On 6 August 2026, the Dutch Authority for the Financial Markets (Autoriteit Financiële Markten, AFM) published an update on the Digital Operational Resilience Act (Regulation (EU) 2022/2554, DORA). This update focuses on the progress of the financial sector since the introduction of DORA.

The AFM has noticed strong improvement in the number of information registers approved by the European Banking Authority (EBA) as part of its annual exercise, during which the EBA requests all national competent authorities to collect the registers of information of DORA-regulated entities and submit them to the EBA. To provide further guidance in this area, the AFM published a Q&A on the information register (available here).

The AFM’s supervision of compliance with the DORA requirements in 2025 focused on ICT risk management. The AFM’s observations are as follows:

  • Policies and procedures: financial entities do not always have all the policies and procedures in place that are required under DORA. In addition, not all submitted policies and procedures met the requirements under DORA. The AFM recommends firms to periodically conduct a self-assessment to determine whether their existing policies and procedures comply with DORA requirements and to ensure that their policies and procedures are aligned with their current risks and the actual operating practices of the organisation.
  • Group entities: for group entities, the AFM stresses that financial entities that are part of a larger group must verify independently whether all relevant DORA requirements have been fully incorporated into their policies and procedures, as the licensed financial entity remains fully responsible for their compliance with the DORA requirements.
  • Disruptions: while most financial entities have implemented sufficient measures to detect (potential) disruptions, these entities have often not yet established adequate preventive measures to avoid such disruptions. Particularly, room for improvement exists in the areas of logical access management and patch and vulnerability management.

Separately, the AFM notices a lower number of incident reports than expected. The AFM recommends that financial entities review their incident management processes to ensure they are properly designed and implemented and to enable incidents to be detected, recorded, managed, classified, and, where required, reported within the statutory time limits.

Finally, the AFM highlights the clarification provided by the European Supervisory Authorities (ESAs) on how to determine whether insurance intermediaries fall within the scope of DORA when only a part of their business relates to insurance mediation. As follows from the ESAs guidance, in general, the figures for the undertaking as a whole should be considered. However, in accordance with the principle of proportionality, entities whose insurance mediation activities are only of limited significance should consider solely the activities and resources dedicated to those insurance-related activities.

The DORA update is available here.