Skip to content

DORA 2026 compliance guide

DORA 2026 guide

What the guide covers

Summary of the Digital Operational Resilience Act (DORA (Digital Operational Resilience Act) is Regulation (EU) 2022/2554 on digital operational resilience for the financial sector. It requires EU banks, insurers and investment firms to withstand ICT disruptions and threats, respond to them and recover. It has applied since 17 January 2025.Read more → DORA) for compliance officers, CISOs and financial entity executives. This page is the index: the material is published on the blog, in DORA 2026: a practical guide for financial entities and in DORA for fintech and insurtech: a 90-day checklist. The guide is published on the blog and has no PDF version.

Chapters

ChapterContent
1. What is DORAScope, affected entities, 2024-2026 timeline
2. The 5 operational pillarsRisk management, incidents, testing, third parties, information
3. Incident classificationMajor-incident criteria (DR 2024/1772, Art. 8) and internal Minor/Significant categories
4. Notification chainDR 2025/301 deadlines (4h → 72h → 1 month) with ITS 2025/302 templates
5. Departmental checklistBoard, CISO, IT, Compliance — concrete tasks
6. Automation with BlueUPALMHow the platform covers requirements natively
7. Next steps90-day action plan for your entity

Next steps

Three resources that are delivered today to measure and check DORA/SEPBLAC (Servicio Ejecutivo de la Comisión de Prevención del Blanqueo de Capitales e Infracciones Monetarias) is Spain's Financial Intelligence Unit and its supervisor for the prevention of money laundering and terrorist financing. Obliged entities file suspicious transaction reports with it (Law 10/2010).Read more → SEPBLAC compliance status:

Last updated: