2026-08-06

DORA-update 7

Autoriteit Financiele Markten

Netherlands

AFM

2026-08-05

Frontier Artificial Intelligence Models and the Evolving Cyber-Threat Landscape

Malta Financial Services Authority

Malta

MFSA

2026-07-27

Operational Risk Management Regulation

Central Bank of UAE

United Arab Emirates

CBUAE

2026-07-15

Supervisory Expectations on Geopolitical Risk Management

Banco de Portugal

Portugal

BDP

2026-07-07

Financial Policy Committee Record – July 2026

Bank of England

United Kingdom

BOE

2026-07-07

ESRB warns of vulnerabilities in the financial system linked to advanced AI models

Sveriges Riksbank

Sweden

Riksbank

2026-07-02

Minutes of the London FXJSC Operations Sub-Committee Meeting – 18 March 2026

Bank of England

United Kingdom

BOE

2026-06-26

Final Report on revised SREP and supervisory stress testing Guidelines

European Banking Authority

European Union

EBA

2026-06-25

Warning of the European Systemic Risk Board on systemic cyber risks from frontier AI models

European Systemic Risk Board

European Union

ESRB

2026-06-16

Comparing the TIBER-EU Framework with other established Non-EU TLPT Frameworks

Malta Financial Services Authority

Malta

MFSA

2026-06-15

Summary of the RTGS CHAPS Industry Forum

Bank of England

United Kingdom

BOE

2026-06-11

ICT Self-Assessment Tool 2026

Central Bank of Ireland

Ireland

CBI

2026-06-09

General Observations on Digital Operational Resilience in Authorisation Applications Received in 2025

Malta Financial Services Authority

Malta

MFSA

2026-06-08

Law on Markets in Financial Instruments

Financial Supervision Commission Bulgaria

Bulgaria

FSC

2026-06-04

MFSA Issues AI Governance and Prudential Risk Expectations for Malta Financial Services Firms

Malta Financial Services Authority

Malta

MFSA

2026-06-01

Operational Resilience: Sustaining and Uplifting

Hong Kong Monetary Authority

Hong Kong

HKMA

2026-05-29

Law on Crypto-Asset Markets

Financial Supervision Commission Bulgaria

Bulgaria

FSC

2026-05-15

The Bank, FCA and HM Treasury joint statement on Frontier AI models and cyber resilience

Bank of England

United Kingdom

BOE

2026-05-05

GFSC Guidance Note on Outsourcing and Third Party Risk Management for Banks and Insurers

Gibraltar Financial Services Commission

Gibraltar

GFSC

2026-04-01

Good practices for addressing vulnerabilities related to operational resilience

Hong Kong Monetary Authority

Hong Kong

HKMA

2026-04-01

Good Practices for Addressing Vulnerabilities Related to Operational Resilience

Hong Kong Monetary Authority

Hong Kong

HKMA

2026-03-27

Notice of Consultation Paper Release: CP 170

Dubai Financial Services Authority

United Arab Emirates

DFSA

Showing the 30 most recent of 255.